21,000 MCP servers exposed: the protocol reaches a security inflection point

Wpnx330 11 points 1 comment August 16, 2026
forkast.news · View on Hacker News

Discussion Highlights (1 comments)

Wpnx330

21,000 exposed servers with 92% lacking OAuth. The OWASP MCP Top 10 is a good start.... but it's reactive. It doesn't address the fundamental issue. There's no standard way to verify what an MCP server actually does before you connect to it. Not without studying the github repo, if one is even available. We need lockfiles, audit commands, and signed provenance, just like we got with npm.

Semantic search powered by Rivestack pgvector
4,128 stories · 37,281 chunks indexed