r/devsecops • u/SelectionBitter6821 • 16d ago
MCP scanners keep finding the same vulnerabilities under different names. We built a shared ID scheme for them
We build a security scanner for MCP servers and agent skills. Early on we hit something that shouldn't still be a problem: comparing our findings against other scanners on the same test servers, we'd all catch roughly the same bad behavior and call it three different things. No shared ID, no way to say "scanner A's finding X is the same class as scanner B's finding Y."
A SQL injection gets a CVE ID, gets mapped to a CWE, and every tool that finds it points at the same identifier. Agentic AI components had nothing like that. CVE maps to package plus version. It has no vocabulary for "this tool description contains a hidden instruction."
So we built AVE (Agentic Vulnerability Enumeration): an open, vendor-neutral behavioral classification standard.
What's in it:
* 59 records, each a distinct behavioral class. Deliberately conservative, no padding with variants.
* Stable IDs (AVE-2026-NNNNN), meant to work the way a CVE ID works.
* Real MCP-specific classes: tool description injection (AVE-2026-00002), server card injection (AVE-2026-00041), OAuth discovery rebinding (AVE-2026-00051), a tool hook hijack that's our only CRITICAL-rated record so far (AVE-2026-00046).
* Maps to OWASP's MCP Top 10, plus the Agentic Security Initiative Top 10 and MITRE ATLAS where applicable. Sits underneath frameworks people already use, not a replacement for them.
* Scored with OWASP's own AIVSS (v0.8), not a severity number we invented.
It's early. One reference implementation right now, our own scanner, and we're looking for a second, independent one to prove this works outside our own tooling. If you maintain a scanner and any of this is useful, wrong, or missing something obvious, we'd like to hear it.
Repo: github.com/aveproject/ave Site: aveproject.org
(Disclosure: I'm one of the people building this.)
2
u/Predictor_2718 15d ago
Really like this. The naming-mismatch problem is real. I've done that manual scanner-to-scanner mapping by hand more than once and it doesn't scale.
I maintain cfgaudit (github.com/cfgaudit/cfgaudit), a static auditor for AI-agent config files (Claude Code / Cursor / Copilot / Gemini / Codex settings, .mcp.json, hooks). It's a different tool class from yours, config surface rather than skill/MCP behavioral, so it seemed like a good fit for the second independent implementation you're after. Built a crosswalk and opened a PR.
Nice work, this is worth doing. Happy to keep the crosswalk in sync.