[ TRANSMISSION // BLOG ]
We measured the MCP ecosystem.
Today we're releasing the MCP Security Index 2026: a rubric-based survey of the 50 most widely used public MCP servers — reference, vendor, and community — with the full dataset public under CC BY 4.0.
Blog/September 7, 2026·Rupam Biswal
The numbers: 48% of the surveyed servers have no per-call authorization of any kind. 92% have no hook where a policy decision could even be inserted. 58% document no audit logging. And 30% expose destructive tools — delete, execute, spend — with zero per-call authorization. Across the population we recorded 55 documented CVEs, advisories, and security write-ups, each cited in the dataset.
The full analysis, the four patterns in the data, and the method are in the summary: The MCP Security Index 2026. The dataset — CSV, JSON, rubric, per-server evidence — is at github.com/sentnelops/mcp-security-index. If you maintain one of the fifty servers and we got something wrong, corrections are welcome and attributed.
SentnelOps is an AI agent runtime governance platform — an MCP firewall giving every agent an identity, runtime policy on every tool call, and an audit-ready evidence trail. Start with the knowledge layer or log your first call in 10 minutes.