The MCP security evidence gap
Runtime scans have covered 12.0% of canonical MCP implementations. Completed evidence for the selected current version covers 11.7%. Those are different measures: historical scanning does not guarantee that the release selected today has completed evidence.
Current evidence states
What “proven vulnerable” means
A current version is counted as vulnerable only when the proof engine completes the required evidence flow for that exact selected version and retains at least one publishable proven finding. The result describes the tested method and deployment context; it does not automatically prove remote exploitability, vendor ownership, bounty eligibility, or identical behavior in every installation.
What “verified clean” means
Verified clean means the completed current-version run did not prove a vulnerability using the scanner methods exercised in that run. It does not prove the absence of every possible vulnerability, configuration error, credential exposure, malicious behavior, or cross-MCP attack path.
Remote MCP exposure
The catalog currently links 5,032 MCPs to remote endpoints. Bounded observation has reached 4,445 of them; 1,439 require authentication, 2,860 have unhealthy outcomes, and 1,135 are blocked by observation policy. Availability and authentication outcomes are not vulnerability verdicts.
Where verification has the highest value
- MCPs enabled in a real organization or agent environment.
- Servers exposing write, destructive, execution, credential, or open-world authority.
- Remote services whose ownership or behavior can change independently of a package release.
- Packages with unresolved publisher attribution or conflicting distribution coordinates.
- New versions that materially change observed tools or authority.
Methodology and limitations
The public catalog joins canonical identity, package version, protocol discovery, remote observation, and proof-engine results. Embargoed evidence is excluded and must remain indistinguishable from unscanned public inventory. Rates describe the observed population and must not be projected onto unknown MCPs.
Investigate the evidence
Review current verification records, vulnerable MCPs, and attack paths formed between separate servers.
Completed verificationVulnerable MCPsCross-MCP attacks