Open-Source Scanner Exposes Unauthenticated MCP Servers Hidden Inside Corporate Networks
A developer has released an open-source tool called shadow-mcp-scanner that detects Model Context Protocol (MCP) servers running inside internal networks, including those unknown to platform or security teams. MCP servers are lightweight HTTP services that teams often spin up informally to connect AI agents to internal systems like databases, CRMs, and build pipelines, rarely appearing in official service catalogs. The scanner identifies MCP servers by sending a JSON-RPC handshake request and checking for a protocol-specific response, requiring no credentials and completing a scan in roughly 15 seconds using only Docker. A 2025 Trend Micro report found 492 internet-exposed MCP servers running without authentication or encryption, collectively exposing over 1,400 tools — a figure the author notes has never been updated despite rapid ecosystem growth. The tool highlights that internal, VPN-accessible MCP servers pose an equal or greater risk than public-facing ones, as they are reachable by every workload and device on a corporate network.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in