- 69 critical vulnerabilities - 32 servers using eval() on untrusted input - 31 SQL injection vulnerabilities - 32 servers with hardcoded API credentials
10.5% of servers have at least one critical vulnerability.
MCP servers run with your permissions. AI agents trust them implicitly. A prompt injection can exploit them remotely.
MCPSafe (https://mcpsafe.org) lets you scan before you connect. Free tier includes 30 top servers.
Feedback welcome: What patterns are we missing? CI/CD integration useful?