Intelligence assessments
The dominant ecosystem risk is unresolved trust, not a single vulnerability class.
High confidence66,986 of 71,565 active identities (93.6%) are not independently verified as official publishers. Community status is not evidence of maliciousness; it means adoption decisions cannot rely on a familiar product name alone.
Observed relationship: active listing → canonical implementation → retained publisher classification.
Decision: verify repository, namespace, package publisher, and domain evidence before granting credentials.
Tool authority creates exposure before a vulnerability is proven.
High confidenceAmong 11,197 implementations with independently observed current tool inventory, 1,150 expose at least one write-capable tool, 860 expose a destructive annotation, and 1,426 expose open-world behavior.
Observed relationship: exact current package → successful protocol discovery → tool schema and annotations.
Decision: evaluate the combined authority available to an agent, not tool names in isolation.
Remote MCP adoption moves the boundary from package trust to service trust.
High confidence5,032 MCPs are linked to remote endpoints. 4,445 have an observation outcome; 1,439 require authentication, while 2,860 are currently unhealthy and 1,135 were blocked by observation policy.
Observed relationship: canonical implementation → retained endpoint claim → latest bounded observation job.
Decision: treat endpoint ownership, authentication, availability, and capability drift as continuous external-attack-surface intelligence.
Missing verification is an intelligence gap, not evidence of safety.
High confidence63,163 canonical implementations do not currently have a publicly eligible completed verification for the selected current version. The gap includes untested, ineligible, changed, and otherwise unresolved evidence states.
Observed relationship: canonical implementation → selected current artifact → successful verification evidence.
Decision: preserve “unknown” as a first-class state and prioritize by identity ambiguity, authority, exposure, and organizational use.