Home / Companies / Apollo / Blog / Post Details
Content Deep Dive

Where Apollo MCP Server Stands on the OWASP MCP Top 10

Blog post from Apollo

Post Details
Company
Date Published
Author
Camille Lawrence
Word Count
1,672
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

Apollo MCP Server’s self-audit against the OWASP MCP Top 10 concludes that its typed, schema-validated GraphQL tool architecture directly prevents shell-based command injection, while most other protections depend on deployment configuration and operational controls. The server supports authentication checkpoints, global and per-operation OAuth scopes, mutation gating, telemetry, environment-based header configuration, container attestations, and description overrides, but users must configure these features carefully and maintain reviews of tool definitions, scopes, credentials, and source changes. Key residual risks include plaintext static headers, opt-in per-operation authorization, unredacted tracing by default, uneven binary signing, hot-loaded tool changes without approval workflows, and caller tokens being forwarded upstream by default despite MCP specification concerns. The assessment also states that agent instruction injection remains possible within the set of exposed operations, while shadow server discovery and tenant isolation fall outside the server’s control and must be addressed through asset management and deployment topology.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 16 8,729 854 211 -20%
AI Agents 1 5,780 1,243 245 -15%
Secrets Management 1 2,244 480 132 -13%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.