Conformance

Runnable evidence, not a checklist.

Every row on this page is a check that drives the real engine, proxy call path, tool-integrity scanner, redaction, audit chain, approvals, rate limiter and metrics against a bundled policy with one rule per mechanism. Nothing in the decision path is mocked. Generated by aggrete conformance from aggrete 0.10.0 on 2026-09-18.

$pip install aggrete && aggrete conformance
OWASP MCP Top 10

7 pass · 2 partial

1 not applicable, 0 failing, of 10 controls.

OWASP Top 10 for Agentic Applications

6 pass · 2 partial

2 not applicable, 0 failing, of 10 controls.

CoSAI MCP Security v2.0

13 pass · 1 partial

0 not applicable, 0 failing, of 14 controls.

AIUC-1

16 pass · 2 partial

0 not applicable, 0 failing, of 18 controls.

The sixteen checks

Each prints the evidence it found. --format json exits non-zero on any failure, so this runs in CI; --format md is what an auditor gets.

checkwhat it provesresultevidence
C01Refuses before fetching: a walled domain is never contactedpassplan__read refused at stage=pre, upstream calls=0, audit rule=CONF-WALL
C02Catches the combination: three individually-fine reads, the third refusedpassfinance + hr allowed; ops refused pre-fetch by CONF-JOIN with entity overlap
C03Prompt-injection shield: no write after reading untrusted contentpasswrite allowed before taint; after an untrusted read both the write and the private-repo read are refused (CONF-FLOW)
C04Argument-level rules: the same tool is fine or forbidden by what it is askedpasscrm__export scope=team allowed; scope=all refused pre-fetch (CONF-ARG)
C05Redaction: SSNs and emails masked before the model sees the resultpassresult masked; audit redacted={'email': 2, 'ssn': 1}
C06Inbound secrets: a credential in tool arguments is never forwardedpassAWS key in arguments refused, upstream not called, audit rule=inbound-secret
C07Tool integrity: poisoned descriptions blocked, rug pulls flaggedpasshidden instruction -> block; definition changed after pin -> alert (rug pull)
C08Rate limit: per-user ceiling, refused with an audit rowpass6th call in the window refused, audit rule=rate-limit
C09Audit chain: every decision hash-chained; tampering is detected at the linepass3 rows chained and intact; editing line 2 is reported as the first bad line
C10Identity from the token; HTTP refuses to start without auth; caller tokens never go upstreampassemail claim -> identity; streamable-http without auth: SystemExit; upstream headers come from config, not the caller
C11Human-in-the-loop: a held call, an approval, a retry that succeeds, all auditedpassheld (request 6192934eac), approved by the clause owner, retry allowed with purpose on the audit row
C12Hidden tools: what a person can never call is never listedpasswalled and blocked domains hidden for non-allowed users; approval-gated tools remain visible
C13Post-call rules: small groups, self-comparison and budgets refuse the resultpassresults describing 2 people, self+colleague, and 6 distinct customers all refused post-call
C14Purpose binding: a granted purpose opens a scoped, audited windowpassrefused, then allowed under a granted purpose that is stamped on the audit row
C15Dry run: 'would this be allowed?' answered without fetchingpassthree-step plan reported REFUSED at step 3 by CONF-JOIN; upstream calls=0
C16Observability: metrics and OTLP records derive from the same audit rowspassPrometheus counters and an OTLP log record produced from the audit rows

OWASP MCP Top 10 (2025, beta)

Source: https://owasp.org/www-project-mcp-top-10/

controltitlestatusshown bynote
MCP01Token Mismanagement & Secret ExposurepassC06, C05, C10the proxy holds upstream credentials; callers' tokens are never forwarded (C10)
MCP02Privilege Escalation via Scope CreeppassC01, C12, C04
MCP03Tool PoisoningpassC07
MCP04Software Supply Chain Attacks & Dependency TamperingpartialC07rug-pull detection by fingerprint; package-level supply chain is out of scope
MCP05Command Injection & ExecutionpartialC04, C06argument-level rules and secret blocking constrain what reaches a server; injection inside the server is the server's job
MCP06Prompt Injection via Contextual PayloadspassC03, C07
MCP07Insufficient Authentication & AuthorizationpassC10, C01, C12
MCP08Lack of Audit and TelemetrypassC09, C16
MCP09Shadow MCP Serversn/adeployment property: make the proxy the only allowed server (docs/DEPLOY.md, managed client allow-lists)
MCP10Context Injection & Over-SharingpassC02, C13, C05

OWASP Top 10 for Agentic Applications (2026)

Source: https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/

controltitlestatusshown bynote
ASI01Agent Goal HijackpassC03, C07
ASI02Tool Misuse & ExploitationpassC04, C08, C15
ASI03Identity & Privilege AbusepassC10, C01, C12
ASI04Agentic Supply Chain VulnerabilitiespartialC07
ASI05Unexpected Code Executionn/anot a proxy concern; see MCP05
ASI06Memory & Context PoisoningpassC03, C05
ASI07Insecure Inter-Agent Communicationn/aA2A is out of scope for an MCP proxy
ASI08Cascading FailurespartialC08, C16
ASI09Human-Agent Trust ExploitationpassC11, C15
ASI10Rogue AgentspassC02, C13, C08

CoSAI MCP Security v2.0 (Aug 2026) threats

Source: https://github.com/cosai-oasis/ws4-secure-design-agentic-systems/blob/main/whitepapers/model-context-protocol-security.md

controltitlestatusshown bynote
T2Tool PoisoningpassC07
T3Full Schema PoisoningpassC07
T4Resource Content PoisoningpassC03
T8Confused Deputy (OAuth proxy)passC10
T9Insecure Human-in-the-LooppassC11
T11Prompt InjectionpassC03
T13Consent / User-Approval FatiguepartialC11, C15approvals are per rule with a TTL, not per call
T14Resource Exhaustion & Denial of WalletpassC08
T15Invisible Agent ActivitypassC09, C16
T16Credential / Token TheftpassC06, C10
T20Excessive Permissions / OverexposurepassC01, C12, C13
T23Insufficient Integrity CheckspassC07, C09
T24Data Exfiltration & CorruptionpassC03, C02, C05
T34Lack of ObservabilitypassC16, C09

AIUC-1 (live IDs, Sept 2026)

Source: https://standard.aiuc-1.com/

controltitlestatusshown bynote
A003.1Data access scopingpassC01, C02, C13
A003.2Agent identity managementpassC10
A003.3Agent access & permissions managementpartialC11, C12time-limited approvals; per-tool OAuth scopes are on the roadmap
A008.1Secrets detection in user inputspassC06
A008.5Secrets redaction in logs & artifactspassC05
B006.1Agent service access restrictionspassC07, C12
B006.2Agent security monitoring & alertingpassC09, C16
B006.3Execution-level safeguardspartialC07, C01
B008.1API & agentic interface authenticationpassC10
B008.3Agentic interface data integritypassC07, C06
C007Flag high risk outputs for human reviewpassC11
D003.1Tool authorization & validationpassC01, C04
D003.2Rate limits for toolspassC08
D003.3Tool call logpassC09
D003.4Human-approval workflowspassC11
E009.1Third-party access monitoringpassC09, C16
E015.2AI agent logging implementationpassC09
E015.4Log integrity protectionpassC09

Black-box: score any gateway

The same scenarios also run from the outside, over real MCP, against any endpoint. Nothing in the suite knows how a gateway words a refusal: every fixture payload carries a unique marker, and a scenario passes when the forbidden marker never reaches the client. Each has a control step, so a target that simply blocks everything scores inconclusive, not pass.

# 1. front this fixture connector with the gateway under test
python -m aggrete._mockco --profile fixture

# 2. run the scenarios against the gateway
aggrete conformance --url https://gateway.example/mcp --token "$TOKEN"
aggrete conformance --stdio "my-gateway --config gw.yaml"
aggrete conformance --self                 # Aggrete itself, as the reference
aggrete conformance --write-fixture ./fx   # the reference config and policy

Two real runs, side by side: Aggrete in front of the fixture, and the fixture with nothing in front of it. The second column is the suite's own sanity check, and what an ungoverned MCP setup looks like.

scenariowhat it testsaggretenothing in frontwhat happened with nothing in front
B00Fixture tools are reachable through the targetpasspass9 tools listed
B01Combination: budget + personnel + rota about the same peoplepassfailall three reads returned: the combination formed
B02Exfiltration: no write after reading untrusted contentpassfailthe write went through after an untrusted read
B03Arguments: the same tool allowed or refused by what it is askedpassfailscope=all returned the whole base
B04Redaction: an SSN in a result never reaches the clientpassfailthe SSN arrived in clear
B05Inbound secrets: a credential in arguments never reaches the upstreampassfailthe upstream received and echoed the key
B06Tool poisoning: a tool with hidden instructions is not usablepassfailthe poisoned tool ran
B07Walls: a tool this person may never call is hidden or refusedpassfailthe walled document was returned
B08Refusals explain themselves (rule and reason, not a bare error)passinfo0 of 0 refusals carried a readable reason

Controls the outside cannot see (audit integrity, identity handling, approvals) are reported as "not observable" rather than guessed. Those are covered by the sixteen in-process checks above.

Reading the statuses. Pass: every mapped check held against the real components. Partial: the checks hold, but the control is broader than a policy proxy can enforce, and the note says what is out of scope. n/a: a server-side or deployment property, such as making the proxy the only permitted server.
Open source

Deterministic policy for what AI can reach and do.

Aggrete is Apache-2.0. No model in the decision path.

Star on GitHub How it works