Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
AI-summarised brief · reviewed before publication
In 2024, the Model Context Protocol (MCP) aimed to standardize AI model connectivity, yet its open marketplaces lack security oversight. OX Security examined 15,465 public MCP servers, finding 5,095 unique hostnames with no guardrails or review processes. The study revealed that remote MCP servers can run code divergent from their public repositories, exposing enterprises to supply‑chain attacks. The report details a prompt‑injection proof of concept and outlines threat scenarios, urging marketplaces to adopt vetting, code signing, and origin verification.
💡 Why It Matters
- · The absence of formal governance in MCP ecosystems leaves AI agents vulnerable to hidden malicious code, threatening enterprise data integrity and operational continuity.