MCP Security Intelligence · Ecosystem report 001

MCP ecosystem threat map

A relationship-level view of the MCP ecosystem: who publishes integrations, how implementations connect to packages and remote infrastructure, what authority their tools expose, and where independent evidence is still missing.

Snapshot generated 2026-09-08T08:54:27.142Z · live production catalog · aggregate and published evidence only

71,565active canonical identities
66,986publishers not verified as official
11,197MCPs with independently observed current tools
5,032MCPs linked to remote endpoints

Intelligence assessments

The dominant ecosystem risk is unresolved trust, not a single vulnerability class.

High confidence

66,986 of 71,565 active identities (93.6%) are not independently verified as official publishers. Community status is not evidence of maliciousness; it means adoption decisions cannot rely on a familiar product name alone.

Observed relationship: active listing → canonical implementation → retained publisher classification.

Decision: verify repository, namespace, package publisher, and domain evidence before granting credentials.

Tool authority creates exposure before a vulnerability is proven.

High confidence

Among 11,197 implementations with independently observed current tool inventory, 1,150 expose at least one write-capable tool, 860 expose a destructive annotation, and 1,426 expose open-world behavior.

Observed relationship: exact current package → successful protocol discovery → tool schema and annotations.

Decision: evaluate the combined authority available to an agent, not tool names in isolation.

Remote MCP adoption moves the boundary from package trust to service trust.

High confidence

5,032 MCPs are linked to remote endpoints. 4,445 have an observation outcome; 1,439 require authentication, while 2,860 are currently unhealthy and 1,135 were blocked by observation policy.

Observed relationship: canonical implementation → retained endpoint claim → latest bounded observation job.

Decision: treat endpoint ownership, authentication, availability, and capability drift as continuous external-attack-surface intelligence.

Missing verification is an intelligence gap, not evidence of safety.

High confidence

63,163 canonical implementations do not currently have a publicly eligible completed verification for the selected current version. The gap includes untested, ineligible, changed, and otherwise unresolved evidence states.

Observed relationship: canonical implementation → selected current artifact → successful verification evidence.

Decision: preserve “unknown” as a first-class state and prioritize by identity ambiguity, authority, exposure, and organizational use.

Where observed capability authority concentrates

Categories describe independently observed current tools. They are workflow intelligence, not vulnerability labels.

Capability categoryImplementationsObserved tools
Unclassified11,197175,581

Published high-authority examples

These records expose write-capable, destructive, or open-world tools in the current observed inventory. Inclusion indicates authority requiring policy review; it does not assert a vulnerability.

MCP recordToolsDestructiveOpen worldMaximum tool risk score
hostinger-api-mcpVerified official publisher2201220Not scored
Kontent.ai MCP ServerVerified official publisher31220Not scored
Playwright MCP ServerVerified official publisher241724Not scored
Mobile Next MCP ServerVerified official publisher17170Not scored
Microsoft Fabric RTI MCP ServerVerified official publisher18110Not scored
@yawlabs/aws-mcpVerified official publisher23621Not scored
KeyID Agent KitVerified official publisher35616Not scored
LocalStack MCP ServerVerified official publisher1060Not scored

Evidence and limitations

Explore the catalog evidence · Compare publisher identity · Review completed verification

Let’s talk about MCP security.

Share your details and our security team will contact you.