Original Research from OX Security
As enterprises rush to deploy AI agents, a critical security boundary is failing:
Who governs the infrastructure behind those connections?
OX Security Research analyzed 15,465 published MCP servers to uncover the hidden infrastructure and supply-chain risks behind AI agent tooling.
Inside the Report:
- 15,465 MCP servers analyzed
- 5,095 Unique hostnames analyzed
- 15.6% Hostnames resolved to infrastructure outside the US
- 6 Unregistered domains identified
Key Findings
Data Residency Blind Spots
15.6% of analyzed hostnames resolved to infrastructure outside the US, including infrastructure in China and Russia.
MCP currently provides no native protocol mechanism to enforce where connected tools run or where data may be processed.
Enterprise Exposure Through Consumer Networks
0.45% of analyzed hostnames were associated with home networks or consumer tunneling tools.
AI agent workflows can connect to infrastructure outside traditional corporate network controls, creating visibility and governance gaps.
Low-Cost Domain Takeover Paths
2.3% of hostnames failed to resolve, including six unregistered domains available for as little as $4 per year.
These domains create potential takeover paths if MCP clients or workflows continue to trust and call them.
Trust That Outlives the Original Permission
In testing against Claude Code with Haiku 3.5, granting a single “Always-Allow” permission allowed a malicious MCP server to use subsequent prompt injection to execute privileged file access without another user confirmation.
The same attack did not succeed against Opus 4.6 or 4.7.
Get the Complete Report
Discover how MCP is introducing new infrastructure, residency, and supply-chain risks into AI agent workflows.
Download the free research report from OX Security.