Research · curated 21 Jul 2026

Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability

Coverage timeline

14 Jul 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

MCP servers increasingly mediate security-sensitive agent operations, and this study shows that the scanners defenders rely on to assess them are unreliable, undercutting current MCP risk-assessment practices.

The paper "Rethinking MCP Security" presents MCPZoo, the largest collection of runtime Model Context Protocol (MCP) servers for dynamic analysis (64,611 unique servers, 37,288+ supporting dynamic analysis), built via a multi-agent framework that transforms static repositories into runnable services. Using it, the authors conduct an ecosystem-scale measurement showing that while existing MCP security scanners flag 96.89% of servers as risky, manual validation finds under 50% of sampled alerts are true positives, with inconsistent outputs across scanners.