Who publishes MCPs, where they ship, and what remains unverified
The MCP market is not one registry. Packages, source repositories, remote endpoints, publisher claims, tools, and exact-version security evidence form separate trust layers. This report measures each layer without treating popularity, “official” status, or missing evidence as safety.
Packages are coordinates, not identities
16,865 canonical MCPs select npm as their primary channel, 5,411 select PyPI, and 49,289 resolve through another or source-only coordinate.
Question: where is this implementation obtained?Explore distributions →Official requires retained evidence
4,579 active identities have official attribution. The remaining 66,986 are community or unresolved—not automatically unsafe.
Question: who controls this integration?Compare publishers →Remote is an additional trust boundary
5,032 identities link to remote endpoints. 4,445 have bounded observation outcomes; authentication and health are not vulnerability verdicts.
Question: what can change outside the package?Inspect remote MCPs →Claims stop where observation begins
11,197 implementations have independently observed tool inventories. 60,368 do not have that evidence in the current relationship snapshot.
Question: what authority was actually observed?Open ecosystem evidence →Supply-chain decision model
- Resolve the canonical implementation across listings.
- Confirm package, repository, or endpoint coordinates.
- Verify publisher attribution independently.
- Observe initialized tools and authority.
- Bind security evidence to the exact selected version.
- Re-evaluate when any layer changes.
What this report does not claim
35,069 implementations without a retained package relationship are not therefore malicious. 66,986 identities without official attribution are not therefore impersonators. 63,163 current versions without completed verification are neither clean nor vulnerable. These are investigation states, not accusations.
Move from market intelligence to evidence
Inspect publisher attribution, exact-version vulnerabilities, and the canonical implementation records behind these aggregates.
Official vs communityVulnerability indexIntelligence Center