- OX Security analyzed 15,465 publicly indexed MCP servers across five registries, representing 5,095 unique hostnames.
- OX Security said community-published MCP server marketplaces had no guardrails or review.
- OX Security said remote MCP servers can run backend code that differs from their public repositories.
OX Security said it analyzed 15,465 publicly indexed MCP servers across five registries, finding no guardrails or review in community-published marketplaces.
The findings matter for organizations connecting AI agents to remote MCP servers. OX Security said those servers can run backend code that differs from their public repositories, while agents connected to some of them may send data to jurisdictions a security team never approved.
The analysis covered 5,095 unique hostnames after deduplication. OX Security said it had earlier traced critical vulnerabilities in Anthropic’s MCP source code, which had been downloaded more than 150 million times.
On this page
Remote MCP servers can differ from their public repositories
OX Security said a remote MCP server may run backend code that differs entirely from the code shown in its public repository. That creates a gap between what a team reviews and what an agent reaches when it connects to the server.
OX Security found exposed infrastructure and abandoned domains
OX Security said 15.6% of hostnames resolve to infrastructure outside the United States, including 19 in China and 18 in Russia. It also said 0.45% route traffic through consumer tunneling services, mainly ngrok-free.
The company said 2.3% of servers no longer resolved, and six sat on expired domains that anyone could register for $4 to $12 a year. A new owner could inherit an established server identity and requests from agents still configured to call it.
OX Security said that until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work.
OX Security said its full report covers its methodology, a prompt-injection proof of concept, and the threat scenarios behind each finding.
FAQ
What did OX Security find in its MCP server analysis?
OX Security said it analyzed 15,465 publicly indexed MCP servers across five registries and found no guardrails or review in community-published marketplaces.
Can remote MCP servers run code that is not in their public repositories?
OX Security said remote MCP servers can run backend code that differs entirely from what their public repositories show.
Can MCP servers send data outside an approved jurisdiction?
OX Security said an agent connected to some servers may send data to jurisdictions the security team never approved.
What happened to the MCP servers on expired domains?
OX Security said six servers sat on expired domains that anyone could register for $4 to $12 a year, and a new owner could inherit the server identity and requests from agents still configured to call it.
Sources
How we checked this story
| Claim | Source | Status |
|---|---|---|
| OX Security said it analyzed 15,465 publicly indexed MCP servers across five MCP registries. | OX Security, via The Hacker News | Attributed |
| OX Security said 15.6% of hostnames resolved to infrastructure outside the United States. | OX Security, via The Hacker News | Attributed |
| OX Security said 19 hostnames were in China and 18 were in Russia. | OX Security, via The Hacker News | Attributed |
| OX Security said 0.45% of publicly listed servers routed traffic through consumer tunneling services. | OX Security, via The Hacker News | Attributed |
| OX Security said 2.3% of servers no longer resolved and six sat on expired domains. | OX Security, via The Hacker News | Attributed |
| OX Security said remote MCP servers can run backend code that differs from their public repositories. | OX Security, via The Hacker News | Attributed |
| OX Security said an agent connected to some servers may send data to jurisdictions the security team never approved. | OX Security, via The Hacker News | Attributed |
| OX Security said a new owner could inherit an established server identity and requests from agents still configured to call it. | OX Security, via The Hacker News | Attributed |
| OX Security said its full report covers its methodology, a prompt-injection proof of concept, and threat scenarios. | OX Security, via The Hacker News | Attributed |
| OX Security said it had previously traced critical vulnerabilities in Anthropic’s MCP source code. | OX Security, via The Hacker News | Attributed |
Could not verify
- Whether any MCP server was exploited is not established
- Whether any organization or user was harmed is not established
- Whether the reported findings correspond to CVEs is not established
- How many MCP servers exposed sensitive data is not established



