Mitigation ID: SAFE-M-16
Type: Preventive Control
Complexity: Medium
Effectiveness: High
Enforce minimal OAuth scopes and warn users when MCP servers request broad permissions to limit potential damage from compromised tokens.
[To be documented]
- SAFE-T1007: OAuth Authorization Phishing
- SAFE-T1202: OAuth Token Persistence