mcp-static-security-suite

SECURITY TEST ARTIFACT: DO NOT USE AS A PRODUCTION MODEL

This repository is part of the Layerfault synthetic security corpus. It is deliberately constructed to contain security-relevant characteristics for scanner testing.

Corpus ID: LF-CORPUS-MCP-0001

Purpose

Static MCP configuration combining plaintext transport, URL credentials, fake env credentials, overbroad scopes, unpinned npx, auto-confirm and contradictory tool annotation.

Direct expected Layerfault rules

  • LF-MCP-TLS-ABSENT
  • LF-MCP-CREDENTIAL-IN-URL
  • LF-MCP-CREDENTIAL-ENV-EXPOSURE
  • LF-MCP-SCOPE-OVERBROAD
  • LF-MCP-SUPPLY-CHAIN-AUTO-DOWNLOAD
  • LF-MCP-SUPPLY-CHAIN-AUTO-CONFIRM
  • LF-MCP-CONTRADICTORY-ANNOTATION
  • LF-MCP-TOKEN-PASSTHROUGH-RISK

Candidate rules

These are deliberately plausible targets that remain marked as candidates until the exact Layerfault build used for certification confirms them.

  • LF-MCP-AUTH-ABSENT
  • LF-MCP-AUTH-METADATA-MISSING
  • LF-MCP-TOKEN-AUDIENCE-UNBOUND
  • LF-MCP-ORIGIN-UNRESTRICTED

Negative-control rules

These should remain silent for this corpus item.

  • None

Safety

The corpus uses fake secrets, loopback/.invalid network destinations, harmless marker output, and synthetic model behavior only. It is intended for static scanning and isolated security testing.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Collection including LayerFault/mcp-static-security-suite