# MCP Security — scans, structural risks, and fixes | Topic hub

MCP security research from first-party scans: 8,216 servers classified, 7,522 agent skills audited, plus the structural risks — input validation, schema vulnerabilities, audit gaps, rate limits — and what fixes each.

<div class="acp-section" style="padding-top:56px;">
  <div class="acp-container" style="text-align:center;">
    <div style="display:inline-block;padding:5px 16px;border-radius:100px;background:linear-gradient(135deg,rgba(79,70,229,0.14),rgba(6,182,212,0.10));color:var(--color-accent);font-size:12px;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;margin-bottom:16px;">Topic hub</div>
    <h1 class="acp-hero-h1" style="font-size:44px;margin:0 auto;max-width:780px;">MCP security</h1>
    <p class="acp-subtitle" style="max-width:720px;margin:18px auto 0;">
      MCP is becoming the default integration layer between AI clients and tools, and it ships with structural gaps every deployment inherits: no input validation story, no audit requirement, no rate limiting, auth left to the server author. Rather than repeat the ecosystem's warnings, we scanned it — <strong>8,216 MCP servers</strong> classified by auth appropriateness, <strong>7,522 agent skills</strong> statically analyzed for credential leaks and injection patterns — and wrote up each risk class with what actually mitigates it.
    </p>
    <p class="acp-subtitle" style="max-width:720px;margin:14px auto 0;font-size:14px;">
      The six structural risks are collected in the <a href="/series/mcp-security">MCP Security series</a>; the checklist post below is the practical starting point. For the layer that closes most of these by construction, see <a href="/what-is-an-mcp-control-plane">what an MCP control plane is</a>.
    </p>
  </div>
</div>

<div class="acp-section" style="padding-top:8px;">
  <div class="acp-container" style="max-width:780px;">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title" style="margin-bottom:20px;">Posts on MCP security</h2>
      <ol style="list-style:none;padding:0;margin:0;display:grid;gap:18px;">
        
        
        
        <li style="padding-bottom:18px;border-bottom:1px solid var(--color-border);">
          <a href="" style="font-size:17px;font-weight:600;color:var(--color-text-primary);text-decoration:none;line-height:1.35;"></a>
          <div class="acp-muted" style="font-size:14px;margin-top:6px;line-height:1.5;"></div>
        </li>
        
        
      </ol>
      <p class="acp-muted" style="margin-top:24px;font-size:14px;">
        Related: <a href="/blog/tool-policy/">tool permissions &amp; policy</a> · <a href="/series/mcp-security">the MCP Security series</a> · <a href="/blog">all posts</a>
      </p>
    </div>
  </div>
</div>

<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "CollectionPage",
  "name": "MCP security",
  "url": "https://agenticcontrolplane.com/blog/mcp-security/",
  "description": "MCP security research and analysis: first-party scans of 8,216 MCP servers and 7,522 agent skills, plus the structural risk classes in Model Context Protocol deployments and their mitigations."
}
</script>
