We Analyzed 15,400+ MCP Servers and Found a Security Mess
Read the Report
Rethink cloud security in an AI-driven era. Watch our webinar with James Berthoty and Chris Lindsey
Save your spot
Announcing OX Cloud: CNAPP Coverage Plus Runtime Security for AI Agents
Read More

15,465 MCP Servers. 0 Governance.

Geolocation, domain integrity, and prompt injection risk. We Analyzed 15,400+ MCP Servers and Found a Security Mess
15,465 MCP Servers, 0 Governance (1)

Download the Report

Original Research from OX Security

As enterprises rush to deploy AI agents, a critical security boundary is failing:

Who governs the infrastructure behind those connections?

OX Security Research analyzed 15,465 published MCP servers to uncover the hidden infrastructure and supply-chain risks behind AI agent tooling.

Inside the Report:

  • 15,465 MCP servers analyzed
  • 5,095 Unique hostnames analyzed
  • 15.6% Hostnames resolved to infrastructure outside the US
  • 6 Unregistered domains identified

Key Findings

Data Residency Blind Spots

15.6% of analyzed hostnames resolved to infrastructure outside the US, including infrastructure in China and Russia.

MCP currently provides no native protocol mechanism to enforce where connected tools run or where data may be processed.

Enterprise Exposure Through Consumer Networks

0.45% of analyzed hostnames were associated with home networks or consumer tunneling tools.

AI agent workflows can connect to infrastructure outside traditional corporate network controls, creating visibility and governance gaps.

Low-Cost Domain Takeover Paths

2.3% of hostnames failed to resolve, including six unregistered domains available for as little as $4 per year.

These domains create potential takeover paths if MCP clients or workflows continue to trust and call them.

Trust That Outlives the Original Permission

In testing against Claude Code with Haiku 3.5, granting a single “Always-Allow” permission allowed a malicious MCP server to use subsequent prompt injection to execute privileged file access without another user confirmation.

The same attack did not succeed against Opus 4.6 or 4.7.

Get the Complete Report

Discover how MCP is introducing new infrastructure, residency, and supply-chain risks into AI agent workflows.

Download the free research report from OX Security.

"The OX Security platform is a game changer for application security teams. It is easy to adopt and integrate into the CI/CD pipeline and provides us the visibility and focus we need to develop fast and secure."

Moshe Belostosky Director of Infrastructure at

"OX Security supports our need for transparency and end to end traceability, ensuring security throughout our processes. This provides us with greater control - blocking vulnerabilities and improving accuracy during the development lifecycle."

Danny Wishlitzky Head of IT and Cybersecurity, CISO, DPO, Proximity

OX is changing the software supply chain security game. It gives a complete and reliable snapshot of code security before deployment

Golan Barash CISO at 888 holdings

Change the trajectory of your entire security program today

A unified platform that uses environment-aware context to prioritize risks saves

Get a Demo
Frame 2085669014
Group 1261154229