MCPP-PRM09: Unsafe signed_metadata¶
| Family | Protected Resource Metadata (RFC 9728) |
| Default severity | medium |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | 2025-06-18 and later |
Why it matters¶
Signed metadata takes precedence over plain values (RFC 9728 ยง2.2). It MUST be a JWS with an iss claim; alg=none, or claims that contradict the JSON, defeat its purpose.
Remediation¶
Sign metadata with an asymmetric algorithm, include iss, and keep the signed claims identical to the plain document (or drop signed_metadata).
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-PRM09"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31