MCPP-TRN05: HSTS header missing¶
| Family | Transport |
| Default severity | low |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
Without Strict-Transport-Security, a network attacker can downgrade the first connection of browser-based clients to plain HTTP.
Remediation¶
Send Strict-Transport-Security: max-age=31536000; includeSubDomains on every HTTPS response.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN05"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31