Skip to content

Enhance C10#713

Merged
jmanico merged 2 commits intoOWASP:mainfrom
DotDotSlashRepo:C10-Edits
Apr 25, 2026
Merged

Enhance C10#713
jmanico merged 2 commits intoOWASP:mainfrom
DotDotSlashRepo:C10-Edits

Conversation

@DotDotSlashRepo
Copy link
Copy Markdown
Contributor

  • Added 10.1.3 - Verify that all MCP tool and resource schemas include cryptographically verifiable provenance metadata — including author, timestamp, version hash, signature, and approved‑by fields.

Rationale

Schema Provenance Metadata closes auditability gap in the MCP supply chain. Well written metadata can help in figuring out, for e.g.

Who authored or modified a schema

When it changed

Whether the change was approved
  • Fix numbers in 10.2

  • Modify 10.4.2 to include integrity protection for schema manifest as well

*Added 10.1.3 - Verify that all MCP tool and resource schemas include cryptographically verifiable provenance metadata — including author, timestamp, version hash, signature, and approved‑by fields.

Rationale

Schema Provenance Metadata closes auditability gap in the MCP supply chain. Well written metadata can help in figuring out, for e.g.

Who authored or modified a schema

When it changed

Whether the change was approved

* Fix numbers in 10.2

*Modify 10.4.2 to include integrity protection for schema manifest as well
Change c10.1.3 to L2
@jmanico jmanico merged commit e6e4ac7 into OWASP:main Apr 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants