Address OWASP Top 10 A04 Insecure Design + A11 API Abuse and Business Logic Attacks per OWASP Top 10:2025. Insecure Design reflects missing or inadequate security design including missing threat modelling + missing security requirements + insecure reference architecture + missing business logic security controls + and missing security testing of design. API Abuse and Business Logic Attacks occur when business workflows are abused at scale via automation + scalping + scraping + fake transaction generation + bot abuse. Mitigations include (a) conduct threat modelling at design phase + revise on significant change + (b) maintain documented security requirements + reference architecture + (c) integrate security activities into SDLC + (d) implement business logic security controls including step ordering + state validation + replay prevention + (e) implement bot management + rate limiting + velocity controls + (f) conduct abuse case modelling + negative testing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.