In 2024, the Model Context Protocol (MCP) was introduced to act like the USB-C of AI: a universal standard allowing AI models, agents, and tools to hook up to data and each other. It achieved rapid adoption. Yet a new investigation reveals that while the protocol works, its surrounding ecosystem is almost entirely unregulated. That could leave sensitive data and enterprise systems exposed — especially through the hundreds of publicly published MCP servers with no oversight.
Security researchers with OX Security recently analyzed thousands of public MCP servers across popular marketplaces and registries. What they uncovered paints a wild frontier: production-quality servers in the hands of unknown operators, running off personal machines, spanning global jurisdictions, and often left to run unchecked.
A Marketplace Without Gatekeepers
Unlike app stores with malware scanning or security checks, MCP marketplaces have no process to vet servers before listing. Anyone can publish a server, no questions asked. Even if code is open source, what’s listed publicly might differ substantially from what’s running behind the scenes. Public repositories don’t guarantee safety when remote servers can host entirely different backends.
What the Numbers Reveal
The OX Security team catalogued 15,465 publicly indexed MCP servers across five registries, which boiled down to 5,095 unique hostnames after removing duplicates. Key findings include:
- About 15.6% of hostnames point to infrastructure outside the United States, including servers located in China and Russia. That raises serious concerns for enterprises governed by data residency rules.
- Approximately 0.45% use consumer tunneling services (like free tiers of ngrok), suggesting many servers run from home networks or personal machines.
- Around 2.3% are associated with dangling domains that no longer resolve correctly. Six domains have already expired and are available for cheap purchase — meaning an attacker could seize an identity previously tied to a now-abandoned server.
Beyond that, locations can shift over time: servers launched in compliant jurisdictions under a trusted IP may later move, and traffic can be rerouted without detection, undermining governance and trust frameworks.
These risks are especially acute for enterprises that expect all components of their AI supply chain to adhere to standards like Zero Trust, granular access control, and audited usage. MCP connections often fall outside such structures. If a server you rely on is handled by someone in another country, or is running code different from what a public repo shows, then your compliance controls could be meaningless.
Trust Is the Real Vulnerability
The report emphasizes that MCP itself isn’t broken. The protocol provides utility and flexibility. The problem is in the permissions and trust we grant it silently. Without vetting, code signing, strict origin verification, or policies governing who can deploy and operate servers, enterprises are forced to assume risk instead of managing it.
Unchecked MCP servers are more than a theoretical danger: they can lead to prompt injection attacks, data exfiltration, and violations of compliance — especially when critical workloads depend on them. Enterprises relying on tools and agents connected through MPC need to treat external servers as high-risk third parties.
OX Security has released a full report, “15,465 MCP Servers, 0 Governance,” which probes their methodology, threat models, and proof-of-concept vulnerabilities. It makes clear that enterprises need to demand governance if MCP is going to be safe at scale.
Why this matters: MCP adoption is accelerating fast, especially among AI agents and cloud data pipelines. If governance doesn’t catch up, every public server you plug into could open the door to data leaks, supply-chain attacks, or worse. Going forward, organizations should insist on vetting standards, audit trails, signing mechanisms, and firm policies about server origin. In the jungle of MCP servers, those are the machetes you’ll need to survive.