675 MCP Servers Scored on Security: 89% Fail, Only 6 Deemed Safe
Low_Location1261 · reddit · 2026-09-04
RepoAI scored all 675 published MCP servers in its directory on 15 structural security signals (read-only mode, auth, maintenance, publisher). Results: only 0.9% rated safe, 9.8% medium, 89.3% high risk.
Key findings
- 92.1% offer no read-only mode — installs get full read/write access
- 35.9% ship dangerous tools (code execution, deletion, file writes); 43.1% of those have no read-only escape hatch
- Only 14.7% support OAuth; 1.9% have no authentication at all
- Only 12% are published by the actual vendor
Ruling out selection bias: 20 popular unindexed GitHub MCP servers (top: 1,860 stars) were scored cold — none reached medium tier, best was 55/100.
Case study: mcp-server-trello exposes 35 tools including dangerous delete operations with no read-only mode, scoring 20/100.
The authors invoke Log4Shell (dormant for 8 years) to argue absence of incidents isn't evidence of safety, and highlight MCP's specific prompt-injection attack surface: an assistant needs no server bug to be tricked into abusing its permissions.
More from coding & agent
- A visual AI learning roadmap: 3Blue1Brown, Transformer Explainer, Neuronpedia and more — techNmak · 2026-09-04
- 3Blue1Brown and LLM Visualization: the best ways to build geometric intuition for AI — techNmak · 2026-09-04
- Transformer Explainer lets you watch your text flow through GPT-2, token by token — techNmak · 2026-09-04
- Meta's Research Preference Models paper teaches AI agents 'research taste' — Ibrahimdidamson · 2026-09-04
- Dev has an agent audit its own traces to flag fishy behavior, skips real-time watching — lucasmeijer · 2026-09-04
- MIT professor runs Grok agent team from photos to 3D-printed part end to end — ProfBuehlerMIT · 2026-09-04