MCPP-TRN10: Weak security headers on discovery endpoints¶
| Family | Transport |
| Default severity | low |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
Metadata documents steer clients to authorization servers. They should not be MIME-sniffable, and must never be readable cross-origin with credentials.
Remediation¶
Serve metadata as application/json with X-Content-Type-Options: nosniff. Public CORS (*) is fine for metadata, but never combine it with Access-Control-Allow-Credentials: true.
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN10"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31