ended4월 2일· 1 sources

Large-Scale MCP Audit Reveals Critical Supply Chain Trust Gaps

MCP 생태계의 공급망 보안 위기, 대규모 감사로 드러나다

Why it matters

This unprecedented security assessment of 5,154 MCP servers exposes a significant trust deficit in the ecosystem. While live-verified servers maintain a respectable average trust score of 76/100, static npm packages lag significantly at 54/100, revealing a two-tier ecosystem. The analysis found that supply chain vulnerabilities account for 71% of all security issues—most servers lack provenance attestation, depend on single maintainers for security, and show evidence of impersonation attacks. As MCP adoption accelerates in AI applications, these systemic gaps represent a growing threat to downstream agents and the applications they power.

1
Sources
+0
24h
Growth
172d
Active
MCPSupply chainTrust scoringCraftedTrustProvenance attestation

Sources

Related Issues