Top AI Repos — open-source AI, indexed and scored
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
SAF-MCP is a comprehensive security framework for documenting and mitigating threats in the AI Agent ecosystem.
| Date | Stars |
|---|---|
| 2026-07-31 | 353 |
| 2026-08-06 | 353 |
Today
— stars today
This week
— stars this week
This month
— stars this month
Momentum
0.0
growth rate 0.00%/day
# SAF-MCP: Secure Agentic Framework for Model Context Protocol | SIG-SAFE-MCP | Details | | ---------------- | ------------------------------------------------------------------------------------------ | | **Mailing List** | [[email protected]](https://lists.openssf.org/g/openssf-sig-safe-mcp) | | **SIG Leads** | Sarah Evans; Frederick Kautz | | **Maintainers** | Bishnu Bista; Sarah Evans; Frederick Kautz | | **Meeting Time** | 1:00 PM PT (PST/PDT) Bi-Weekly | | **Slack** | OpenSSF #sig-safe-mcp | ## About SAF-MCP SAF-MCP is a comprehensive security framework for documenting and mitigating threats in the Model Context Protocol (MCP) ecosystem. This framework adapts the proven MITRE ATT&CK methodology specifically for MCP environments, providing structured documentation of adversary tactics, techniques, and procedures (TTPs) that target MCP implementations and AI-powered applications. ### Key Features - **MITRE ATT&CK Alignment**: We use patterns and methodologies from the MITRE ATT&CK Framework, explicitly targeting MCP-specific threats while maintaining compatibility with established security practices. - **Compliance Mapping**: Each SAF-MCP technique links to corresponding MITRE ATT&CK techniques where applicable, helping organizations determine compliance with existing security frameworks and controls. - **Comprehensive Coverage**: Documenting attack techniques across 14 tactical categories, from initial access to impact, with continuous additions as new threats emerge. - **Actionable Mitigations**: Each technique includes detailed mitigation strategies and detection rules to help defenders protect their MCP deployments. ### How to Use This Framework 1. **Security Teams**: Use the TTP reference table below to understand potential threats to your MCP implementation 2. **Developers**: Review techniques relevant to your MCP tools and implement recommended mitigations 3. **Compliance Officers**: Map SAF-MCP techniques to your existing security controls via MITRE ATT&CK linkages 4. **Red Teams**: Reference attack techniques for security testing of MCP deployments ## TTP Reference Table This table provides a comprehensive reference of all Tactics, Techniques, and Procedures (TTPs) defined in the SAF-MCP framework. ## SAF-MCP Tactics The SAF-MCP framework defines 14 tactics that align with the MITRE ATT&CK methodology: | Tactic ID | Tactic Name | Description | | ---------- | -------------------- | ------------------------------------------------------------------------------------ | | ATK-TA0043 | Reconnaissance | The adversary is trying to gather information they can use to plan future operations | | ATK-TA0042 | Resource Development | The adversary is trying to establish resources they can use to support operations | | ATK-TA0001 | Initial Access | The adversary is trying to get into your MCP environment | | ATK-TA0002 | Execution | The adversary is trying to run malicious code via MCP | | ATK-TA0003 | Persistence | The adversary is trying to maintain their foothold in MCP | | ATK-TA0004 | Privilege Escalation | The adversary is trying to gain higher-level permissions | | ATK-TA0005 | Defense Evasion | The adversary is trying to avoid being detected | | ATK-TA0006 | Credential Access | The adversary is trying to steal account names and passwords | | ATK-TA0007 | Discover
Excerpt of 42,720 characters
Read on GitHubWould you bet a product on this? Bounded 0–100 and slow moving.
matched fp:0fbae6b38f690aac, llm:Repository description: 'SAF-MCP is a comprehensive security framework for documenting and mitigating threats in the AI Agent ecosystem.' (secure-agentic-framework/saf-mcp)
matched fp:0fbae6b38f690aac, llm:Repository description: 'SAF-MCP is a comprehensive security framework for documenting and mitigating threats in the AI Agent ecosystem.' (secure-agentic-framework/saf-mcp)
matched fp:0fbae6b38f690aac, llm:Repository description: 'SAF-MCP is a comprehensive security framework for documenting and mitigating threats in the AI Agent ecosystem.' (secure-agentic-framework/saf-mcp)