AI · 7h ago
OX Security audited 15,465 public Model Context Protocol (MCP) servers and found marketplaces with no vetting or governance. The sample included servers on expired domains, consumer tunnel services, and infrastructure outside the United States.
The problem is identity drift: a listing can point to where a server used to live, or where its developer says it lives, without proving who runs it now. If the domain expires or the host is a personal machine, the same integration name can quietly resolve to a different operator, so agents may send data to unapproved jurisdictions or hands.
For teams wiring AI assistants into third-party tools and data sources, the trust boundary is the backend host, not the public listing. If you treat the registry entry as proof of approval, you can inherit whatever machine, owner, or network sits behind it today.
1 source covering this story
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
OX found no marketplace vetting across 15,465 indexed MCP servers, including expired domains and hosts routed through consumer tunnels.
Part of the PlainSec briefing for 2026-10-06