A discussion around the Machine Communication Protocol (MCP) spec has revealed that a significant portion of servers requiring authentication do not enforce it for their tool lists. Out of 117 servers that mandate credentials, approximately 15% still serve their complete tool list anonymously, and another 16% refuse requests in a manner non-compliant clients cannot act upon. This issue is more prevalent in smaller teams, where a default specification setting could be more impactful. Furthermore, the majority of MCP servers lack a reachable remote endpoint, meaning their discoverability primarily relies on source code and package metadata rather than pre-authentication discovery surfaces. AI
IMPACT This analysis highlights potential security and discoverability issues in a protocol used for software development tooling, impacting how developers interact with services.
RANK_REASON Analysis of a technical specification and its implementation, including data collection and reporting. [lever_c_demoted from research: ic=1 ai=0.4]
- application programming interface key
- GitHub
- MCP
- OAuth 2
- Python Package Index
- RFC 9728: OAuth 2.0 Protected Resource Metadata
- software as a service
- unempyd
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →