the open-tool gap · 2026 edition · early findings
MCP Servers · an early security read · 2026
Early findings — small sample, growing. Reported descriptively, not as a "State of" claim.
MCP is the newest way to give an AI real tools. We scanned 86 servers from our catalog straight from their repositories; 27 are network-exposed (the rest run locally over stdio, where network auth doesn't apply). This is an early read on a young protocol — the sample is small and growing.
86 scanned · 27 network-exposed (auth assessed) · 59 run locally over stdio, where network auth does not apply.
The findings
- No error tracking declared — 95%Nothing declared in the public repo — dashboard-only setups are invisible here.
- No rate limiting declared — 81%Nothing declared in the public repo — a limit set at a CDN or gateway is invisible here.
- No authentication — 0%The server runs tools for anyone who can reach it — no API key, no token.
- Leaked secret — 0%A secret key shipped in the code — anyone can steal it.
- Committed .env — 0%Credentials checked into the repo.
Why MCP is the scary one
An MCP server hands an AI the keys to *do things* — read files, hit APIs, run code. When a network-exposed one ships with no authentication, anyone who can reach it gets those keys too. This is the newest category, with the least settled security culture.
Early findings, stated plainly
Of the 27 network-exposed servers we could assess for auth, 0 require none. That's an early signal on a small sample — not a verdict on every MCP server. The 59 that run over stdio are excluded from the auth count, because network auth doesn't apply to a local process. We'll keep widening the sample.
Sample composition
Not a random sample — this is what we measured. The mix below is the caveat; judge it for yourself.
- MCP & Integrations: 76
- AI & Agents: 4
- Developer Tools: 2
- Other: 2
- Frameworks & Starter Kits: 1
- Infrastructure & DevOps: 1
- Largest single maker: 3% (microsoft, 3)
What we measured (86)
The full list, so anyone can spot-check. Every item links to its public benchmark.
- @expo/mcp-tunnel
- skillgesture
- @azure-devops/mcp
- @shortcut/mcp
- mcp-use
- OSM Edit MCP
- mcp-handler
- CodexPro
- @mobilenext/mobile-mcp
- Desktop Commander
- @sap-ux/fiori-mcp-server
- mcptoon
- @mcp-use/inspector
- @langchain/mcp-adapters
- @penpot/mcp
- @supabase/mcp-utils
- mcp-searxng
- mcpscore
- n8n-nodes-mcp
- cc-connect
- withmcp
- DataNexus MCP
- GhidraMCP
- GitMCP
- mcp-auth-keydris-template
- NotFair
- fentaris
- tradingview-mcp
- mcpsnoop
- lain
- MCP TypeScript SDK
- @storybook/mcp
- MCP Python SDK
- @azure/mcp
- handoff
- contextplus
- MCPersist
- hexstrike-ai
- AnySearch
- arkon
- miniapp-cdp-mcp
- opencode-mempalace-persistence
- @clerk/mcp-tools
- Constraint Programming in Your AI Agent
- fastmcp
- mcp-framework
- @agentmemory/mcp
- אחיה אוטומציה
- declick
- @rekog/mcp-nest
- webmcp-stack
- playwright-mcp
- bb-browser
- firecrawl-mcp-server
- Astah Pro MCP – Enabling AI-Powered UML Modeling
- add-mcp
- @modelcontextprotocol/ext-apps
- @notionhq/notion-mcp-server
- webmcp-react
- Figma-Context-MCP
- computer-use-mcp
- Windows-MCP
- mcp
- Tarfio bounded spending controls for MCP tools
- Blender MCP by ArchBench
- c64-kb
- next-devtools-mcp
- Jira Project Health Auditor (MCP Server)
- deepmem-claude-plugin
- @traceloop/instrumentation-mcp
- hostinger-api-mcp
- intermcp
- @vercel/mcp-adapter
- connect-mcp
- Tradingview-MCP
- @payloadcms/plugin-mcp
- @salesforce/mcp
- Use Strava's official MCP with other chatbots
- Concord AI
- @ui5/mcp-server
- @eslint/mcp
- tavily-mcp
- ai-engineering-hub
- gopher
- tradingview-mcp
- n8n-mcp