CBS Statistics Netherlands
MCP server for accessing CBS (Statistics Netherlands) open data. Search datasets, retrieve table metadata, download observations, and list topics from the Dutch national statistics bureau. 6 tools for demographic, economic, and social data.
0Tools
2Findings
Mar 24, 2026Last Scanned
1 medium ยท 1 low findings detected
Security Category Deep Dive
Prompt Injection
Prompt & context manipulation attacks
69
Maturity
14
Rules
5
Sub-Categories
1
Gaps
64%
Implemented
56
Tests
1
Stories
100%3 rules
Injection via tool descriptions and parameter fields
GAP-001Prompt Injection Coverage GapMissing detection coverage for emerging prompt injection attack variants not addressed by current rules
100%4 rules
Hidden instructions via external content and tool responses
100%2 rules
Context window saturation and prior-approval exploitation
100%3 rules
Payload hiding via invisible chars, base64, schema fields
100%2 rules
Injection via prompt templates and runtime tool output
Findings2
1medium
1low
Medium1
mediumE1No Authentication RequiredMCP07-insecure-config
[Protocol] Server does not require authentication. Any client can connect and invoke tools.
Implement authentication. For remote servers, use OAuth 2.0 (MCP Authorization spec).
Low1
lowF4MCP Spec Non-ComplianceMCP07-insecure-config
Server fails MCP spec compliance checks: required:server_name; required:server_version; required:protocol_version; recommended:tool_descriptions; recommended:parameter_descriptions
Follow the MCP specification for server metadata. Include server name, version, and protocol version. Provide descriptions for all tools and parameters.