Thousands of Public AI Connectors Found With No Vetting: What Businesses Need to Know About MCP Servers
MCP (Model Context Protocol) was introduced in 2024 as a common standard for connecting AI models, agents and developer tools to other tools and data. Many developers have built MCP servers, and enterprises have plugged them into agent workflows. Researchers at OX Security say the ecosystem around the protocol has not kept pace. They examined 15,465 publicly indexed MCP servers across 5 registries, which reduced to 5,095 unique hostnames once duplicates were removed.
Their central finding is that the marketplaces have no equivalent of the automated malware checks once used for Android apps. Anyone can write a server and publish it. Even a review would not fully close the gap, because remote MCP servers can run backend code that differs entirely from what their public repository shows. Code review reveals what the developer published, not what the server actually runs. A server's location can also change: an operator could launch on a clean US IP address and later route traffic elsewhere.
OX Security notes that businesses spent a decade building governance to use public cloud safely, including data residency rules, Zero Trust boundaries and supply chain audits. MCP connections often sit outside all of these controls. The researchers say the protocol itself is not the problem; the trust placed in it is. Until marketplaces add vetting, code signing and origin verification, they argue the organisations using these servers must do that work themselves.