Research · curated 21 Jul 2026

State of MCP Security 2026 v2

Coverage timeline

11 Jul 2026canopii.dev 12 Jul 2026canopii.dev

Why it matters

MCP servers are the tool-calling backbone of AI agents, and this study quantifies how widespread code-execution sinks, unpinned supply chains, and silent tool-definition rug pulls are across the ecosystem defenders increasingly rely on.

Canopii's "State of MCP Security 2026" report scanned more than 11,000 published Model Context Protocol servers and found 830 graded D or F, 232 with confirmed dangerous code sinks (eval, shell injection, unsafe deserialization) that can turn prompt injection into host code execution, 184 versions that silently altered tool definitions after publication ("rug pulls"), 1,617 servers shipping dependencies with known vulnerabilities, 260 running install-time scripts, and 7 confirmed typosquats. Popular servers with 1,000+ GitHub stars were over 5x more likely to be high-risk.