Skip to content

MCPP-SCP01: Over-broad scopes advertised

Family Scopes
Default severity medium
Confidence medium
Mode passive (default scan)
Spec revisions 2025-06-18 and later

Why it matters

Wildcard or administrative scopes (*, admin, all, files:*) defeat least privilege: every client gets a token able to do everything, and a stolen token is a full compromise. MCP's scope selection and step-up model assumes fine-grained scopes.

Remediation

Split permissions into narrow scopes (e.g. notes:read, notes:write), advertise the minimum in the challenge, and use 403 insufficient_scope step-up for the rest.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-SCP01"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31