Model Context Protocol (MCP) is Anthropic’s open standard for connecting AI agents to external tools and data sources. The case cites Censys as counting 12,520 internet-accessible MCP services on April 28, 2026 and more than 21,000 by May 6, while other supplied reports describe unauthenticated deployments, exploitable server flaws, and risks involving identity, supply chains, prompt injection, data exfiltration, and unauthorized file access. However, the snippets do not independently confirm Censys’s exact 21,000 count or establish that all—or most—of those exposed services are exploitable; they support exposure as a serious attack surface and recommend gateways, least privilege, sandboxing, egress controls, and monitoring rather than documenting a broad confirmed compromise.
The radar already tracks this same development in `radar:remote-mcp-auth-exposure-study`, which covers publicly reachable, unauthenticated MCP servers and the need for follow-up audits. The reported scale bears directly on Scott’s production MCP connector and his existing position that MCP is not itself a security boundary, but the unverified 21,000 count and absence of demonstrated broad compromise limit the new actionable signal.
ip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:framework.siloosdev:project.mcp-ip-wikiradar:remote-mcp-auth-exposure-studyradar:concept.mcp-security
queries asked of Scott's wikis
- MCP threat model and secure deployment defaults
- agent tool capability boundaries and least privilege
- gateways and sandboxing for agent tool servers
- prompt injection across tool and data trust boundaries
- agent tool supply-chain verification and change monitoring
- internet-exposed agent infrastructure and egress controls
2026-08-30T11:32:15Z
The episode has exhausted its evidence ladder without an updated exposure audit, broad exploitation evidence, or adoption of stronger defaults. MCP remains a credible security surface, but the specific 21,000-server hypothesis has faded without enough movement to keep this case active.
2026-08-28T11:24:59Z
The signed-in-browser MCP artifact repeats the already established pattern of agents receiving high-privilege session access. It adds no exposure measurement, exploit, compromise, adoption signal, or stronger safeguard response, so the case remains corroborated but cold.
2026-08-28T11:23:25Z
evidence attached: hn.story.49476743 — A first-party MCP artifact that drives an already signed-in browser materially illustrates the credential and session exposure risks of MCP deployments.
2026-08-27T20:43:35Z
The remote-HTTPS wrapper lowers friction for publishing MCP servers and therefore modestly expands the prospective exposure surface, but it provides no evidence of insecure defaults, adoption, new vulnerable deployments, or exploitation. The case remains a corroborated security concern with early mitigation activity, not an accelerating ecosystem incident.
2026-08-27T20:24:47Z
evidence attached: hn.story.49470457 — A first-party artifact for putting MCP servers on the public web expands the deployment and exposure surface relevant to MCP security risk.
2026-08-26T14:39:34Z
The Semgrep rulesets broaden the ecosystem response from isolated vulnerability reports and sandbox prototypes to reusable MCP auditing tooling. Their coverage, findings, adoption, and influence on deployment defaults remain unknown, so they do not establish widespread exploitability or justify promotion to accelerating.
2026-08-26T14:25:04Z
evidence attached: hn.story.49449062 — These released Semgrep rulesets provide independent, usable security tooling for auditing MCP servers and materially corroborate the MCP exposure-risk episode.
2026-08-25T13:36:49Z
mcpd adds a concrete implementation of sandbox-separated MCP tool execution, modestly broadening evidence that practitioners are building mitigations. It remains an early, unadopted artifact and does not verify widespread vulnerability among exposed servers or establish stronger ecosystem defaults.
2026-08-25T13:24:39Z
evidence attached: hn.story.49433211 — A concrete sandboxed MCP implementation provides relevant evidence about separating agent loops from privileged tool execution.
2026-08-25T07:29:35Z
The high-severity SSRF CVE in Google’s official MCP Toolbox adds a verified, implementation-level exploit path and a concrete vendor safeguard response, moving the case beyond exposure estimates and hypothetical failure modes. It still does not show that a material share of the roughly 21,000 exposed servers is vulnerable or that stronger defaults are spreading ecosystem-wide.
2026-08-25T07:23:06Z
evidence attached: hn.story.49429926 — A concrete CVE in Google’s official MCP Toolbox independently corroborates that agent-facing MCP infrastructure has exploitable security weaknesses.
2026-08-23T13:34:31Z
No new verification, compromise evidence, adoption of Mcploitable, or stronger deployment defaults has appeared. The case remains a credible but unquantified attack-surface concern rather than evidence of widespread exploitable risk, and is now cold pending a substantive audit or ecosystem response.
2026-08-21T13:28:52Z
Mcploitable marks a modest ecosystem response by turning MCP security failure modes into a practical testing artifact, but the available evidence does not establish its coverage or adoption. It neither verifies widespread exploitability among the exposed-server population nor shows materially stronger deployment defaults.
2026-08-21T13:23:07Z
evidence attached: hn.story.49387017 — Mcploitable is a concrete MCP security-testing artifact that materially contextualizes the risks and mitigations around exposed MCP servers.
2026-08-19T15:47:18Z
The expanded NeoBrowser discussion remains repetitive amplification of a known high-privilege MCP usage pattern, without a demonstrated exposure, exploit, compromise, or safeguard response. The central claim that the public-server population creates widespread exploitable risk remains uncorroborated.
2026-08-18T15:45:26Z
The refreshed discussion only reinforces that developers intentionally give browser MCP tools authenticated-session access; it adds no exposure, exploit, compromise, or safeguard response. With the central 21,000-server risk claim still unverified, this is repetitive amplification and the case cools.
2026-08-18T14:46:27Z
NeoBrowser makes the potential blast radius more concrete by packaging MCP access to authenticated browser sessions, and comments suggest this is a desired usage pattern. It still provides no evidence that the counted public servers are broadly exploitable or that maintainers are strengthening deployment defaults, so the case does not advance.
2026-08-18T14:23:50Z
evidence attached: hn.story.49345320 — A concrete MCP server reusing logged-in browser sessions illustrates the high-impact capabilities and security exposure at stake in MCP deployments.
2026-08-17T14:05:41Z
The duplicate-execution finding adds a concrete MCP implementation failure mode, but remains a single narrow report without demonstrated exploitability, broad applicability, or vendor response. It does not independently verify widespread risk across the exposed-server population or show movement toward stronger ecosystem defaults.
2026-08-17T13:23:28Z
evidence attached: hn.story.49329849 — A concrete statically discovered MCP duplicate-execution vulnerability materially strengthens the case that MCP tooling needs stronger security review and deployment safeguards.
2026-08-16T08:24:18Z
The Composio credential incident adds a distinct, concrete example of agent-integration blast radius, moving the case beyond a scanner-derived exposure count. It strengthens the argument for broker credential isolation and least privilege, but does not yet corroborate widespread exploitability among the reported 21,000 MCP servers or an ecosystem safeguard response.
2026-08-16T07:22:25Z
evidence attached: hn.story.49317473 — This concrete incident independently corroborates that agent integration platforms can expose live credentials and strengthens the case for ecosystem-wide safeguards.
2026-08-16T05:28:09Z
Re-evaluation adds no corroboration: Censys’s count remains credible evidence of a large discoverable MCP footprint, not evidence that most servers are unauthenticated, exploitable, or driving stronger deployment defaults.
2026-08-16T05:26:15Z
grounded: known/medium — The radar already tracks this same development in `radar:remote-mcp-auth-exposure-study`, which covers publicly reachable, unauthenticated MCP servers and the n
2026-08-16T05:23:22Z
origin walked (codex/luna, conf 0.99): anchor hn.story.49316815 -> echo.blog.7b7dcfdee6 by Censys
2026-08-16T05:22:25Z
case created — The ecosystem-scale exposure claim is concrete and security-relevant, but currently rests on a single report with limited corroboration.