OWASP GenAI Security Project · v1.0, Nov 2025 · cheat sheet
Third-Party MCP Servers CheatSheet
For servers you did not write: tool poisoning, prompt injection and memory poisoning risks, with vetting, sandboxing, least privilege and oversight as the mitigations.
Source: genai.owasp.org↗
Other MCP guidance
- Careful Adoption of Agentic AI Services CISA, NSA, ACSC, CCCS, NCSC-UK, NCSC-NZ · advisory guidance
- Managing the cyber risk of agentic AI NCSC-UK · advisory guidance
- MCP specification, 2026-07-28 release Model Context Protocol maintainers · protocol release
- MCP Top 10 OWASP · risk list
- Secure MCP Server Development OWASP GenAI Security Project · guide
- MCP-Security-Checklist SlowMist · checklist