On 24 September 2026, OX Security published a scan of 15,465 MCP servers across public registries. The headline numbers are ugly on purpose: hostnames in China and Russia, consumer tunnels into home networks, and six abandoned domains still cheap enough to buy for the price of lunch.
The useful reading is not “MCP is over.” It is this: a directory listing is not a trust boundary. Agents will call whatever URL is already in the config. If that hostname expires, whoever registers it next inherits the standing approval.
That is an allowlist problem. Not a search problem.
What OX actually measured
OX started with listings in the official registry, Cline’s marketplace, and GitHub’s MCP registry, then reduced the set to 5,095 unique hostnames. From their 24 September write-up:
- 15.6% of those hostnames (796) resolved outside the United States — including 19 in China and 18 in Russia. MCP has no protocol-level residency control.
- 0.45% routed through home ISPs or consumer tunnels. Production agent traffic on infrastructure that was never designed for audit logs.
- 2.3% no longer resolved at all. Six of those domains were unregistered and listed for about $4–$12 per year.
They also showed a standing-approval failure: once an agent has been allowed to read a sensitive path, a later malicious tool can reuse that permission. That is not a exotic exploit. It is how most MCP clients work today.
None of this should surprise anyone who has watched the long tail. Influzer’s own catalog is now about 12,150 MCP servers, with only about 386 listings that have indexed tools. Search is abundant. Governed surfaces are not.
What this is not
It is not an argument to unplug agents. It is not an argument that every remote MCP server in another country is hostile. Geography is a compliance input, not a morality score.
It is also not a reason to stamp a public directory SAFE. We already refused that badge in Not “safe” — just honest. A live handshake and an auth gate tell you what we observed. They do not tell you who will own the domain next quarter.
YellowMCP’s reliability work makes the same point from another angle: a large share of remote endpoints do not answer, and a meaningful slice answers with no auth at all. Dead plus open is not a catalog you install from.
The failure mode that actually ships
Here is the sequence that will show up in a real incident review:
- Someone pastes a remote URL into
.cursor/mcp.json, Claude connectors, or a ChatGPT custom MCP because the listing looked official. - The team never records owner, region, or a kill date. The Connect button was the review.
- The operator lets the domain lapse. DNS goes dark. The config still points at the name.
- A new registrant stands up a lookalike
tools/list. The client already trusts the host.
That is domain takeover with a friendly JSON file. Stars, READMEs, and “works with Claude” copy do not survive step 3.
The operator response (this week, not this year)
Reuse the sequencing from policy before plugins. Search can stay open. Install stays default-deny for writes.
- Inventory every remote URL your agents already call. Cursor project configs, Claude Desktop / Claude Code, ChatGPT connectors, Slack Claude Tag. If it is not on a page, it does not exist.
- Resolve DNS and WHOIS for each hostname. NXDOMAIN, registrar expiry inside 90 days, or a consumer tunnel is a ticket — not a “watch item.”
- Require an owner and a region. If nobody can say who runs it and where it lives, it does not belong in shared config. Residency is a policy field even when the protocol does not enforce it.
- Prefer Ready surface + Auth required over Thin listing. Filter the directory for quality. A 401 on
tools/listis a heartbeat. Zero tools is a rumor. - Put write tools on a separate allowlist row from read-only search. Eyes before hands is still the first week that survives security review.
- Stop paste-a-key in team configs. Standing credentials plus an abandoned hostname is how takeover becomes exfil. See paste-a-key is dead.
How Influzer treats this as catalog work
We will keep indexing the long tail. Hiding 11,000 thin listings does not make the remaining ones honest. What we will keep doing:
- Label what we know: tools indexed, live handshake, auth gate, thin vs ready — never a SAFE chip.
- Let agents search by capability through Discovery MCP without auto-installing anything.
- Ask submitters for a real URL. A name without a host is not a listing — and a host without tools stays a Thin listing.
- Keep SSE marked as deprecated and treat unknown transports as unverified, not finished.
If you maintain a server we list, the bar is the same as for buyers: a live URL, a tool surface, and an owner who will still be there when the domain invoice arrives.
A 45-minute drill you can run Monday
- Export every MCP URL from shared configs (15 min).
- For each host:
dig, TLS cert expiry, and whethertools/listreturns tools, 401, or silence (20 min). - Write three columns on one page: keep / quarantine / kill. Quarantine means read-only or disconnected until an owner signs (10 min).
Anything that fails DNS this week is already the OX finding, just closer to home.
Quick answers
Does a public MCP directory cause domain takeover?
No. Directories surface URLs. Clients that keep calling expired names without an owner review cause takeover. Treat listings as leads.
Should we ban every non-US MCP hostname?
Only if your residency policy says so. Record region. Do not confuse “not in us-east-1” with “malicious.”
Is an unauthenticated remote ever acceptable?
For a public read-only demo, maybe. For anything that can see customer data or write to GitHub, no. Open 2xx with tools is an incident waiting for a crawler.
Where should we start in the Influzer catalog?
Ready surface first, then Discovery search, then an allowlist row. Skip Thin listing until someone handshakes it.
Related reading
- Not “safe” — just honest
- Policy before plugins
- Most MCP servers are still demoware
- Eyes before hands
- Paste-a-key is dead
- Scan skills with SkillSpector — don’t badge MCP “safe”
- OX Security: How MCP is bypassing a decade of cloud security best practices
Final thought
Fifteen thousand listings is not governance. Six abandoned domains is not a fun fact. It is what happens when Connect is cheaper than an owner field.
Write the allowlist. Handshake the host. Kill anything you cannot name.
Start on the directory. Search from inside the agent with Discovery. And if a hostname in your config no longer resolves, do not wait for a research report to tell you what that means.
One clear email each Thursday
Actionable frameworks on AI execution, agents, and MCP. Join 4,200+ builders.
Leave a comment
Be the first to share your thoughts.