// AI threat desk · 6 Oct 2026
Home/AGENT · Agent Security
Agent SecurityMediumMCPCVSS not assigned

MCP servers lacked guardrails in OX Security analysis

OX Security analyzed 15,465 publicly indexed MCP servers and found no guardrails or review in community marketplaces.

AI-generated image of security analysts reviewing blurred server listings and code on monitors in a security operations centre.
AI-generated image, not a photo of the event.
Key takeaways
  • OX Security analyzed 15,465 publicly indexed MCP servers across five registries, representing 5,095 unique hostnames.
  • OX Security said community-published MCP server marketplaces had no guardrails or review.
  • OX Security said remote MCP servers can run backend code that differs from their public repositories.

OX Security said it analyzed 15,465 publicly indexed MCP servers across five registries, finding no guardrails or review in community-published marketplaces.

The findings matter for organizations connecting AI agents to remote MCP servers. OX Security said those servers can run backend code that differs from their public repositories, while agents connected to some of them may send data to jurisdictions a security team never approved.

The analysis covered 5,095 unique hostnames after deduplication. OX Security said it had earlier traced critical vulnerabilities in Anthropic’s MCP source code, which had been downloaded more than 150 million times.

On this page

Remote MCP servers can differ from their public repositories

OX Security said a remote MCP server may run backend code that differs entirely from the code shown in its public repository. That creates a gap between what a team reviews and what an agent reaches when it connects to the server.

OX Security found exposed infrastructure and abandoned domains

OX Security said 15.6% of hostnames resolve to infrastructure outside the United States, including 19 in China and 18 in Russia. It also said 0.45% route traffic through consumer tunneling services, mainly ngrok-free.

The company said 2.3% of servers no longer resolved, and six sat on expired domains that anyone could register for $4 to $12 a year. A new owner could inherit an established server identity and requests from agents still configured to call it.

OX Security said that until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work.

OX Security said its full report covers its methodology, a prompt-injection proof of concept, and the threat scenarios behind each finding.

FAQ

What did OX Security find in its MCP server analysis?

OX Security said it analyzed 15,465 publicly indexed MCP servers across five registries and found no guardrails or review in community-published marketplaces.

Can remote MCP servers run code that is not in their public repositories?

OX Security said remote MCP servers can run backend code that differs entirely from what their public repositories show.

Can MCP servers send data outside an approved jurisdiction?

OX Security said an agent connected to some servers may send data to jurisdictions the security team never approved.

What happened to the MCP servers on expired domains?

OX Security said six servers sat on expired domains that anyone could register for $4 to $12 a year, and a new owner could inherit the server identity and requests from agents still configured to call it.

Sources

  1. Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers, The Hacker News
How we checked this story
ClaimSourceStatus
OX Security said it analyzed 15,465 publicly indexed MCP servers across five MCP registries.OX Security, via The Hacker NewsAttributed
OX Security said 15.6% of hostnames resolved to infrastructure outside the United States.OX Security, via The Hacker NewsAttributed
OX Security said 19 hostnames were in China and 18 were in Russia.OX Security, via The Hacker NewsAttributed
OX Security said 0.45% of publicly listed servers routed traffic through consumer tunneling services.OX Security, via The Hacker NewsAttributed
OX Security said 2.3% of servers no longer resolved and six sat on expired domains.OX Security, via The Hacker NewsAttributed
OX Security said remote MCP servers can run backend code that differs from their public repositories.OX Security, via The Hacker NewsAttributed
OX Security said an agent connected to some servers may send data to jurisdictions the security team never approved.OX Security, via The Hacker NewsAttributed
OX Security said a new owner could inherit an established server identity and requests from agents still configured to call it.OX Security, via The Hacker NewsAttributed
OX Security said its full report covers its methodology, a prompt-injection proof of concept, and threat scenarios.OX Security, via The Hacker NewsAttributed
OX Security said it had previously traced critical vulnerabilities in Anthropic’s MCP source code.OX Security, via The Hacker NewsAttributed

Could not verify

  • Whether any MCP server was exploited is not established
  • Whether any organization or user was harmed is not established
  • Whether the reported findings correspond to CVEs is not established
  • How many MCP servers exposed sensitive data is not established
Explore with AI