mcp-static-security-suite
SECURITY TEST ARTIFACT: DO NOT USE AS A PRODUCTION MODEL
This repository is part of the Layerfault synthetic security corpus. It is deliberately constructed to contain security-relevant characteristics for scanner testing.
Corpus ID: LF-CORPUS-MCP-0001
Purpose
Static MCP configuration combining plaintext transport, URL credentials, fake env credentials, overbroad scopes, unpinned npx, auto-confirm and contradictory tool annotation.
Direct expected Layerfault rules
LF-MCP-TLS-ABSENTLF-MCP-CREDENTIAL-IN-URLLF-MCP-CREDENTIAL-ENV-EXPOSURELF-MCP-SCOPE-OVERBROADLF-MCP-SUPPLY-CHAIN-AUTO-DOWNLOADLF-MCP-SUPPLY-CHAIN-AUTO-CONFIRMLF-MCP-CONTRADICTORY-ANNOTATIONLF-MCP-TOKEN-PASSTHROUGH-RISK
Candidate rules
These are deliberately plausible targets that remain marked as candidates until the exact Layerfault build used for certification confirms them.
LF-MCP-AUTH-ABSENTLF-MCP-AUTH-METADATA-MISSINGLF-MCP-TOKEN-AUDIENCE-UNBOUNDLF-MCP-ORIGIN-UNRESTRICTED
Negative-control rules
These should remain silent for this corpus item.
- None
Safety
The corpus uses fake secrets, loopback/.invalid network destinations, harmless marker output,
and synthetic model behavior only. It is intended for static scanning and isolated security testing.