NewSolo / Entrepreneur access, by invitation.Redeem invite →

What 463 Public MCP Configurations Revealed About AI Connector Security

By Ernest Provo, founderLast reviewed: 2026-08-30

DSE, the team that operates PrivateStack, scanned 463 publicly exposed Model Context Protocol configurations and published what it found. Two numbers matter most for anyone running AI tools with connectors.

The findings, in brief

Roughly two thirds of the remote MCP servers referenced by those configurations declared no authentication at all, and 31% of configurations carried at least one authentication-posture finding. The published piece also documents a correction: the first pass overcounted committed credentials, and the team published the corrected number with the method that produced it.

Why this matters for a governed workspace

Every MCP server a team connects is an input path into whatever the assistant can reach. An unauthenticated one is an input path anyone can write to. That is why PrivateStack treats connector inventory and declared surface as governance objects rather than developer conveniences: you cannot approve what nobody has enumerated.

The full piece carries the method, the raw counts, and the correction history: We scanned 463 public MCP configurations →