Legit.Show is a directory of launched web apps, SaaS, AI tools, MCP servers and developer tools — each with an objective 7-Frame production-readiness benchmark, measured deterministically from the public surface. How we measure →


Legit.Show benchmarks every launched service it lists — measured deterministically from the public surface. See the methodology →

Cross-links · Directory · Reports · Methodology · About

Privacy · Terms · operated by Madeflo Inc., a Delaware corporation. Benchmark engine powered by commit.show.

the open-tool gap · 2026 edition · early findings

MCP Servers · an early security read · 2026

Early findings — small sample, growing. Reported descriptively, not as a "State of" claim.

MCP is the newest way to give an AI real tools. We scanned 48 servers from our catalog straight from their repositories; 24 are network-exposed (the rest run locally over stdio, where network auth doesn't apply). This is an early read on a young protocol — the sample is small and growing.

29%
require no authentication
across 24 network-exposed MCP servers we scanned · according to Legit.Show · 2026

48 scanned · 24 network-exposed (auth assessed) · 24 run locally over stdio, where network auth does not apply.

The findings

Why MCP is the scary one

An MCP server hands an AI the keys to *do things* — read files, hit APIs, run code. When a network-exposed one ships with no authentication, anyone who can reach it gets those keys too. This is the newest category, with the least settled security culture.

Early findings, stated plainly

Of the 24 network-exposed servers we could assess for auth, 7 require none. That's an early signal on a small sample — not a verdict on every MCP server. The 24 that run over stdio are excluded from the auth count, because network auth doesn't apply to a local process. We'll keep widening the sample.

Sample composition

Not a random sample — this is what we measured. The mix below is the caveat; judge it for yourself.

What we measured (48)

The full list, so anyone can spot-check. Every item links to its public benchmark.

How this was measured →