21,000 exposed servers with 92% lacking OAuth. The OWASP MCP Top 10 is a good start.... but it's reactive. It doesn't address the fundamental issue. There's no standard way to verify what an MCP server actually does before you connect to it. Not without studying the github repo, if one is even available.
We need lockfiles, audit commands, and signed provenance, just like we got with npm.
Wpnx330•1h ago
We need lockfiles, audit commands, and signed provenance, just like we got with npm.