ended3월 13일· 3 sources

We Scanned 17 Popular MCP Servers — Here's What We Found

인기 MCP 서버 17개를 보안 스캔한 결과

Why it matters

A security audit of 17 popular MCP servers using Agent Shield found that 100% lack proper permission declarations, 29% scored as high risk, and a real eval() code injection vulnerability exists in Playwright MCP. The MCP ecosystem currently has no standard security scanning, despite servers granting AI agents significant access to files, clusters, and other resources.

3
Sources
+0
24h
Growth
191d
Active
agent securityagent shieldatrclaude codeeval() vulnerabilitymcpmonoreponpmoktsecpermission declarationsplaywright mcpprompt injectionsupply chaintool policies

Sources

Related Issues