Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Oct 06, 2026
Supply Chain / Artificial Intelligence
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security , traced critical vulnerabilities in Anthropic's MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy. A Marketplace With No Bouncer In 2012, Google ran Bouncer, an automated scanner that checked Android apps for malware before they reached users. It wasn't perfect: researchers slipped malware past it . But it existed. MCP marketplaces have no equivalent. Anyone can write a server, push it, and publish it. Even a review wouldn'...