Skip to content

Check catalogue

68 rules. IDs are stable and never reused. Severities are defaults; some checks adjust them per spec revision or evidence.

Transport

ID Title Severity Mode Revisions
MCPP-TRN01 MCP endpoint not served over HTTPS critical passive all
MCPP-TRN02 Legacy TLS (1.0/1.1) accepted high passive all
MCPP-TRN03 TLS certificate invalid or expiring high passive all
MCPP-TRN04 Plain HTTP not redirected to HTTPS medium passive all
MCPP-TRN05 HSTS header missing low passive all
MCPP-TRN06 Legacy HTTP+SSE transport only medium passive all
MCPP-TRN07 Session identifier carried in a URL high passive all
MCPP-TRN08 Weak Mcp-Session-Id high passive 2025-03-26 to 2025-11-25
MCPP-TRN09 Session ID minted on a stateless revision info passive 2026-07-28
MCPP-TRN10 Weak security headers on discovery endpoints low passive all
MCPP-TRN11 MCP endpoint redirects info passive all

Authentication challenge

ID Title Severity Mode Revisions
MCPP-AUTHN01 MCP tools listed without authentication high passive all
MCPP-AUTHN02 401 without a Bearer challenge medium passive all
MCPP-AUTHN03 No way to discover Protected Resource Metadata high passive 2025-06-18 and later
MCPP-AUTHN04 resource_metadata URL not HTTPS or on another origin medium passive 2025-06-18 and later
MCPP-AUTHN05 Error code in an unauthenticated challenge low passive all
MCPP-AUTHN06 Error responses leak internals medium passive all

Protected Resource Metadata (RFC 9728)

ID Title Severity Mode Revisions
MCPP-PRM01 Protected Resource Metadata not found high passive 2025-06-18 and later
MCPP-PRM02 Protected Resource Metadata malformed medium passive 2025-06-18 and later
MCPP-PRM03 PRM resource does not match the server URL high passive 2025-06-18 and later
MCPP-PRM04 PRM lists no authorization server high passive 2025-06-18 and later
MCPP-PRM05 Authorization server issuer not HTTPS high passive 2025-06-18 and later
MCPP-PRM06 Bearer tokens accepted in the query string high passive 2025-06-18 and later
MCPP-PRM07 PRM does not list scopes low passive 2025-06-18 and later
MCPP-PRM08 PRM resource has a fragment or query high passive 2025-06-18 and later
MCPP-PRM09 Unsafe signed_metadata medium passive 2025-06-18 and later
MCPP-PRM10 offline_access advertised by the resource low passive 2026-07-28
MCPP-PRM11 PRM variants disagree medium passive 2025-06-18 and later

Authorization Server Metadata (RFC 8414 / OIDC)

ID Title Severity Mode Revisions
MCPP-ASM01 Authorization server metadata not found high passive 2025-06-18 and later
MCPP-ASM02 Issuer mismatch high passive all
MCPP-ASM03 Authorization server endpoint not HTTPS high passive all
MCPP-ASM04 PKCE S256 not advertised critical passive all
MCPP-ASM05 PKCE plain method allowed high passive all
MCPP-ASM06 Deprecated grant types enabled high passive all
MCPP-ASM07 Response types incompatible with OAuth 2.1 medium passive all
MCPP-ASM08 Resource indicator (RFC 8707) enforcement not verified info passive 2025-06-18 and later
MCPP-ASM09 Dynamic Client Registration endpoint exposed info passive all
MCPP-ASM10 Dynamic Client Registration without Client ID Metadata Documents low passive 2025-11-25 and later
MCPP-ASM11 Authorization response iss parameter not supported low passive 2025-06-18 and later
MCPP-ASM12 Unsigned (alg=none) client authentication allowed medium passive all
MCPP-ASM13 Default authorization endpoints without metadata (2025-03-26) medium passive 2025-03-26

Client ID Metadata Documents

ID Title Severity Mode Revisions
MCPP-CIMD01 Client ID Metadata Documents not advertised low passive 2025-11-25 and later
MCPP-CIMD02 Client registration strategies info passive all
MCPP-CIMD50 Invalid client identifier URL high lint 2025-11-25 and later
MCPP-CIMD51 Document client_id does not match its URL high lint 2025-11-25 and later
MCPP-CIMD52 Required client metadata missing medium lint 2025-11-25 and later
MCPP-CIMD53 Unsafe redirect URI medium lint 2025-11-25 and later
MCPP-CIMD54 Shared secret in a public metadata document critical lint 2025-11-25 and later
MCPP-CIMD55 Private key material in the document critical lint 2025-11-25 and later
MCPP-CIMD56 Authentication method inconsistent with key material medium lint 2025-11-25 and later
MCPP-CIMD57 Document not served the way authorization servers fetch it medium lint 2025-11-25 and later

Scopes

ID Title Severity Mode Revisions
MCPP-SCP01 Over-broad scopes advertised medium passive 2025-06-18 and later
MCPP-SCP02 Challenge does not name the required scope low passive 2025-11-25 and later
MCPP-SCP04 Resource scopes unknown to the authorization server info passive 2025-06-18 and later

Tool surface

ID Title Severity Mode Revisions
MCPP-TOOL01 Instruction-like text in a tool description high passive all
MCPP-TOOL02 Invisible or bidirectional Unicode in tool metadata high passive all
MCPP-TOOL03 Encoded blob in tool metadata medium passive all
MCPP-TOOL04 Tool description references other tools (shadowing) medium passive all
MCPP-TOOL05 Sensitive paths or suspicious URLs in tool metadata medium passive all
MCPP-TOOL06 Abnormally long tool metadata low passive all
MCPP-TOOL07 Tool annotations contradict the tool's name low passive all
MCPP-TOOL08 Tool accepts arbitrary URLs, paths or code low passive all
MCPP-TOOL09 Confusable or colliding tool names medium passive all
MCPP-TOOL10 Tool metadata nested too deeply to inspect medium passive all

Rug-pull pinning

ID Title Severity Mode Revisions
MCPP-PIN01 Tool surface item added since the baseline medium passive all
MCPP-PIN02 Tool surface item removed since the baseline low passive all
MCPP-PIN03 Tool definition changed since the baseline (rug pull) high passive all
MCPP-PIN04 Target not covered by the baseline info passive all