🛡 MCP-3OWASP-MCP

Excessive agency

The agent has more tool privileges than the user task requires. Mitigation: per-task capability scoping, explicit confirmation for destructive ops.

Live signal on this risk

7

Ideas classified into this risk

7 submitted ideas

3

#1 (top) risk for

43% of matches

4

Dominant verdict tier

ALREADY EXISTS, YOU'RE LATE

5.4

Mean difficulty

out of 10

8

Avg competitor surface per idea

tools + integrations Claude found

0

Soonest predicted kill

Nobody — it's already dead on arrival (months until obsolete)

Sample verdicts that flagged MCP-3

Mitigation pointer

The agent has more tool privileges than the user task requires. Mitigation: per-task capability scoping, explicit confirmation for destructive ops.

← All 10 OWASP-MCP codes

Got an agent idea you want classified?

Roast My Problem