Analysis · curated 21 Jul 2026
MCP Server Supply Chain Security: The Install Path Nobody Reviews
First reported deepinspect.ai
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
MCP servers embed unreviewed install paths where malicious tool descriptions and STDIO configuration flow directly into command execution and model instructions, exposing defenders to supply-chain and prompt-injection risk across an estimated 150 million downloads and 7,000+ public servers.
A DeepInspect analysis lays out five review gates for securing the MCP server supply chain, arguing that adding a third-party MCP server grants code execution, credential access, and text injection with far less scrutiny than an npm dependency. It cites CSA/OX Security research finding 9 of 11 MCP marketplaces affected by a STDIO-interface design flaw, 40+ MCP CVEs in early 2026 (including CVE-2026-33032 in nginx-ui MCP and CVE-2026-0755 in gemini-mcp-tool, both CVSS 9.8), and details tool-description poisoning as indirect prompt injection (MITRE ATLAS AML.T0051.001).