MCP Security / Intelligence / Supply-chain security
LIVE CATALOG EVIDENCE
MCP SUPPLY-CHAIN INTELLIGENCE

Who publishes MCPs, where they ship, and what remains unverified

The MCP market is not one registry. Packages, source repositories, remote endpoints, publisher claims, tools, and exact-version security evidence form separate trust layers. This report measures each layer without treating popularity, “official” status, or missing evidence as safety.

CANONICAL MARKET71,565deduplicated implementations
OFFICIAL ATTRIBUTION4,5796.4% of active identities
PACKAGE-LINKED36,49651.0% coverage
REMOTE-LINKED5,032endpoint relationship overlay
CURRENT VERIFIED8,40211.7% coverage
Primary package distributionCanonical implementation share
npm
16,86523.6%
PyPI
5,4117.6%
Source / other
49,28968.9%
01 / DISTRIBUTION

Packages are coordinates, not identities

16,865 canonical MCPs select npm as their primary channel, 5,411 select PyPI, and 49,289 resolve through another or source-only coordinate.

Question: where is this implementation obtained?Explore distributions →
02 / PUBLISHER

Official requires retained evidence

4,579 active identities have official attribution. The remaining 66,986 are community or unresolved—not automatically unsafe.

Question: who controls this integration?Compare publishers →
03 / DELIVERY

Remote is an additional trust boundary

5,032 identities link to remote endpoints. 4,445 have bounded observation outcomes; authentication and health are not vulnerability verdicts.

Question: what can change outside the package?Inspect remote MCPs →
04 / EXECUTION EVIDENCE

Claims stop where observation begins

11,197 implementations have independently observed tool inventories. 60,368 do not have that evidence in the current relationship snapshot.

Question: what authority was actually observed?Open ecosystem evidence →

Supply-chain decision model

  1. Resolve the canonical implementation across listings.
  2. Confirm package, repository, or endpoint coordinates.
  3. Verify publisher attribution independently.
  4. Observe initialized tools and authority.
  5. Bind security evidence to the exact selected version.
  6. Re-evaluate when any layer changes.

What this report does not claim

35,069 implementations without a retained package relationship are not therefore malicious. 66,986 identities without official attribution are not therefore impersonators. 63,163 current versions without completed verification are neither clean nor vulnerable. These are investigation states, not accusations.

Move from market intelligence to evidence

Inspect publisher attribution, exact-version vulnerabilities, and the canonical implementation records behind these aggregates.

Official vs communityVulnerability indexIntelligence Center

Let’s talk about MCP security.

Share your details and our security team will contact you.