cd /news/ai-agents/welcome-to-the-jungle-what-we-found-… · home › topics › ai-agents › article
[ARTICLE · art-146677] src=swapupdate.in ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

OX Security analyzed 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames, and found no marketplace vetting or code signing, according to a report titled "15,465 MCP Servers, 0 Governance" authored by Security Research Team Lead Moshe Siman Tov Bustan. The findings include 15.6% of hostnames resolving to infrastructure outside the United States (19 in China and 18 in Russia), 0.45% routing traffic through consumer tunneling services such as ngrok-free, and 2.3% no longer resolving, with six on expired domains registerable for $4 to $12 a year. The report follows OX Security's earlier tracing of critical vulnerabilities in Anthropic's MCP source code, which has been downloaded more than 150 million times.

read3 min views1 publishedOct 7, 2026
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Image: Swapupdate (auto-discovered)

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows.

The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic’s MCP source code, downloaded more than 150 million times. This time, we looked at what people actually install: community-published servers across the most popular MCP marketplaces. We found no guardrails and no review. Security is a recommendation, not a policy.

A Marketplace With No Bouncer

In 2012, Google ran Bouncer, an automated scanner that checked Android apps for malware before they reached users. It wasn’t perfect: researchers slipped malware past it. But it existed. MCP marketplaces have no equivalent. Anyone can write a server, push it, and publish it.

Even a review wouldn’t close the gap. At RSAC and OWASP last year, we presented “In GitHub We Trust: 10 Ways You Can Get Pwned,” on how developers over-trust what they see in a repository. MCP repeats that mistake. Remote MCP servers can run backend code that differs entirely from what their public repository shows. Code review tells you what the developer published, not what the server runs.

Where Does Your Data Go?

Over the past decade, enterprises built strict governance to adopt public cloud safely: data residency rules, Zero Trust boundaries, granular IAM, and supply chain audits. MCP connections often sit outside all of it.

To measure the gap, we analyzed 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames.

  • Hosted outside the US: 15.6% of hostnames resolve to infrastructure outside the United States, including 19 in China and 18 in Russia. An agent connected to these servers may send data to jurisdictions the security team never approved.
  • Running on personal machines: 0.45% route traffic through consumer tunneling services, mainly ngrok-free. These publicly listed servers run from personal machines and, likely, home networks.
  • Dangling domains: 2.3% no longer resolve. Six sit on expired domains that anyone can register for $4 to $12 a year. A new owner would inherit an established server identity, along with requests from any agent still configured to call it.

Location can also change. An operator could launch a server on a clean US IP address and later route traffic somewhere else.

The full report covers our methodology, a prompt-injection proof of concept, and the threat scenarios behind each finding. Download “15,465 MCP Servers, 0 Governance”

Trust Is the Attack Surface

The protocol isn’t the problem. The trust we hand it is. Until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work.

It’s still a jungle out there. Make sure you’re not the prey.

Get the full report, “15,465 MCP Servers, 0 Governance” Want to go further? Join our live webinar, “The AI Attack Surface Is Already in Your Cloud,” on October 13 at 12:00 PM ET. Latio founder and CEO James Berthoty and OX Field CTO Chris Lindsey will cover how AI is reshaping cloud threats and what security teams should do about it. Register

Note: This article has been expertly written and contributed by Moshe Siman Tov Bustan, Security Research Team Lead, OX Security.

Google News,

── more in #ai-agents 4 stories · sorted by recency
── more on @ox security 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/welcome-to-the-jungl…] indexed:0 read:3min 2026-10-07 · —