VMTech
Discuss a project →

OX Security finds governance gaps across public MCP server registries

OX Security finds governance gaps across public MCP server registries

OX Security analyzed 15,465 publicly indexed Model Context Protocol (MCP) servers across five MCP registries and reduced the set to 5,095 unique hostnames. Its findings highlight an ecosystem in which community-published servers can be listed without marketplace vetting, code signing or origin verification.

MCP was designed to provide a common way for models, agents and integrated development environments to connect with tools and data. The protocol has attracted thousands of developers and enterprise use cases, but OX Security argues that the surrounding marketplace model does not provide the governance controls enterprises expect for externally hosted services.

Public infrastructure exposes governance questions

Among the 5,095 unique hostnames, 15.6% resolved to infrastructure outside the United States. The research identified 19 hostnames in China and 18 in Russia. An agent connected to one of these services may send data to jurisdictions that a security team has not approved.

The review also found that 0.45% of hostnames routed traffic through consumer tunnelling services, mainly ngrok-free. OX Security said these publicly listed servers run from personal machines and likely home networks, rather than infrastructure subject to an organisation's usual operational controls.

Availability and ownership are additional concerns. The researchers found that 2.3% of hostnames no longer resolved, including six on expired domains that could be registered for between $4 and $12 a year. A new registrant could take over an established server identity and receive requests from agents that remain configured to call it.

Repository visibility is not runtime verification

OX Security stresses that reviewing a public code repository cannot establish what a remote MCP server is executing. Backend code may differ from the code published by a developer, so a repository review shows only what was shared, not the workload handling an agent request.

The company also notes that hosting location can change after a server is deployed. An operator could initially use a US IP address and later redirect traffic elsewhere. That makes an initial assessment insufficient when an MCP connection remains active over time.

What enterprises need to verify

OX Security's report calls for marketplace vetting, code signing and origin verification. Until such controls are available, organisations need to apply their own checks to public MCP services and assess where agent data is sent.

For businesses adopting MCP, the practical implication is to maintain an inventory of agent-to-server connections, validate server ownership and hosting, and review configured endpoints when their domain status or infrastructure changes.

#mcpsecurity#aiagents#cloudsecurity#supplychain
Open analytics
On the site 0 views
min read 3 06.10.2026
Instagram

OX Security finds governance gaps across public MCP server registries

Open the post on Instagram ↗