MCP and Agentic Skills Risk Coverage
What this is. This pack turns fresh MCP and agent-skill risk language into a reviewer-readable coverage artifact. It shows which SecurityRecipes evidence paths and MCP tools answer each OWASP MCP Top 10 and OWASP Agentic Skills Top 10 risk.
SecurityRecipes is positioned as The Secure Context Layer for Agentic AI. That claim needs to cover both sides of the emerging control plane:
- MCP and tools: how an agent discovers, authorizes, describes, invokes, and audits external tools.
- Agentic skills: the behavior packages, rules, hooks, extensions, and workflow instructions that tell agents how to combine tools into real actions.
The MCP and Agentic Skills Risk Coverage Pack maps those two layers
to existing SecurityRecipes artifacts. It is designed for platform teams,
procurement reviewers, GRC, reviewers, and reviewers who need to know
whether the project tracks the newest risks without reading the whole
site. Rechecked September 28, 2026: MCP
2026-07-28
is still current and stateless. The current
security best practices
page is unchanged since the August 27 review. Servers MUST implement
server/discover
and MUST NOT treat possession of a state handle as authentication.
OWASP MCP Top 10 remains
beta / v0.1 with IDs MCP01–MCP10:2025; the project is in Phase 3
pilot testing, with the next planned release in October 2026. OWASP
Agentic Skills Top 10
is a v1.0 (2026 Edition) project in active development. AST05 is now
Untrusted External Instructions; unsafe YAML/JSON loading is treated
under AST04. The pack keeps source-reference id
mcp-security-best-practices-2025 as a labeled 2025-06-18 prior
revision and uses mcp-security-best-practices-2026-07-28 for current
controls.
Generated artifact
- Source model:
data/assurance/mcp-risk-coverage-profile.json - Generator:
scripts/generate_mcp_risk_coverage_pack.py - Evidence pack:
data/evidence/mcp-risk-coverage-pack.json - MCP tool:
recipes_mcp_risk_coverage_pack
Regenerate and validate the pack:
python3 scripts/generate_mcp_risk_coverage_pack.py
python3 scripts/generate_mcp_risk_coverage_pack.py --check
Workflow at a glance
MCP and Agentic Skills Risk Coverage workflow
Map MCP and agentic-skill risks to preventive, detective, response, evidence, and ownership controls and expose coverage gaps.
Signal
Inventory risk surfaces
List servers, connectors, tools, resources, prompts, skills, clients, transports, auth, data, side effects, and deployments.
Scope
Select risk scenarios
Map authorization, state-handle hijacking, injection, untrusted external skill instructions, exfiltration, supply chain, tool drift, confused deputy, unregistered server/discover, tenancy, destructive action, and availability risks.
Decision
Bind existing controls
Link registry, gateway, auth, context, egress, skill, telemetry, receipt, incident, eval, and owner evidence.
Action
Assess effective coverage
Classify prevention, detection, containment, recovery, assurance, test status, freshness, and residual risk per scenario.
Proof
Publish coverage actions
Prioritize missing controls, owners, SLAs, accepted risks, tests, and readiness gates.
Decision gate
Does every material MCP/skill risk have current preventive, detective, containment, recovery, and evidence coverage?
Accept the bounded residual risk and monitor the declared controls.
Hold readiness and remediate critical uncovered or stale risk scenarios.
Evidence to retain
- surface/risk inventory
- control-to-risk mappings
- coverage and residual-risk assessment
Expected outputs
- MCP risk coverage pack
- prioritized control backlog
- risk acceptance list
Why this matters
MCP gives agents a common way to reach tools and context. Skills give agents reusable workflows for using those tools. Enterprise failure modes now cross both layers: a safe-looking tool can be poisoned, a safe looking skill can over-request authority, and a well-scoped context package can become unsafe when it is handed to a different agent, model, or runtime.
This pack makes that coverage explicit:
| Risk surface | SecurityRecipes evidence |
|---|---|
| MCP token, scope, and authorization failures | MCP Authorization Conformance, Gateway Policy, Elicitation Boundary, Agent Identity Ledger, Entitlement Review |
| Tool poisoning and drift | MCP Tool Risk Contract, MCP Tool Surface Drift Sentinel, Connector Intake, Context Poisoning Guard |
| Local server and command execution | MCP STDIO Launch Boundary, Agent Skill Supply Chain, Action Runtime Pack |
| Shadow MCP servers | Connector Intake, Connector Trust, STDIO Launch Boundary, SOC Detection Pack, Agentic System BOM |
| Context injection and over-sharing | Secure Context Trust Pack, Context Poisoning Guard, Context Egress Boundary, Memory Boundary, Handoff Boundary |
| Malicious or over-privileged skills | Agent Skill Supply Chain, Gateway Policy, Identity Ledger, Entitlement Review, Action Runtime Pack |
| Untrusted external skill instructions | Agent Skill Supply Chain, Context Poisoning Guard, Secure Context Trust Pack, Measurement Probes, Red-Team Drills |
| Skill isolation, scanning, and update drift | Browser Agent Boundary, Measurement Probes, Red-Team Drills, Tool Surface Drift |
| Governance and trust review evidence | Enterprise Trust Center Export, Agentic System BOM, Telemetry Contract, SOC Detection Pack, Run Receipts |
MCP examples
Get the full coverage summary:
{}
Inspect one risk:
{
"risk_id": "MCP03"
}
Inspect one standard:
{
"standard_id": "owasp-agentic-skills-top-10-2026"
}
Find every risk covered by one capability:
{
"capability_id": "agent-skill-supply-chain-pack"
}
Filter for critical risks:
{
"risk_tier": "critical"
}
Readiness gate
The open pack proves that SecurityRecipes understands the current MCP and skills risk landscape. The trusted-source layer is the natural hosted version of those controls:
- live MCP connector discovery and admission,
- tool-surface and annotation drift monitoring,
- skill registry scanning and permission review,
- endpoint launch policy for local MCP servers,
- hosted action firewall APIs,
- signed run and approval receipts,
- telemetry redaction validation,
- customer-private trust-center exports.
That is the path from useful public knowledge to a production control plane a frontier lab, AI coding platform, cloud provider, or security vendor could buy.
Source anchors
Review and regenerate the pack when these sources change:
- OWASP MCP Top 10
- OWASP Agentic Skills Top 10
- Model Context Protocol Security Best Practices
- NIST AI RMF Generative AI Profile
- CISA Secure by Design