MCPGrade Tool Finds 65% of Public MCP Servers Lack Basic Authentication
A security audit by SentinelReign examined 5,308 publicly accessible Model Context Protocol (MCP) servers and found that over 3,450 of them — roughly 65% — exposed tool execution capabilities without any transport-layer authentication. The Model Context Protocol has become a widely adopted standard for connecting AI models to external tools and data sources, but security practices among developers deploying these servers have not kept pace. In response, SentinelReign founder Syed Zada Abrar has released MCPGrade (version 1.4.0), a rating algorithm that evaluates MCP servers across 39 checks in four domains: transport authentication, tool scope and authorization, input validation, and rate limiting with audit logging. The tool assigns an A-to-F grade based on weighted scores, with transport authentication carrying the highest impact weight at 35%. A live scanner is available via the Andrax Pentester platform.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in