How are you actually vetting MCP servers before you install them?
Summary
A discussion about the lack of vetting for MCP servers before installation, highlighting a study that found 5.5% tool-poisoned and 14.4% with known bugs, plus a systemic RCE in the MCP SDK.
Similar Articles
Anyone actually doing security review on MCP servers before devs install them?
A question about whether anyone is conducting security reviews on MCP servers before developers install them, highlighting a potential vulnerability in the AI tool ecosystem.
10%+ of MCP servers leak credentials/PII through tool responses, not network calls - SAST/DAST can’t see it
A security report reveals that over 10% of MCP servers leak credentials or personally identifiable information through tool responses, bypassing traditional SAST/DAST scanning.
What's actually in your MCP allowlist?
Raises security concerns about blindly trusting MCP server allowlists without reviewing tool schemas, comparing it to piping curl into bash in 2013.
The State of MCP Security [pdf]
This PDF report examines the current state of security for the Model Context Protocol (MCP), covering vulnerabilities and best practices.
Most MCP servers don't need to exist. Your case might be an exception
Most MCP servers are unnecessary; this article presents a framework for deciding when an MCP server is warranted, emphasizing the need for stable APIs and CLIs first.