MCP scanner builders define AVE, a shared ID scheme for agentic vulnerabilities

SelectionBitter6821 · reddit · 2026-07-21

Builders of an MCP security scanner created AVE, a shared ID scheme for agentic vulnerabilities.

The problem: different scanners were finding the same bad behavior on MCP servers but naming it differently, making it impossible to compare results. AVE proposes 59 conservative behavioral classes with stable IDs like AVE-2026-00002 for tool description injection and AVE-2026-00046 for a critical tool hook hijack. It maps to OWASP MCP Top 10, the Agentic Security Initiative Top 10, MITRE ATLAS, and uses OWASP AIVSS scoring. The team is now looking for a second independent implementation.

Original post →

More from Safety

Safety channel →