MCP Security Signals

Every signal below comes from actually scanning the published source of each Model Context Protocol server with one deterministic engine50,796 findings across 11,908 flagged packages, each with a rule id, a severity and a confidence, each linking to its evidence on the server’s page. This is the triage view: review signals, not verdicts. Nothing here is an LLM’s guess — the same input produces the same finding again.

Findings by severity

Counts are individual findings, so one package can appear under several. The engine graded critical at exactly zero across the whole catalog — a measured result, not a gap in coverage — while the long tail is low-severity supply-chain hygiene. The rows above are the shape of the work; the feed further down is the work itself.

critical
267
across 265 servers
unrecoverable compromise — compound tool-poisoning and self-contained exfiltration primitives, now surfaced from the statically-extracted tool surface
high
21,873
across 8,814 servers
exploitable behaviour in the shipped code or how it is installed
medium
8,846
across 4,796 servers
risky patterns worth a human read before you trust the server
low
8,874
across 4,128 servers
hygiene and supply-chain gaps — mostly missing repositories and licenses
info
10,936
across 9,088 servers
advisory notes the engine records but never scores

Rule families

Every rule id belongs to one of three families. Bars count the servers each family flagged; the number beside each is raw findings, because one family can fire many times inside one package.

Rule families by servers affectedSource code: 10,355 (31,138 findings)Source code31,138 findings10,355Supply chain: 9,172 (11,191 findings)Supply chain11,191 findings9,172MTC-CAP: 1,702 (6,146 findings)MTC-CAP6,146 findings1,702Toxic flow: 1,171 (1,222 findings)Toxic flow1,222 findings1,171MTC-NET: 859 (859 findings)MTC-NET859 findings859Tool poisoning: 76 (133 findings)Tool poisoning133 findings76Rug-pull drift: 61 (61 findings)Rug-pull drift61 findings61Unicode smuggling: 7 (46 findings)Unicode smuggling46 findings7

Bar length is servers affected; the note is raw findings.

  • Source code MTC-SRC — What the shipped code does — shell and command execution, dynamic code evaluation, and network sinks read straight out of the published source.
  • Supply chain MTC-SUP — How a package is shipped, before a line of it runs — missing source repository, no license, install-time scripts and names that combosquat a popular one.
  • MTC-CAP MTC-CAP — a family of deterministic rules
  • Toxic flow MTC-FLOW — The lethal trifecta across a server’s tools: untrusted input + sensitive-data read + external egress compose into a data-exfiltration path a prompt-injected model could drive.
  • MTC-NET MTC-NET — a family of deterministic rules
  • Tool poisoning MTC-INJ — Instructions aimed at the model hidden in a tool’s description or parameters — instruction overrides, concealment (“don’t tell the user”), forced sequencing and credential-path targeting. Read from the tool surface statically extracted from the published source.
  • Rug-pull drift MTC-TOFU — Trust-on-first-use: the package’s bytes moved under a version you already trusted. Rare by design, and the signal worth watching.
  • Unicode smuggling MTC-UNI — Hidden payloads in tool metadata — Tags-block characters, zero-width joiners, bidi overrides and homoglyphs that a reviewer’s eye cannot see but the model reads.

Most-affected servers

The worst-graded, most-flagged packages in the catalog — where triage starts. Each links to its full scan, where every finding carries its evidence, location and confidence. A grade describes the exact version that was scanned, never the project in general.

Triage feed

The most recently scanned high and critical findings, limited to confirmed and strong confidence — the rows worth reading first. Each is one finding on one server; follow the name for the evidence behind it.

critical Workbench A MTC-FLOW-002 Completed toxic-flow trifecta across tools
critical Freedom Mcp A MTC-FLOW-002 Completed toxic-flow trifecta across tools
high Freedom Mcp A MTC-CAP-001 Tool "request_attention_spawn" exposes command/code execution
high QuintaDB C MTC-UNI-009 Mixed-script (homoglyph) text in inputSchema.properties.csv_text.description
high QuintaDB C MTC-CAP-001 Tool "create_field" exposes command/code execution
high Mcp C MTC-INJ-ENC-1 Encoded-payload decode/execute instruction
high Mcp C MTC-INJ-ENC-1 Encoded-payload decode/execute instruction
high Mcp C MTC-INJ-ENC-1 Encoded-payload decode/execute instruction
critical AdvocateMCP A MTC-FLOW-002 Completed toxic-flow trifecta across tools
critical SAP MCP Server A MTC-FLOW-002 Completed toxic-flow trifecta across tools
critical Dock A MTC-FLOW-002 Completed toxic-flow trifecta across tools
critical Banking Intelligence F MTC-INJ-POISON Compound tool-poisoning pattern
high Banking Intelligence F MTC-INJ-SECRECY-1 Secrecy directive (conceal action from the user)
high ATA Travel B MTC-INJ-SECRECY-1 Secrecy directive (conceal action from the user)
critical Atom — Premium Domains F MTC-INJ-POISON Compound tool-poisoning pattern
high Atom — Premium Domains F MTC-INJ-SECRECY-1 Secrecy directive (conceal action from the user)
high Camping Australia B MTC-INJ-SECRECY-1 Secrecy directive (conceal action from the user)
high Vaaya C MTC-INJ-SECRECY-1 Secrecy directive (conceal action from the user)
high Vaaya C MTC-CAP-001 Tool "session" exposes command/code execution
high AVnester — Indian Real Estate Intelligence B MTC-INJ-SECRECY-1 Secrecy directive (conceal action from the user)

Top firing rules

Ranked by how many servers each rule flagged, not by how alarming it sounds. Titles are the engine’s own — a combosquat rule names the package it shadows, so a title can be specific to one server.

Most frequently firing rulesMTC-SRC-002: 8,422 (low)MTC-SRC-002low8,422MTC-SUP-011: 5,575 (low)MTC-SUP-011low5,575MTC-SUP-012: 4,442 (info)MTC-SUP-012info4,442MTC-SRC-003: 1,706 (medium)MTC-SRC-003medium1,706MTC-SRC-001: 1,568 (low)MTC-SRC-001low1,568MTC-SRC-005: 1,144 (medium)MTC-SRC-005medium1,144MTC-CAP-005: 1,102 (low)MTC-CAP-005low1,102MTC-SUP-010: 1,046 (low)MTC-SUP-010low1,046MTC-SRC-009: 878 (medium)MTC-SRC-009medium878MTC-NET-005: 859 (info)MTC-NET-005info859

Bar length is servers affected; colour is the rule’s severity.

RuleWhat it catchesServers
MTC-SRC-002 low Shell/command execution in server code (__main__.py) 8,422
MTC-SUP-011 low Package has no source repository 5,575
MTC-SUP-012 info Package has no license 4,442
MTC-SRC-003 medium Hardcoded egress to an external endpoint in packaging/dev tooling (worker/test/mcp.test.ts) 1,706
MTC-SRC-001 low Dynamic code execution in server code (zotero-plugin/bootstrap.js) 1,568
MTC-SRC-005 medium Dynamic module load from a non-literal in packaging/dev tooling (v3/@claude-flow/cli/dist/src/benchmarks/gaia-hardness/predictor.smoke.js) 1,144
MTC-CAP-005 low Mutating tool "zerodb_delete_file" declares no destructiveHint 1,102
MTC-SUP-010 low Package runs install-time scripts (preinstall, postinstall) 1,046
MTC-SRC-009 medium Untrusted input concatenated into a command sink (webasyst-mcp.js) 878
MTC-NET-005 info Remote HTTP MCP endpoint 859

Confidence

This is the honest part. Every finding is deterministic and evidence-backed — never an LLM’s opinion — but not every one is equally certain. 8 findings are confirmed: the engine reproduced the behaviour rather than matching a pattern near it. That is the difference between this and a heuristic code-analysis score.

Findings by confidenceconfirmed: 8 (0%)confirmed0%8strong: 38,439 (75.7%)strong75.7%38,439heuristic: 12,349 (24.3%)heuristic24.3%12,349

Counts are individual findings; the note is each level’s share.

  • confirmed — the engine reproduced the behaviour end-to-end, not merely matched a pattern
  • strong — a deterministic rule matched with solid, evidence-backed grounds
  • heuristic — a lower-certainty pattern match, flagged for a human to confirm

Scanning runs on a queue, not on page load. These figures are recomputed at most once a minute from the stored scans, and this snapshot was built 2026-09-07 15:44 UTC. Re-check any package yourself with the free API or the CLI — same input, same finding, no account needed.