ログイン中: ログイン状態を復元中...

ResearchMay 5, 2026Abcas Security Research

Why 9,036 Profiles Needed Source Fallback in MCP Inspection

detailed profile rows show 9,036 source fallback cases, 8,539 source-substance cases, and 8,406 static-registration evidence cases. MCP review often needs evidence even when runtime execution is incomplete.

Terminology

TermMeaning
Public RegistryInspected MCP candidates searchable in the public Registry
Profile evidenceInspection-profile aggregates used to interpret public candidates in more depth
Review/action rowsEntries in WARN, NEED_REVIEW, RESTRICT, or BLOCK that require reasoned adoption review

Lead

MCP servers cannot always be fully launched because of authentication, environment variables, dependencies, or platform mismatch. Source and static tool-registration evidence therefore matter.

Key Findings

  1. detailed profile rows show 9,036 source fallback cases, 8,539 source-substance cases, and 8,406 static-registration evidence cases. MCP review often needs evidence even when runtime execution is incomplete.
  2. The 20,629 public Registry entries and 11,627 profile-evidence rows answer different questions and should not be mixed casually.
  3. The observation is an adoption input, not a final approval for a specific environment.
  4. Counts are snapshot evidence, so adoption review should check the observation date before treating the number as current state.

Dataset

ItemValue
Article date2026-05-05
Public Registry snapshot20,629 entries, synced 2026-06-06T01:17:38.963Z
Detailed profile evidence11,627 rows, generated 2026-05-20/21
Public disclosure levelAggregates, distributions, anonymized observations, and operational interpretation

Observed Metrics

MetricValueMeaning
Source fallback evidence9,036Fallback evidence from source
Source substance evidence8,539Candidate with source substance observed
Static registration evidence8,406Candidate with static tool registration evidence

What We Observed

MCP servers cannot always be fully launched because of authentication, environment variables, dependencies, or platform mismatch. Source and static tool-registration evidence therefore matter. This lens matters because MCP servers are not just plugins; they are bundles of authority exposed to an AI agent.

Practical Reading

Do not treat a non-runnable candidate as safe. Review source, packages, tool definitions, and required configuration, then record what remains unverified. Review should record execution location, destinations, data touched, and unresolved evidence, not only the server name or README.

Limits

  1. The evidence uses public aggregate data and anonymized observations, not internal detection mechanics.
  2. Counts are snapshot values and will change as the Registry updates.
  3. This is not a claim that any named MCP server is safe or unsafe.

Conclusion

Do not treat a non-runnable candidate as safe. Review source, packages, tool definitions, and required configuration, then record what remains unverified. Keeping this evidence in the intake record makes the review repeatable across teams and deployments.


MCP Guard continuously turns public Registry and profile evidence into adoption-review signals for MCP security teams.