OWASP Top 10 for Agentic AI security MCP server — prompt injection detection, tool poisoning, excessive agency, data leakage assessment
OWASP Top 10 for Agentic AI security MCP server — prompt injection detection, tool poisoning, excessive agency, data leakage assessment. That is what the owasp agentic mcp mcp server brings to an AI assistant: the same capability, reachable through the Model Context Protocol rather than a separate app or dashboard.
The server publishes 5 tools. What each one is for:
full_agent_scan — Full OWASP Agentic Top 10 security scanassess_agentic_security — Assess against specific OWASP Agentic categoriescheck_prompt_injection — Test for prompt injection vulnerabilitiescheck_tool_poisoning — Check for tool poisoning riskscheck_excessive_agency — Assess agency level vs minimum required@smithery/cli on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.
This sits in the monitoring and observability group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Owasp Agentic MCP's toolset — full_agent_scan, assess_agentic_security, check_prompt_injection and 2 more — is a fair guide to whether it matches your workflow. It is maintained by csoai-org; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| full_agent_scan | Full OWASP Agentic Top 10 security scan |
| assess_agentic_security | Assess against specific OWASP Agentic categories |
| check_prompt_injection | Test for prompt injection vulnerabilities |
| check_tool_poisoning | Check for tool poisoning risks |
| check_excessive_agency | Assess agency level vs minimum required |
{
"mcpServers": {
"owasp-agentic": {
"command": "npx",
"args": ["-y", "@smithery/cli"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Give your coding agent the full DevTools toolbox: traces, network, console, heap snapshots and Lighthouse.
Dashboards, Prometheus and Loki queries, incidents and alerts — observability by conversation.
Errors with full context — stack traces, issue triage and AI-powered root-cause analysis from Sentry's server.
Enables enhanced web research capabilities for large language models through intelligent search queuing and advanced content extraction.
Automates browser interactions and enables Large Language Models (LLMs) to interact with web pages through Playwright and Chrome DevTools Protocol
Guides tool usage by providing recommendations for MCP tools at each problem-solving stage.