Explorer for HashgraphOnline/hol-plugin-security: 205 scored registry plugins, 22 public Guard advisories, 220 modeled runtime fixtures, and an honest OWASP MCP Top 10 mapping.
registry-broker-fallback. Scan ≠ safety. Most findings are publishability, not confirmed vulns.Default config: plugins (205 scored registry plugins). Filterable and sortable. scanner_provider is registry-broker-fallback on every current row. Scan ≠ safety.
22 public HOL Guard advisory pages. owasp_mcp is HOL's primary mapping to one OWASP MCP Top 10 (beta) ID. threat_class comes from hub listing badges on hol.org/guard/security, not inferred from titles. A mapped advisory is not proof a plugin is safe. MCP08 has 0 rows.
220 modeled harness outcomes from the published Guard benchmark record. Same outcome across all 5 harnesses. Latency values are placeholders. No real secrets or attacks executed. This is not a live exploit test.
Copied from the dataset card. HOL's mapping of local Guard + catalog scanner to the OWASP MCP Top 10 beta (Phase 3). Not complete coverage.
MCP06 on the Top 10 list is Intent Flow Subversion. The same OWASP page later also titles that item "Prompt Injection via Contextual Payloads". HOL Guard is not a complete prompt-injection preventer.
IDs and names are cited; long OWASP descriptions are not copied. OWASP document license: CC BY-NC-SA 4.0. advisory_rows is counted from this snapshot's advisories.owasp_mcp (one primary ID per advisory).
| ID | Name | Advisory rows | Detect | Prevent | Gap |
|---|---|---|---|---|---|
| MCP01 | Token Mismanagement & Secret Exposure | 4 | catalog/advisory secret-exfil + mcp-token-theft | Guard can block secret-file / env reads at the local action boundary | not a secrets manager; does not rotate tokens; does not scrub secrets already inside model context |
| MCP02 | Privilege Escalation via Scope Creep | 1 | tool-permission-creep advisory | Guard approval on plugin/skill install and MCP server change | not an OAuth scope-expiry gateway |
| MCP03 | Tool Poisoning | 2 | tool-description-poisoning advisory + scanner MCP posture | Guard on changed MCP servers / plugin install | Cursor path is artifact trust, not full pre-exec of every tool description |
| MCP04 | Software Supply Chain Attacks & Dependency Tampering | 4 | catalog scores, lockfile/publishability findings, supply-chain advisories | Guard on plugin/skill install | not a signing/SBOM authority |
| MCP05 | Command Injection & Execution | 1 | unsafe-command / rm-rf advisory | Guard intercepts local shell/file-destructive actions | does not sandbox every MCP server's own backend |
| MCP06 | Intent Flow Subversion | 5 | several prompt-injection advisories (Intent Flow Subversion / contextual payloads) | limited (some injected-instruction to shell paths hit Guard) | NOT a complete prompt-injection preventer |
| MCP07 | Insufficient Authentication & Authorization | 1 | MCP transport hardening (insecure HTTP, wildcard binds, missing auth posture) on Guard pages | local only | not an MCP gateway identity layer |
| MCP08 | Lack of Audit and Telemetry | 0 | local decision trail / receipts on the developer machine | local decision trail / receipts | not an immutable SIEM; local logs |
| MCP09 | Shadow MCP Servers | 1 | shadow-mcp-server-discovery advisory | Guard on new/changed MCP servers before the harness launches | not continuous org-wide network discovery of shadow servers |
| MCP10 | Context Injection & Over-Sharing | 3 | context-window-scraping / data-overexposure advisories | Guard on excessive local file reads | does not quarantine or partition model context windows |
This mapping does not replace the disclaimers above. Guard is local-first, not a cloud MCP gateway. Fixtures are modeled. 205 plugins ≠ Registry Broker agent counts. Scan ≠ safety.