// AI threat desk · 30 Sept 2026
Sample content · apart from the Arup deepfake case, every company, product and CVE ID is fictional
Home/AGENT · Agent Security
Agent SecurityMediumMCP

Audit of 2,000 MCP servers finds 41% ask for more access than they use

An audit of 2,000 public MCP servers found 41% request file or network access beyond what their tools need, widening what a prompt-injected agent can reach.

An audit of 2,000 public MCP servers found 41% request file or network access beyond what their tools need, widening what a prompt-injected agent can reach.

Sample content: on the live site this story follows the same structure, with what happened, who is affected, what to do, an FAQ and sources.

Explore with AI