ログイン中: ログイン状態を復元中...

ResearchApr 11, 2026Abcas Security Research

What 20,629 Inspected MCP Servers Reveal About Review Readiness

The public Registry now covers 20,629 inspected MCP entries. WARN, NEED_REVIEW, RESTRICT, and BLOCK together account for 20,210 rows, meaning 98% of visible entries need some form of review before adoption.

Terminology

TermMeaning
Public RegistryInspected MCP candidates searchable in the public Registry
Profile evidenceInspection-profile aggregates used to interpret public candidates in more depth
Review/action rowsEntries in WARN, NEED_REVIEW, RESTRICT, or BLOCK that require reasoned adoption review

Lead

MCP security can no longer be described through a few unusual examples. Once the public Registry crossed 20,629 inspected entries, the practical question became how teams should continuously triage a large candidate pool before connecting it to AI agents.

Key Findings

  1. The public Registry contains 20,629 inspected MCP entries.
  2. WARN, NEED_REVIEW, RESTRICT, and BLOCK total 20,210 rows, or 98% of the Registry.
  3. PASS accounts for 419 rows, making clearly low-risk entries a minority.
  4. This does not mean nearly every entry is immediately malicious; it means most entries deserve evidence-based review before use.

Dataset

ItemValue
Article date2026-04-11
Public Registry snapshot20,629 entries, synced 2026-06-06T01:17:38.963Z
Detailed profile evidence11,627 rows, generated 2026-05-20/21
Public disclosure levelAggregates, distributions, anonymized observations, and operational interpretation

Observed Metrics

MetricValueMeaning
Public Registry entries20,629Inspected MCP entries searchable in the public Registry
Review/action rows20,210 (98%)WARN, NEED_REVIEW, RESTRICT, and BLOCK combined
PASS rows419Entries currently closed as lower-risk candidates

What We Observed

At a 20,000-entry scale, the distribution matters more than a single alarming example. The high count of WARN and NEED_REVIEW entries shows that many MCP candidates require context before they are safe to adopt. RESTRICT and BLOCK are strong stop signs, but WARN is not a blanket rejection. It is a signal to read the evidence, execution boundary, source status, and tool behavior before allowing the server into a workflow.

Practical Reading

Teams should not choose MCP servers only by popularity, search rank, or a copied configuration snippet. The first operational step is to compare candidates against an inspected Registry and sort them by review state. The small PASS population does not imply that low-risk candidates do not exist. It means the evidence bar for calling something low-risk is intentionally higher than the bar for flagging uncertainty.

Limits

  1. Counts are snapshot values and will change as the Registry updates.
  2. The Registry count covers public, searchable inspected entries, not a complete census of every MCP server that may exist.
  3. Registry state is an adoption input, not a substitute for final approval in a specific environment.

Conclusion

The main lesson from a 20,000-entry Registry is that MCP adoption needs repeatable triage, not one-off trust in whatever server appears first.


MCP Guard continuously turns public Registry and profile evidence into adoption-review signals for MCP security teams.