lead story · investigated
One in eighteen public MCP servers describes its tools dishonestly
A first-of-its-kind scan of 1,899 open-source servers finds 5.5% carry poisoned tool descriptions and 3.6% hard-code live credentials — eight vulnerability classes, only three overlapping traditional software.
The survey's 1,899 public instances split into eight identifiable failure classes — and only three of them have a direct counterpart in traditional software. The other five are peculiar to the agent stack: the way models pick tools, trust descriptions, and chain calls together.
None of the eight required advanced skill. That is the finding's real weight: every class was demonstrated with ordinary tooling, and the credential play in the survey was pulled off with undergraduate-level Python in an afternoon.






