the open-tool gap · 2026 edition · early findings
MCP Servers · an early security read · 2026
Early findings — small sample, growing. Reported descriptively, not as a "State of" claim.
MCP is the newest way to give an AI real tools. We scanned 48 servers from our catalog straight from their repositories; 24 are network-exposed (the rest run locally over stdio, where network auth doesn't apply). This is an early read on a young protocol — the sample is small and growing.
48 scanned · 24 network-exposed (auth assessed) · 24 run locally over stdio, where network auth does not apply.
The findings
- No rate limiting — 92%One caller can hammer the server or run up the bill.
- No error tracking — 88%Failures happen silently — nobody finds out.
- No authentication — 29%The server runs tools for anyone who can reach it — no API key, no token.
- Committed .env — 2%Credentials checked into the repo.
- Leaked secret — 0%A secret key shipped in the code — anyone can steal it.
Why MCP is the scary one
An MCP server hands an AI the keys to *do things* — read files, hit APIs, run code. When a network-exposed one ships with no authentication, anyone who can reach it gets those keys too. This is the newest category, with the least settled security culture.
Early findings, stated plainly
Of the 24 network-exposed servers we could assess for auth, 7 require none. That's an early signal on a small sample — not a verdict on every MCP server. The 24 that run over stdio are excluded from the auth count, because network auth doesn't apply to a local process. We'll keep widening the sample.
Sample composition
Not a random sample — this is what we measured. The mix below is the caveat; judge it for yourself.
- MCP & Integrations: 47
- Other: 1
- Largest single maker: 6% (vercel, 3)
What we measured (48)
The full list, so anyone can spot-check. Every item links to its public benchmark.
- @langchain/mcp-adapters
- n8n-mcp
- @modelcontextprotocol/ext-apps
- n8n-nodes-mcp
- argocd-mcp
- mcp-handler
- GhidraMCP
- @shortcut/mcp
- @mcp-use/inspector
- @notionhq/notion-mcp-server
- @traceloop/instrumentation-mcp
- @storybook/mcp
- github-mcp-server
- pal-mcp-server
- chrome-devtools-mcp
- mcpsnoop
- arkon
- Tradingview-MCP
- tradingview-mcp
- tradingview-mcp
- add-mcp
- @agentmemory/mcp
- @azure-devops/mcp
- @clerk/mcp-tools
- @expo/mcp-tunnel
- hostinger-api-mcp
- mcp-framework
- @mobilenext/mobile-mcp
- @penpot/mcp
- next-devtools-mcp
- @payloadcms/plugin-mcp
- @rekog/mcp-nest
- @salesforce/mcp
- @sap-ux/fiori-mcp-server
- @supabase/mcp-utils
- @ui5/mcp-server
- @vercel/mcp-adapter
- playwright-mcp
- @azure/mcp
- tavily-mcp
- cc-connect
- mcp-searxng
- @upstash/context7-mcp
- mcp-chrome
- bb-browser
- Windows-MCP
- @eslint/mcp
- miniapp-cdp-mcp