Fragmented MCP Security Scanners? AVE Project Proposes Unified Vulnerability IDs
SelectionBitter6821 · reddit · 2026-08-06
Different AI security scanners currently give completely different names to the same underlying issues when checking an MCP server, making tracking, auditing, and deduplication highly difficult.
To solve this fragmentation, a developer introduced the AVE (Agentic Vulnerability Enumeration) project. Similar to CVE/CWE in traditional software, it provides stable IDs for behavioral vulnerability classes in AI agents. The project currently contains 70 records, with severity scored against OWASP's AIVSS framework.
Independent cross-testing shows that unrelated tools converge on the identical AVE ID for most overlapping findings without sharing code.
More from coding & agent
- Cloudflare Launches Kitesurf: A Container-less Browser for AI Agents — irvinebroque · 2026-08-06
- DSPy Launches Flex Module: Optimizing Both Prompts and Code Automatically — lateinteraction · 2026-08-06
- Agentic Harness Matters More Than Models: Big Finance AI Boost — eyishazyer · 2026-08-06
- AI Agents Can Reproduce Papers, But Can They Generate Ideas? — ChenhaoTan · 2026-08-06
- Rewriting SENPAI Agent with OpenHands SDK Breaks 200 TPS Decode Record — morgymcg · 2026-08-06
- Work SDK Tackles Agent Blind Retries with Idempotent Commits for Issue Trackers — its_artur1 · 2026-08-06