Exposed by Design: A Dynamic Security Assessment of Internet-Facing MCP Servers at Scale
It is found that 91.8% of dynamically audited servers lack OAuth authentication, 687 tool instances across confirmed servers expose shell execution capabilities without access controls, and 41.6% of confirmed servers disappear within three days between consecutive measurement runs---indicating rapid deployment cycles w...