{"repo":"mcp-security-standard/mcp-server-security-standard","free":true,"listed":false,"github":"https://github.com/mcp-security-standard/mcp-server-security-standard","clone":"git clone https://github.com/mcp-security-standard/mcp-server-security-standard.git","description":"MCP Server Security Standard (MSSS): an open, testable security control standard for certifying MCP servers, with levels, evidence requirements, and reporting schemas.","language":null,"stars":74,"topics":["cybersecurity","mcp","mcp-security","mcp-server","standard"],"license":"CC-BY-SA-4.0","category":"mcp-servers","readme_excerpt":"MCP Server Security Standard (MSSS) [![CC BY-SA 4.0][cc-by-sa-shield]][cc-by-sa] About MSSS The Model Context Protocol enables AI models to interact with external systems through tools, resources, and prompts. As adoption accelerates, critical vulnerabilities have emerged: command injection, path traversal, SSRF attacks, and supply chain compromises. MSSS provides: - 24 security controls across 8 domains - 4 compliance levels (L1-Essential, L2-Development, L3-Production, L4-Maximum Assurance) - Risk-based level selection framework inspired by NIST CSF, OWASP ASVS, and CIS Controls - 6 deployment profiles (Local Dev, Team Server, Internet-Facing, etc.) - Evidence-based verification with clear acceptance criteria - Machine-readable reporting through JSON schemas Compliant Platforms The following platforms have adopted the MCP Server Security Standard: - Platform Description Status --- ---------- ------------- -------- MCP-Hub MCP server directory and marketplace — discover, publish, and manage MCP-compliant servers ✅ Compliant Are you implementing MSSS? Open an issue or submit a PR to be listed here. Current Status - v0.1.0 Released: January 15, 2026 (Community Review Draft) What's Included - Core standard framework (msss.md) - 6 deployment profiles defined - Comprehensive threat model - 23 fully documented security controls - JSON reporting schemas - i18n framework for translations Areas for Community Contribution - Implementation examples for common frameworks - Automated ver","default_branch":null,"files":null,"tree":[],"storefront":"/r/mcp-security-standard","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mcp-security-standard/mcp-server-security-standard/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}