Tool with unconstrained URL parameter

AI security governance · MCP security

Severity

critical

What it is

Tool input schema has a URL parameter without domain restrictions.

How Igris detects it

Igris's Data Exfiltration Detector flags this during MCP security scans of your configuration.

References

Related MCP security rules

Secure your AI estate with Igris