ended4월 2일· 1 sources
Large-Scale MCP Audit Reveals Critical Supply Chain Trust Gaps
MCP 생태계의 공급망 보안 위기, 대규모 감사로 드러나다
Why it matters
This unprecedented security assessment of 5,154 MCP servers exposes a significant trust deficit in the ecosystem. While live-verified servers maintain a respectable average trust score of 76/100, static npm packages lag significantly at 54/100, revealing a two-tier ecosystem. The analysis found that supply chain vulnerabilities account for 71% of all security issues—most servers lack provenance attestation, depend on single maintainers for security, and show evidence of impersonation attacks. As MCP adoption accelerates in AI applications, these systemic gaps represent a growing threat to downstream agents and the applications they power.
1
Sources
+0
24h
—
Growth
172d
Active
MCPSupply chainTrust scoringCraftedTrustProvenance attestation