AI security
15,465 public MCP servers, and no vetting before you connect
OX Security mapped 15,465 listed MCP servers: hosts in China and Russia, home tunnels and lapsed domains. How to gate what your AI agents connect to.
OX Security has mapped where the public Model Context Protocol (MCP) ecosystem actually runs. MCP is the standard AI agents such as Claude Code, Cursor and Cline use to call outside tools, and each tool lives on an MCP server that someone else operates. The researchers pulled 15,465 servers from three public listings (the official MCP registry, the Cline marketplace and the GitHub MCP registry), reduced them to 5,095 unique hostnames and checked where each one resolves, who hosts it and whether the domain still exists. They published the report on September 24, and a summary ran in The Hacker News on October 6.
The results describe a supply chain with no gate. 796 hostnames resolve outside the United States, including 19 in China and 18 in Russia. Some servers run from home connections and tunnelling tools, and six of the domains have lapsed and can be registered for $4 to $12 a year. None of the listings checks any of this before a server is published. If your developers add MCP servers to their agents, you have this exposure whether or not anyone approved those servers.
What the scan found
OX started from 16,296 endpoints in the registry listings, which came down to 7,791 unique URLs and then 5,095 hostnames. Every percentage below is a share of those hostnames.
796 hostnames, 15.6%, resolve outside the US. MCP has no field for region, so nothing in the protocol tells a client where a tool runs or where the data it receives is processed. A team that keeps customer data in the EU, or is barred from sending it to certain countries, finds out only by resolving the hostname itself.
About 0.45% sit on home networks or consumer tunnels, reachable through residential broadband or through tools such as ngrok that expose a laptop to the internet. Whatever an agent sends to them lands on a personal machine, outside any company's access controls, logging or uptime commitments.
Another 2.3% no longer resolve, and six of those domains are unregistered. A listing, a README or a developer's config that still points at one of these names will connect to whoever registers it next. OX warns that a new owner could stand up a server under the old name, offer malicious tools, collect whatever clients send, or feed crafted content to agents that still trust the endpoint. OX has not published the six names.
Why a listing tells you little about a server
A remote MCP server is a web service. The client sees the tool names and descriptions the server returns at connection time and nothing else. The researchers point out that the code running behind a remote endpoint does not have to match the GitHub repository linked from its listing, and that the operator can change it at any time after you approve it. A repository review only covers the code as it stood on the day you read it.
Local servers have a different version of the problem. A stdio server (one the agent launches as a local process, usually with npx or uvx) runs whatever package version resolves at launch unless the command pins one.
The always-allow test
OX also tested what a hostile server can do once it is trusted. Its server first asked the agent for a harmless file read. The tester approved it with "always allow", the option that stops the client asking again for that kind of action. The server then used prompt injection, meaning instructions hidden in its tool output, to have the agent read the project's .env file, and the agent did so without a new prompt. This worked in Claude Code running Haiku 3.5. Claude Opus 4.6 and 4.7 spotted the injected instructions and refused.
A newer model blocked the attack here, yet model behaviour is hard to audit and changes between releases. With a standing approval in place, the model is the only thing between a hostile server and a secrets file.
What attackers are doing
OX reports exposure only. Neither the report nor the coverage describes anyone registering the lapsed domains, abusing the home-hosted servers or running the always-allow technique outside the lab. RuntimeWire's write-up notes the findings do not show which of these servers enterprises actually use. The numbers measure exposure that could be abused, and the fixes below close it.
What to do
1. Find every MCP server already in use
Developers add these servers themselves, so start on their machines. In Claude Code, claude mcp list shows each server with its source and connection status. The configs live in ~/.claude.json (user and per-project servers) and .mcp.json in each repository root. Cursor uses ~/.cursor/mcp.json and .cursor/mcp.json, and VS Code uses .vscode/mcp.json. Search your repositories for .mcp.json and mcp.json files too, because those servers load for everyone who clones the repo.
For every remote URL, resolve the hostname and look up who hosts it and where. Drop anything that resolves to a residential ISP, a tunnelling service such as *.ngrok-free.app or *.trycloudflare.com, a region your data rules exclude, or a domain that no longer resolves. For stdio servers, check that the command pins a version, for example npx -y @scope/server@1.4.2 rather than the bare package name.
2. Enforce an allowlist centrally
Claude Code reads MCP policy from managed settings. Put allowedMcpServers with { "serverUrl": "https://mcp.example.com/*" } entries for remote servers and { "serverCommand": ["npx", "-y", "@scope/server@1.4.2"] } entries for local ones, and set "allowManagedMcpServersOnly": true so users cannot widen the list in their own settings. Do not rely on serverName entries: Anthropic's documentation notes the name is a label the user picks. For a fixed set, deploy managed-mcp.json to /etc/claude-code/ on Linux, /Library/Application Support/ClaudeCode/ on macOS or C:\Program Files\ClaudeCode\ on Windows. An empty "mcpServers": {} there turns MCP off. Check that it took effect: claude mcp add --transport http test https://example.com/mcp should fail with an enterprise policy error.
Watch your allowlisted domains' registration expiry as well. A domain on your own allowlist that lapses becomes the takeover OX describes.
3. Remove standing approvals around secrets
Add deny rules so no tool approval can reach credential files, for example "permissions": { "deny": ["Read(./.env)", "Read(./.env.*)", "Read(~/.aws/**)", "Read(~/.ssh/**)"] } in managed settings. Ask developers to review the allow rules they have built up in ~/.claude/settings.json and .claude/settings.local.json and remove broad mcp__<server> entries for third-party servers. Keep tools that write, send or delete on a per-call prompt.
4. Check whether anything was already exposed
Claude Code keeps session transcripts as JSONL files under ~/.claude/projects/. Search them for secrets files read during sessions that used third-party servers, for example grep -rlE '\.env|id_rsa|credentials' ~/.claude/projects/, then look at which mcp__ tool calls came just before. If you export telemetry, set OTEL_LOG_TOOL_DETAILS=1 so MCP server and tool names appear in tool events and you can see which servers your people actually use. Rotate any key from a .env file that an agent read while connected to an unvetted server, starting with cloud and payment credentials.
The wider lesson
Most companies already have rules for SaaS vendors: a security review, a data processing agreement, a known hosting region. An MCP server is a vendor that a developer can add in one command, and it receives the same project data. Put MCP servers through the same intake as any other third party and enforce the approved list in the agent client, since none of the three registries checks servers before listing them.
Our AI-native systems team builds agent integrations with these controls in place, and our red team and code review work tests what an agent can be talked into doing with the tools it has. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: OX Security research blog, OX Security report, OX Security press release, The Hacker News, Unite.AI, Cybr Sec Media, RuntimeWire, Claude Code managed MCP documentation, Claude Code MCP documentation.