MCP scanner builders define AVE, a shared ID scheme for agentic vulnerabilities
SelectionBitter6821 · reddit · 2026-07-21
Builders of an MCP security scanner created AVE, a shared ID scheme for agentic vulnerabilities.
The problem: different scanners were finding the same bad behavior on MCP servers but naming it differently, making it impossible to compare results. AVE proposes 59 conservative behavioral classes with stable IDs like AVE-2026-00002 for tool description injection and AVE-2026-00046 for a critical tool hook hijack. It maps to OWASP MCP Top 10, the Agentic Security Initiative Top 10, MITRE ATLAS, and uses OWASP AIVSS scoring. The team is now looking for a second independent implementation.
More from Safety
- Sam Altman is headed to Washington to brief Congress on OpenAI’s GPT-6 line — inductionheads · 2026-07-22
- An MCP server signs every AI agent tool call into a verifiable Merkle chain — Funky_Chicken_22 · 2026-07-22
- AI industry astroturfing roundup tracks the sector’s fake-grassroots problem — ShakeelHashim · 2026-07-22
- New paper defines self-state attacks, showing OS defenses leave four agent-memory cases indistinguishable — Justgototheeffinmoon · 2026-07-22
- Substack starts labeling AI-generated or AI-influenced writing — StewartalsopIII · 2026-07-22
- ControlAI CEO says an international ban on superintelligence is needed to avert extinction risk — zetalyrae · 2026-07-22