CCS Standard v1.2 · IETF Referenced · DOI Registered

The security standard
for MCP.

MCP protocol doesn't enforce security. We do. A runtime security standard for MCP — with an IETF-referenced spec and DOI-registered research. Get certified or stay exposed.

24
Detection Rules
3
MCP CVEs Tracked
1,730+
Findings (v4.2 · 2026-07-21 实测)
IETF
Spec Drafted
DOI
Registered
9.8
Max CVSS
See it in action.

Run the CCS scanner against any MCP configuration. Get results in seconds — no signup, no install required.

🔍

Instant Scan

Paste any MCP config JSON. Get vulnerability results in under 5 seconds.

🛡️

7-Dimension Verification

Structure, Schema, Latency, Identity, Cost, Integrity, Security — all checked.

📊

Severity Mapping

Every finding mapped to CVSS scores and real-world exploit examples.

CCS Scanner v1.2
$ ccs scan --target mcp-server.json
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ℹ Scanning MCP server configuration...
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✗ CRITICAL — Unsanitized env var in tool handler
→ SSRF risk: process.env → MCP subprocess
✗ CRITICAL — Missing auth on tool invocation
→ CVSS 9.8 — No identity verification
⚠ HIGH — No output validation schema
→ Schema drift detected in 3 tools
⚠ HIGH — Cost bounds not enforced
→ Token usage unbounded per session
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
2 CRITICAL 2 HIGH · 0 MEDIUM · 12 PASS
CCS Conformance: FAIL
What is CCS?

Correctover Conformance Specification — the runtime security standard for MCP. Five components. Zero exceptions.

👁️

Runtime Observatory

Capture every agent execution trace with cryptographic integrity. Full visibility into tool calls, data flows, and decision chains.

📋

Fault Taxonomy

Fault taxonomy defined in the IETF-referenced CCS Standard v1.2 spec, grounded in the DOI-registered Correctover research corpus.

Conformance Check

Required(τ) ⊆ Supported(τ). Formal verification that what you claim to support is what you actually support.

🔗

Receipt Schema

Cryptographic chain integrity for every output. Tamper-proof audit trail for compliance and forensics.

🔄

Verification Protocol

Four-axis verification: schema, integrity, cost, compliance. P50 <10μs latency (self-benchmarked). Zero performance tax.

📜

Audit Logger

Immutable forensic trail for SOC2, HIPAA, GDPR. Every decision, every tool call, every data access logged.

Backed by real-world research.

Not theory. Real CVEs in the MCP ecosystem, each verified against NVD. Peer-reviewed research. DOI-registered.

CVE

CVE-2026-42271

LiteLLM MCP-REST: arbitrary command execution via /mcp-rest/test/connection. CVSS 4.0 8.7. In CISA KEV.

View on NVD →
CVE

CVE-2026-30623

LiteLLM 1.18.10 MCP server: RCE via unvalidated command config. CVSS 3.1 9.8. Fixed in later releases.

View on NVD →
CVE

CVE-2026-2287

CrewAI: Docker sandbox fallback allows RCE. CVSS 3.1 9.8. Disclosed via CERT/CC VU#221883.

View on NVD →
IETF

draft-correctover-ccs-02

Correctover Conformance Specification draft submitted to the IETF (2026-08).

View Draft →
Research

MCP Security Research

Cross-framework audit demonstrations across the MCP ecosystem, with reproducible PoCs.

View on GitHub →
DOI

DOI Registered

10.5281/zenodo.21603250 — Permanent, verifiable, blockchain-timestamped record.

View on Zenodo →
Standard is free.
Certification costs money.

Start scanning for free. Upgrade when you need the badge.

Free
$0
Unlimited scans
  • Vulnerability scanning
  • First 2 risks per scan
  • CCS Standard v1.2 spec (free)
  • 20K trajectory samples
Scan Free →
Enterprise
Contactus
Custom volume pricing
  • Everything in Certified
  • Multiple server certifications
  • Custom compliance policies
  • Private threat intel feed
  • SLA + dedicated support
  • On-site audit (optional)
Contact →
Four steps to certified.
1

Scan

Run the free scanner against your MCP config. See exactly what's exposed.

2

Fix

Fix all findings. Install Runtime Guard for continuous protection.

3

Audit

We audit your server. OAuth 2.1 + CCS Standard v1.2 compliance check.

4

Certified

Get the badge. Listed in public registry. Re-certify when your stack changes.

Let's talk security.
📧
📄

Specification

CCS SDK Repository