What 20,629 Inspected MCP Servers Reveal About Review Readiness
The public Registry now covers 20,629 inspected MCP entries. WARN, NEED_REVIEW, RESTRICT, and BLOCK together account for 20,210 rows, meaning 98% of visible entries need some form of review before adoption.
Terminology
| Term | Meaning |
|---|---|
| Public Registry | Inspected MCP candidates searchable in the public Registry |
| Profile evidence | Inspection-profile aggregates used to interpret public candidates in more depth |
| Review/action rows | Entries in WARN, NEED_REVIEW, RESTRICT, or BLOCK that require reasoned adoption review |
Lead
MCP security can no longer be described through a few unusual examples. Once the public Registry crossed 20,629 inspected entries, the practical question became how teams should continuously triage a large candidate pool before connecting it to AI agents.
Key Findings
- The public Registry contains 20,629 inspected MCP entries.
- WARN, NEED_REVIEW, RESTRICT, and BLOCK total 20,210 rows, or 98% of the Registry.
- PASS accounts for 419 rows, making clearly low-risk entries a minority.
- This does not mean nearly every entry is immediately malicious; it means most entries deserve evidence-based review before use.
Dataset
| Item | Value |
|---|---|
| Article date | 2026-04-11 |
| Public Registry snapshot | 20,629 entries, synced 2026-06-06T01:17:38.963Z |
| Detailed profile evidence | 11,627 rows, generated 2026-05-20/21 |
| Public disclosure level | Aggregates, distributions, anonymized observations, and operational interpretation |
Observed Metrics
| Metric | Value | Meaning |
|---|---|---|
| Public Registry entries | 20,629 | Inspected MCP entries searchable in the public Registry |
| Review/action rows | 20,210 (98%) | WARN, NEED_REVIEW, RESTRICT, and BLOCK combined |
| PASS rows | 419 | Entries currently closed as lower-risk candidates |
What We Observed
At a 20,000-entry scale, the distribution matters more than a single alarming example. The high count of WARN and NEED_REVIEW entries shows that many MCP candidates require context before they are safe to adopt. RESTRICT and BLOCK are strong stop signs, but WARN is not a blanket rejection. It is a signal to read the evidence, execution boundary, source status, and tool behavior before allowing the server into a workflow.
Practical Reading
Teams should not choose MCP servers only by popularity, search rank, or a copied configuration snippet. The first operational step is to compare candidates against an inspected Registry and sort them by review state. The small PASS population does not imply that low-risk candidates do not exist. It means the evidence bar for calling something low-risk is intentionally higher than the bar for flagging uncertainty.
Limits
- Counts are snapshot values and will change as the Registry updates.
- The Registry count covers public, searchable inspected entries, not a complete census of every MCP server that may exist.
- Registry state is an adoption input, not a substitute for final approval in a specific environment.
Conclusion
The main lesson from a 20,000-entry Registry is that MCP adoption needs repeatable triage, not one-off trust in whatever server appears first.
MCP Guard continuously turns public Registry and profile evidence into adoption-review signals for MCP security teams.
