Per OWASP MASVS v2 MASVS-PLATFORM: secure platform interaction. Requirements include (a) request only necessary permissions + provide clear justification + (b) implement secure inter-app communication (IPC) restricting receivers + intent filters + URL handlers + content providers + (c) implement WebView security including JavaScript bridge restrictions + URL allowlisting + same-origin policy + (d) implement deeplink + universal link validation against intent hijacking + (e) protect against tapjacking + overlay attacks + (f) implement screen capture protection for sensitive screens where appropriate + (g) protect against background snapshot exposure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.