Where Apollo MCP Server Stands on the OWASP MCP Top 10
Blog post from Apollo
Apollo MCP Server’s self-audit against the OWASP MCP Top 10 concludes that its typed, schema-validated GraphQL tool architecture directly prevents shell-based command injection, while most other protections depend on deployment configuration and operational controls. The server supports authentication checkpoints, global and per-operation OAuth scopes, mutation gating, telemetry, environment-based header configuration, container attestations, and description overrides, but users must configure these features carefully and maintain reviews of tool definitions, scopes, credentials, and source changes. Key residual risks include plaintext static headers, opt-in per-operation authorization, unredacted tracing by default, uneven binary signing, hot-loaded tool changes without approval workflows, and caller tokens being forwarded upstream by default despite MCP specification concerns. The assessment also states that agent instruction injection remains possible within the set of exposed operations, while shadow server discovery and tenant isolation fall outside the server’s control and must be addressed through asset management and deployment topology.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 16 | 8,729 | 854 | 211 | -20% |
| AI Agents | 1 | 5,780 | 1,243 | 245 | -15% |
| Secrets Management | 1 | 2,244 | 480 | 132 | -13% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.