SAFE-MCP

Security Analysis Framework for Evaluation of MCP

80+ Techniques
14 Tactic Categories
ATT&CK Mappings

SAFE-MCP is a specification for MCP attack vectors and mitigation techniques, initiated by astha.ai and now part of the OpenID and Linux Foundations, driven by community collaboration.

Proudly part of

Linux FoundationOpenID Foundation

Initiated by Astha.ai

Who It's For

Role-specific outcomes and quickstart paths

Security Engineers & Red Teams

Plan threat modeling & pentesting

Understand what attacks are possible in MCP architectures and systematically plan your security assessments.

Threat Modeling Guide

Developers / System Architects

Embed mitigations early in tool/server pipelines

Identify which techniques apply to your MCP servers or tool pipelines and integrate security from the start.

Developer Quickstart

Auditors & Researchers

Evaluate maturity & map to existing frameworks

Map SAFE-MCP across existing security frameworks and systematically evaluate MCP system maturity.

Maturity Checklist

Framework Overview

SAFE-MCP adapts the proven MITRE ATT&CK methodology specifically for Model Context Protocol environments, providing a structured approach to understanding and mitigating security risks in agent-tool orchestration.

The framework covers 14 tactic categories and 80+ techniques, each with actionable mitigation and detection guidance.

14 Tactic Categories

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationImpactCommand & ControlResource DevelopmentReconnaissance
Browse All Tactics & Techniques

Featured Techniques

What is SAFE-MCP?

A comprehensive security framework built on industry-proven methodologies

1

MITRE ATT&CK Adaptation

SAFE-MCP adapts the MITRE ATT&CK methodology specifically for MCP environments, providing a structured catalog of adversarial tactics, techniques, and procedures (TTPs) tuned for agent-tool orchestration.
Explore on GitHub
2

Framework Coverage

The framework currently defines 14 tactic categories that mirror the MITRE ATT&CK axes, and supports 80+ techniques across those tactics (e.g. SAFE-T1001 Tool Poisoning, SAFE-T1102 Prompt Injection)
Explore on GitHub
3

Guidance & Mappings

Every technique in SAFE-MCP includes mitigation and detection guidance, along with mappings to existing MITRE ATT&CK techniques when applicable.
Explore on GitHub

Explore our complete framework documentation and contribute to the community

View Full Documentation