PulseAugur
EN
LIVE 23:46:25

Security flaws found in 15% of top MCP servers

A security scan of 500 servers on the MCP registry Smithery revealed that 15.3% of them contained security vulnerabilities. These findings include critical issues like file-disguise vectors and tool description injections, with one in six servers exhibiting toxic flows that form complete attack paths. Notably, some well-known services such as Slack, Google Sheets, and AWS documentation were found to have high-severity issues, indicating that even actively maintained and recognizable servers are not immune to these security risks. AI

IMPACT Highlights critical security risks in AI agent development tools, potentially impacting enterprise adoption and agent security practices.

RANK_REASON Security research findings on a specific platform. [lever_c_demoted from research: ic=1 ai=1.0]

Read on dev.to — MCP tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Security flaws found in 15% of top MCP servers

COVERAGE [1]

  1. dev.to — MCP tag TIER_1 English(EN) · Saray Chak ·

    We scanned 500 MCP servers on Smithery. Here is what we found.

    <p>Smithery is the largest public MCP registry right now. Over 5,400 servers listed. We took the top 500 by install rank, ran them through <a href="https://github.com/bawbel/scanner" rel="noopener noreferrer">Bawbel Scanner v1.2.2</a>, and logged every finding.</p> <p>No theory. …