Fragmented MCP Security Scanners? AVE Project Proposes Unified Vulnerability IDs

SelectionBitter6821 · reddit · 2026-08-06

Different AI security scanners currently give completely different names to the same underlying issues when checking an MCP server, making tracking, auditing, and deduplication highly difficult.

To solve this fragmentation, a developer introduced the AVE (Agentic Vulnerability Enumeration) project. Similar to CVE/CWE in traditional software, it provides stable IDs for behavioral vulnerability classes in AI agents. The project currently contains 70 records, with severity scored against OWASP's AIVSS framework.

Independent cross-testing shows that unrelated tools converge on the identical AVE ID for most overlapping findings without sharing code.

Original post →

More from coding & agent

coding & agent channel →