Security2 distinct publishers3 min readPublished
The oversight ratio comes from one vendor's platform telemetry and should be read as such, but the capability data underneath it is checkable, and half of the 500 MCP servers sampled from npm can execute shell commands.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The capability numbers are the part that does not depend on Reco's customer list. An MCP server is loaded into an agent as a tool, so whatever the agent reads becomes input to whatever the tool can do. Half of the 500 npm servers sampled can execute shell commands [6], which is what converts an indirect prompt injection in a ticket or a fetched web page into a process on the host. Reco's own framing names those toxic combinations as a path to file exfiltration and further compromise [22]. The two counts that matter for writing a rule are file access and egress, and that is where the two published accounts diverge.
SC Media reports 40% of the sample with the full trifecta of shell execution, local file access and network egress, and 62% combining file and network access [7]. Infosecurity Magazine attributes the 62% to the trifecta itself [8]. On a 500-server sample that is 200 servers against 310, a 110-server difference in what a capability-based blocklist catches [9].
The vulnerability counts hold together better. Reco tracked 637 since 2023, 525 of them in the past 18 months, 111 at CVSS 9.0 or above [11]. 525 over 18 months is 29.2 a month [13], which matches the roughly 29 monthly since January 2025 that Reco reports [12]. The remaining 112 spread across 2023 and 2024 comes to 4.7 a month [14], consistent with the sub-five baseline. The critical subset runs 6.2 a month, one every 4.9 days [15], which is what Reco means by every few days [16]. Its conclusion is that disclosure is outpacing patch programmes [23].
What the telemetry is worth depends on who generated it. Reco sells AI security and the ratio comes from its own platform [21][2]. Infosecurity describes the input as anonymised telemetry from large enterprises [21], while the figure of about 414 unsanctioned AI tools per 1,000 employees is attributed to small and mid-size firms [5]. Neither account gives a tenant count or a definition of a tool. The 80-against-21 split is at least an internal comparison, two populations counted by the same product [4]; the per-employee absolute is not portable to your own estimate.
Reco's remediation loop is discover, map, detect, revoke, with OAuth grants showing 60 or more days of activity triaged first [18], marketplace skills vetted after 12% of skills on ClawHub, the OpenClaw marketplace, were found malicious [19], and a kill switch per agentic tool [20]. CEO Ofer Klein's stated concern is that embedded agents work through permissions, OAuth grants and workflow access that already exist [17], which puts discovery in the identity inventory rather than the endpoint inventory. A per-agent revocation path is the cheapest item on that list and earns its keep at any oversight ratio.
Ranked by verification strength, evidence, and original report placement.
The report draws on Reco's platform telemetry, an analysis of 500 MCP servers available on npm, and a review of AI tool vulnerabilities from the National Vulnerability Database.
Reco published its report The State of Agent Security 2026 on Wednesday.
Reco found that 79% of all SaaS applications at organizations were authorized, while 80% of AI tools, including browser extensions and MCP servers, were ungoverned.
Small and mid-size companies averaged about 414 unsanctioned AI tools running per 1,000 employees.
Of 500 MCP servers analysed, 50% enable agents to execute shell commands, 82% enable local file reads and writes, and 73% support outbound network calls.
Infosecurity Magazine describes Reco as an AI security vendor that analysed anonymized platform telemetry from large enterprises, publicly available MCP servers and NVD disclosures.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Checkable capability scan bolted to unverifiable telemetry
The report has two evidentiary halves of very different quality. The MCP leg rests on a defined, publicly repeatable sample — 500 servers on npm — and the NVD leg reproduces arithmetically: 525 disclosures over 18 months is 29.2 per month and 111 criticals is one every 4.9 days, matching the published characterizations. The headline oversight ratio, by contrast, comes from proprietary vendor telemetry with no disclosed sample size, tenant count or definition of a 'governed' tool, and the two accounts disagree on how many servers combine all three capabilities. No incident data ties the capability findings to observed exploitation.
Agent tooling widely in place, governance controls not evidenced
The cluster does contain quantified deployment signals: agents described as moved from experimentation into daily workflows, roughly 414 unsanctioned AI tools per 1,000 employees at SMBs, 80% of AI tools outside oversight, and 500 MCP servers available on npm with permissive default capabilities. All of it, however, is one vendor's measurement of one customer base plus a package-registry sample; there is no named enterprise deployment, no independent usage disclosure, and zero evidence of uptake for the recommended controls (kill switches, scope revocation, OAuth activity triage).
Headline ratio outruns the evidence behind it
The framing that drives both headlines — four in five AI tools ungoverned, shadow AI outpacing shadow IT roughly four to one — rests entirely on undisclosed vendor telemetry produced by a company selling the remedy, and is presented without methodology caveats by either outlet. The capability and vulnerability findings underneath are more solid and arguably undersold, but the risk narrative jumps from capability presence to end-to-end exfiltration toolkits without a single documented incident, and one of the load-bearing combination figures is reported two different ways. Modestly overstated rather than fabricated.
Vendor sizes the gap its own product closes
Every headline number originates with Reco, an AI security vendor, and the report's prescribed loop — discover tools and attached identities, map permissions, detect, revoke, keep a kill switch, triage OAuth grants with 60-plus days of activity — describes precisely the capability set such a platform sells. The CEO is quoted framing the risk class. The npm and NVD legs draw on public data and are therefore less incentive-loaded, but the ungoverned-share statistic that both outlets led with is derived from the vendor's own telemetry, and neither publisher flags the commercial interest.
Two secondary accounts of one primary vendor source
Both cluster sources are established security trade publications reporting within a day of release, and they agree on the core figures for oversight, capability prevalence, unauthenticated endpoints and vulnerability counts — which raises confidence that the report says what is attributed to it. But there is only one primary source behind everything, no independent replication of any number, an unresolved 22-point discrepancy on the capability-combination metric, and two claims (ClawHub malicious skills, patching absorption) that the cluster cannot substantiate at all.
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
build
The Postgres MCP server in tens of thousands of installs stopped shipping in December 20241 distinct publisher
build
Four agent runtimes, four blast radii: the teammate interface converged, isolation did not1 distinct publisher
security
Kaspersky's CVE surge has two sources, and only one of them lands in the CVE count1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026
1 article · August 27, 2026