How the index reaches a vulnerability verdict
Inventory size, historical scan coverage, current verification, and proven vulnerability evidence answer different questions. The funnel shows the denominator behind every public verdict.
deduplicated MCP implementations
implementations scanned across retained versions
completed current-version runs without a proven finding
completed current-version runs with proven evidence
Investigate the underlying MCP records
The intelligence report does not manufacture a second list. These views open the canonical catalog records and their retained version evidence.
Vulnerable MCP servers
Current selected versions with at least one publishable finding reproduced by the proof engine.
Completed evidenceVerified MCP servers
Review completed current-version verification while keeping clean and vulnerable outcomes distinct.
Coverage gapAwaiting current scan
The unknown population requiring prioritization before any security conclusion can be made.
Composition riskCross-MCP attack paths
Risks created by combining source and sink authority across servers, beyond single-package findings.
What the current rate does—and does not—say
6.0% of exact current versions with completed public verification have at least one proven finding. This is an observed rate within the verified population. It must not be projected onto unverified MCPs, and it is not an estimate of ecosystem-wide vulnerability prevalence.
A proven finding establishes repeatable behavior under the retained scanner method and tested environment. Severity, remote reachability, default exposure, vendor ownership, and deployment impact require their own evidence.