{"id":442,"date":"2026-10-08T06:18:18","date_gmt":"2026-10-08T06:18:18","guid":{"rendered":"https:\/\/managedt.com\/blog\/15465-public-mcp-servers-no-governance\/"},"modified":"2026-10-08T06:18:19","modified_gmt":"2026-10-08T06:18:19","slug":"15465-public-mcp-servers-no-governance","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/15465-public-mcp-servers-no-governance\/","title":{"rendered":"15,465 Public MCP Servers Were Indexed. Almost None Have Governance"},"content":{"rendered":"<p>Security teams now have a measured view of public MCP marketplaces: 15,465 publicly indexed servers across five registries were deduplicated to 5,095 unique hostnames, and the scan found no mandatory review, foreign-hosted endpoints, traffic running through consumer tunnels on personal machines, and expired domains that anyone can re-register for a few dollars.<\/p>\n<h2>What the protocol was supposed to fix<\/h2>\n<p>Model Context Protocol was introduced in 2024 as a single standard for connecting AI models, agents, and IDEs to tools and data. The protocol delivered on that promise. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around the protocol fell short, and that gap is where the risk now lives.<\/p>\n<h2>How big is the gap between MCP and app-store-era vetting?<\/h2>\n<p>Google ran Bouncer starting in 2012, an automated scanner that checked Android apps for malware before users could install them. It was imperfect, and researchers did slip malware past it. Crucially, it existed as a checkpoint. Public MCP marketplaces have no equivalent. Anyone can write a server, push it, and publish it. The comparison matters because code review of a public repository only confirms what the developer published. A remote MCP server can run backend code that differs entirely from what the repository shows.<\/p>\n<h2>Where does enterprise data actually go?<\/h2>\n<p>Over the past decade enterprises built strict guardrails for public cloud adoption: data residency rules, Zero Trust boundaries, granular IAM, and supply chain audits. MCP connections often sit outside all of it. The scan measured the gap and the numbers show how exposed that posture is.<\/p>\n<h3>Hosted outside the United States<\/h3>\n<p>15.6% of unique hostnames resolve to infrastructure outside the United States. That includes 19 hostnames in China and 18 in Russia. An agent connected to these servers may send enterprise data to jurisdictions the security team never approved.<\/p>\n<h3>Running on personal machines<\/h3>\n<p>0.45% of servers route traffic through consumer tunneling services, with the report calling out ngrok-free style endpoints. These publicly listed servers appear to run from personal machines and, likely, home networks, well outside corporate network controls.<\/p>\n<h3>Dangling domains<\/h3>\n<p>2.3% of hostnames no longer resolve. Six sit on expired domains that anyone can register for $4 to $12 a year. A new owner would inherit the established server identity, along with any requests from agents still configured to call it. The operator can also change hosting location over time, launching on a clean US IP address and later redirecting traffic elsewhere.<\/p>\n<h2>Why trust is the real attack surface<\/h2>\n<p>The protocol itself is not the problem. The trust handed to it is. Until marketplaces add vetting, code signing, and origin verification, the enterprise has to do that work itself. A report titled &#8220;15,465 MCP Servers, 0 Governance&#8221; covered the methodology, a prompt-injection proof of concept, and the threat scenarios behind each finding.<\/p>\n<h2>What security teams can do now<\/h2>\n<p>Treat community-published MCP servers the same way you treat unverified open-source dependencies. Pin exact server versions and hashes, audit the code you actually run rather than only what the repository links, log every outbound call so a foreign endpoint or a sudden IP change is visible, and require allowlists for the data an agent can hand to a third-party tool. Treat the marketplace as untrusted by default and put your own gate at the boundary, since the registries publish without checking.<\/p>\n<h2>FAQ<\/h2>\n<h3>What did the scan of public MCP servers find?<\/h3>\n<p>The scan covered 15,465 publicly indexed MCP servers across 5 registries, deduplicated to 5,095 unique hostnames. There was no mandatory vetting, 15.6% of hostnames resolved outside the US, 0.45% routed through consumer tunneling services running from personal machines, and 2.3% no longer resolved because their domains had lapsed.<\/p>\n<h3>Why is hosting data through foreign MCP servers a risk?<\/h3>\n<p>An agent connected to these servers may send enterprise data to jurisdictions the security team never approved. The operator can also relaunch on a clean US IP and later route traffic elsewhere.<\/p>\n<h3>What does the protocol itself have to do with the risk?<\/h3>\n<p>Model Context Protocol is positioned as a universal connector for AI models, agents, and IDEs. The protocol works as intended. The risk sits in the ecosystem around it: marketplaces publish servers without review, code review of the public repository does not match what the remote server actually runs, and domains can be re-registered cheaply by anyone after expiry.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What did the scan of public MCP servers find?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The scan covered 15,465 publicly indexed MCP servers across 5 registries, deduplicated to 5,095 unique hostnames. There was no mandatory vetting, 15.6% of hostnames resolved outside the US, 0.45% routed through consumer tunneling services running from personal machines, and 2.3% no longer resolved because their domains had lapsed.\"}},{\"@type\":\"Question\",\"name\":\"Why is hosting data through foreign MCP servers a risk?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"An agent connected to these servers may send enterprise data to jurisdictions the security team never approved. The operator can also relaunch on a clean US IP and later route traffic elsewhere.\"}},{\"@type\":\"Question\",\"name\":\"What does the protocol itself have to do with the risk?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The Model Context Protocol is positioned as a universal connector for AI models, agents, and IDEs. The protocol works as intended. The risk sits in the ecosystem around it: marketplaces publish servers without review, code review of the public repository does not match what the remote server actually runs, and domains can be re-registered cheaply by anyone after expiry.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/thehackernews.com\/2026\/10\/welcome-to-jungle-what-we-found-inside.html\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A scan of public MCP registries finds thousands of community servers with no vetting, hosted across borders and even on expired domains.<\/p>\n","protected":false},"author":3,"featured_media":441,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-442","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/442","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=442"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/442\/revisions"}],"predecessor-version":[{"id":443,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/442\/revisions\/443"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/441"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=442"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=442"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}