| Check | Level | Result | Details |
|---|---|---|---|
| LIFE-01 | MUST | ✗ FAIL |
initialize returns protocolVersion, capabilities and serverInfo
initialize result missing: serverInfo
Fix: Return protocolVersion, capabilities and serverInfo in the initialize result.
|
| LIFE-02 | SHOULD | ! WARN |
server negotiates the newest handshake revision (2025-11-25)
negotiated 2025-03-26; the newest handshake revision is 2025-11-25 — a newer server SDK will negotiate it
Fix: Upgrade the server SDK to a release that negotiates the newest initialize-handshake revision (2025-11-25).
|
| LIFE-03 | MUST | ✓ PASS |
server answers tools/list after the initialized notification
tools/list returned 4 tool(s) across 1 page(s) after initialized
|
| LIST-01 | MUST | ✓ PASS |
tools/list pagination terminates (no cursor loop)
single page, no pagination cursor
|
| RPC-01 | MUST | ✓ PASS |
unknown method gets a JSON-RPC error response
unknown method rejected with error code -32603
|
| RPC-02 | SHOULD | ✗ FAIL |
unknown method error code is -32601 (method not found)
expected -32601, got -32603
Fix: Use JSON-RPC 2.0 code -32601 when rejecting unknown methods.
|
| RPC-03 | MUST | ✗ FAIL |
malformed tools/call params are rejected with an error
malformed tools/call params returned a result instead of an error
Fix: Validate tools/call params and return an error when required fields are missing.
|
| TOOL-01 | MUST | ✓ PASS |
every tool has a non-empty name and an inputSchema
all 4 tools have a name and an inputSchema
|
| TOOL-02 | SHOULD | ! WARN |
every tool has a non-empty description
undocumented tools: no_docs_tool
Fix: Add a one-line description to every tool so agents can choose correctly.
|
| TOOL-03 | MUST | ✗ FAIL |
every tool inputSchema compiles as JSON Schema
no_docs_tool: 'strang' is not valid under any of the given schemas
Fix: Fix the inputSchema so it validates under JSON Schema draft 2020-12.
|
| TOOL-04 | MUST | ✓ PASS |
calling a nonexistent tool is rejected
rejected as JSON-RPC error (code -32602)
|
| TOOL-05 | MUST | ✗ FAIL |
a call missing required arguments is rejected
lookup_account called with empty args returned a normal result (silent success)
Fix: Validate arguments against the inputSchema and reject calls missing required params.
|
| TOOL-06 | MUST | – SKIP |
declared outputSchemas compile as JSON Schema
no tool declares an outputSchema
|
| TOOL-08 | MUST | – SKIP |
observed structuredContent matches the declared outputSchema
no tool declares an outputSchema
|
| TOOL-07 | SHOULD | ! WARN |
declared input constraints are enforced
declared constraints not enforced — lookup_account: minimal invalid input (account_id=12345) was answered normally; lookup_account: minimal invalid input (missing required 'account_id') was answered normally; fetch_url: minimal invalid input (url=12345) was answered normally; fetch_url: minimal invalid input (missing required 'url') was answered normally
Fix: Validate tool arguments against the declared inputSchema; inputs that violate it must be rejected, not answered normally.
|
| RES-01 | MUST | – SKIP |
advertised resources capability serves resources/list
resources capability not advertised
|
| RES-02 | MUST | – SKIP |
every resource carries a uri and a name
resources/list unavailable
|
| RES-03 | MUST | – SKIP |
resources/read returns contents for an advertised resource
no listed resource to read
|
| RES-04 | MUST | – SKIP |
resources/list pagination terminates (no cursor loop)
no surface to paginate
|
| PROMPT-01 | MUST | – SKIP |
advertised prompts capability serves prompts/list
prompts capability not advertised
|
| PROMPT-02 | MUST | – SKIP |
every prompt has a name and well-formed argument metadata
prompts/list unavailable
|
| PROMPT-03 | MUST | – SKIP |
prompts/get rejects a call missing required arguments
no prompt declares required arguments
|
| PROMPT-04 | MUST | – SKIP |
prompts/list pagination terminates (no cursor loop)
no surface to paginate
|
| CAP-02 | SHOULD | ✓ PASS |
declared capabilities match served features (resources)
capabilities.resources not declared and resources/list not served
|
| CAP-03 | SHOULD | ✓ PASS |
declared capabilities match served features (prompts)
capabilities.prompts not declared and prompts/list not served
|
| HYG-01 | MUST | ✗ FAIL |
stdout carries only JSON-RPC messages
1 non-JSON-RPC stdout line(s); first 3: Starting bad server...
Fix: Send logs and banners to stderr; stdout is reserved for the protocol stream.
|
| CAP-01 | SHOULD | ✓ PASS |
declared capabilities match served features (tools)
capabilities.tools declared and tools/list served
|
| Check | Domain | Result | Details |
|---|---|---|---|
| SEC-01 | MCP-INPUT-01 | ✗ FAIL |
no prompt-injection patterns in tool descriptions
lookup_account: "ignore previous instructions"; lookup_account: "always call this tool first"
Fix: Rewrite descriptions to describe tool behaviour; remove instructions aimed at the model.
|
| SEC-02 | MCP-INPUT-01 | ✗ FAIL |
no invisible or bidi control characters in tool metadata
lookup_account.description: U+200B
Fix: Strip zero-width, bidi-control and tag-block characters from tool names and descriptions.
|
| SEC-03 | MCP-LOG-02 | ✗ FAIL |
no secret-looking strings in tool metadata
lookup_account: sk-demo123… (27 chars)
Fix: Remove embedded credentials from descriptions/schemas and rotate any real keys.
|
| SEC-04 | MCP-INPUT-02 | ! WARN |
injection-surface string params carry constraints
unconstrained injection-surface params: run_shell.cmd, fetch_url.url
Fix: Add enum, pattern or maxLength to path/url/command-like string params.
|
| SEC-05 | MCP-INPUT-01 | ✓ PASS |
tool descriptions stay under 2000 chars
longest description 142 chars across 4 tools
|
| SEC-06 | MCP-EXEC-01,MCP-EXEC-02 | ! WARN |
no tool advertises unconstrained arbitrary execution
exec-style tools with free-form string params: run_shell(cmd)
Fix: Replace free-form command/shell tools with parameterized, allowlisted operations (MSSS MCP-EXEC-01/02).
|
L1: 0/2 auto-assessable controls met · 4 require manual review. Mapped against MSSS v0.1 (control-level mapping v2.0 (2026-01-20)): 3 of 24 controls are auto-assessable from this audit's deterministic checks (partial = evidence ran clean but cannot prove the control on its own); the remaining 21 need deployment, code or process evidence and are marked manual review — never assessed by this tool.
| Control | Domain | Level | Result | Title |
|---|---|---|---|---|
| MCP-EXEC-01 | Execution | L1 | – manual review |
Prohibition of Shell Execution
SEC-06 flags advertised arbitrary-exec tools, but proving the absence of shell invocation requires source review.
|
| MCP-FS-01 | Filesystem | L1 | – manual review |
Path Allowlisting and Canonical Resolution
|
| MCP-FS-02 | Filesystem | L1 | – manual review |
Symlink Resolution Validation
|
| MCP-NET-01 | Network | L1 | – manual review |
URL Validation and SSRF Mitigation
|
| MCP-INPUT-01 | Input Validation | L1 | ✗ gap |
JSON Schema Validation
Evidence checks: TOOL-01, TOOL-03, RPC-03, TOOL-05, SEC-01, SEC-02, SEC-05
failing checks: RPC-03, SEC-01, SEC-02, TOOL-03, TOOL-05
Auto-assessed from advertised schemas (present and valid), live rejection probes, and the tool-metadata poisoning scan.
|
| MCP-LOG-02 | Logging | L1 | ✗ gap |
Secret Redaction in Logs
Evidence checks: SEC-03
failing checks: SEC-03
Supporting evidence only: SEC-03 scans advertised tool metadata for secret-like strings; server log output is not inspected, so a clean scan cannot prove log redaction (a leak still proves a gap).
|
| MCP-SUPPLY-02 | Supply Chain | L2 | – manual review |
Trusted Package Sources
|
| MCP-INPUT-02 | Input Validation | L2 | ◐ partial |
Input Bounds Enforcement
Evidence checks: SEC-04
SEC-04: unconstrained injection-surface params: run_shell.cmd, fetch_url.url
Auto-assessed from advertised schema constraints (enum/pattern/maxLength); runtime payload limits are not probed.
|
| MCP-INPUT-03 | Input Validation | L2 | – manual review |
Timeout Enforcement
|
| MCP-NET-03 | Network | L2 | – manual review |
TLS Enforcement
MSSS marks this N/A for stdio-only deployments with no network access.
|
| MCP-EXEC-02 | Execution | L2 | – manual review |
Command Allowlisting
See the SEC-06 advisory for advertised command tools; allowlist verification requires source review.
|
| MCP-EXEC-03 | Execution | L2 | – manual review |
Argument Separator Usage
|
| MCP-AUTHZ-01 | Authorization | L3 | – manual review |
OAuth Token Delegation
MSSS marks this N/A for stdio transport with OS-level user isolation.
|
| MCP-AUTHZ-02 | Authorization | L3 | – manual review |
Per-Tool Scope Definition
|
| MCP-AUTHZ-03 | Authorization | L3 | – manual review |
Least Privilege Tool Design
|
| MCP-AUTHZ-04 | Authorization | L3 | – manual review |
Resource-Based Access Control
|
| MCP-LOG-01 | Logging | L3 | – manual review |
Comprehensive Audit Logging
|
| MCP-DEPLOY-01 | Deployment | L3 | – manual review |
Container Hardening
|
| MCP-FS-03 | Filesystem | L4 | – manual review |
Filesystem Sandboxing
|
| MCP-SUPPLY-01 | Supply Chain | L4 | – manual review |
Package Integrity Verification
|
| MCP-DEPLOY-03 | Deployment | L4 | – manual review |
Resource Limits and Rate Limiting
|
| MCP-NET-02 | Network | L4 | – manual review |
Egress Traffic Filtering
|
| MCP-DEPLOY-02 | Deployment | L4 | – manual review |
System Call Filtering (seccomp/AppArmor)
|
| MCP-DEPLOY-04 | Deployment | L4 | – manual review |
Runtime Integrity Monitoring
Future control in MSSS v0.1 — implementation details TBD upstream.
|
Control taxonomy from the MCP Server Security Standard (MSSS), CC BY-SA 4.0, mcp-security-standard.org.