MCP server builders ask whether anyone actually checks their security

NotIdealBut · reddit · 2026-07-28

A builder of MCP servers asks whether security concerns are real in practice or mostly noise. The questions are whether users, enterprise security teams, or evaluators have ever asked for proof that an MCP server is secure, and what they wanted: documentation, read-only mode, auth, or something else.

The author also asks how maintainers test for obvious issues such as unsafe execution, path traversal, and missing authentication before shipping, and says they are building a checker only if the demand is real.

Original post →

More from coding & agent

coding & agent channel →