MCP Security Research

Independent intelligence on the MCP ecosystem

Original analysis derived from exact-version inventory, isolated runtime verification, capability history, and publisher attribution across the MCP ecosystem.

Ecosystem ranking
Continuously updated
Catalog attribution data

Companies With the Most Community-Associated MCP Servers

Compare company product ecosystems by community publication, retained official attribution, distribution presence, and current-version verification coverage.

Flagship report
Continuously updated
Shareable dataset

State of MCP Security 2026

The market, publisher-attribution, remote-exposure, observed-tool, vulnerability, and verification findings that define the current MCP security landscape.

Scanner dataset
Continuously updated
Primary research

MCP Security Scanner Coverage: What We Tested and Proved

Exact counts for npm, PyPI, and remote coverage; current-version outcomes; retained vulnerability techniques; methodology; and explicit evidence limits.

Security landscape
Continuously updated
Live evidence

MCP Security Landscape: vulnerabilities, coverage, and risk

What current exact-version verification proves, what remains unknown, and where MCP security evidence is most consequential.

Threat intelligence
Continuously updated
Living report

MCP Ecosystem Threat Map

Decision-grade analysis of identity fragmentation, remote exposure, and high-authority capability concentration derived from the live catalog relationship graph.

Attack-path research
Aug 27, 2026
8 min read

Cross-repository MCP risk is the missing security boundary

A safe-looking server in one repository can become the read step in an attack path completed by a second server elsewhere. Repo-by-repo controls cannot see the composition.

Brand intelligence
Aug 27, 2026
6 min read

Unofficial MCPs create a brand security perimeter companies do not control

Our catalog links brand-associated names to publisher identity, exact versions, observed tools, and reproduced findings—revealing customer risk outside the vendor’s repositories.

Ecosystem data
Aug 27, 2026
7 min read

What our runtime verification data reveals about MCP security

Live coverage, proven findings, and the gap between source claims and behavior observed while executing exact releases.

Let’s talk about MCP security.

Share your details and our security team will contact you.