Security1 distinct publisher3 min readUpdated
Nine of eleven MCP marketplaces accepted proof-of-concept malware with zero review, and a fake agent skill cleared both Cisco's and NVIDIA's scanners to reach roughly 26,000 corporate agents.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Figures cited on SC World's Security Weekly News #607 put measurements on a gap operators have been describing anecdotally for months: AI agents load third-party skills and MCP servers at runtime while inheriting the user's email, files and system access [1]. The same segment notes the ecosystem shipped without the supply-chain controls open source spent fifteen years assembling: no mandatory authentication, no cryptographic signing, no provenance verification, no publisher vetting [2].
That is not a list of nice-to-haves. It is the entire set of mechanisms that makes it possible to answer, after an incident, the question of who published the code that ran on your endpoint.
The distribution layer has already been tested. Nine of eleven MCP marketplaces accepted unvetted proof-of-concept malware with zero review [3], which is an acceptance rate of about 82 percent across the marketplaces tested [4] and leaves two that did not wave it through [5]. Marketplaces are the closest thing this ecosystem has to a package registry, and four out of five of them are functioning as file hosts.
Detection did not compensate. A fake agent skill passed both Cisco's and NVIDIA's scanners and reached approximately 26,000 corporate agents [6]. Two vendors with security scanning products in market did not catch it, and the blast radius was five figures of agents inside companies. Whatever assurance is being sold on top of this ecosystem, it is not currently a substitute for provenance.
The foundations are also carrying defects. OX Security found more than ten critical CVEs in Anthropic's own MCP SDKs, affecting 200,000 servers, according to the same segment [7]. Critical bugs in a young SDK are unremarkable in isolation. What makes this different from an ordinary library advisory is that there is no signing or provenance layer above it [2], so the usual remediation path of identifying affected builds and their publishers is largely unavailable.
Put the three data points in sequence and the shape is familiar to anyone who worked through the early package-manager years: a fast-growing distribution channel, no publisher identity, scanners doing the work that registries should be doing, and a runtime that grants inherited access by default [1]. The difference is that a compromised npm package usually needed a build step and a deploy to reach production. A skill loaded at runtime with the operator's own mail and filesystem access does not [1].
What to watch. First, whether any of the eleven marketplaces move to mandatory signing and publisher identity rather than post-hoc takedowns, and whether the two that held the line publish their review criteria [3][5]. Second, whether Cisco or NVIDIA disclose detection rates for skill and MCP-server content after the bypass [6], since a scanner with an unpublished false-negative rate is an unpriced control. Third, patch uptake on the Anthropic MCP SDKs, which is the one number that will indicate whether 200,000 servers can actually be reached by a fix [7]. Fourth, and most practical inside your own estate: whether you can currently produce a list of which skills and MCP servers your agents loaded last week, and who published them.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
AI agents load third-party skills and MCP servers at runtime, inheriting the user's email, files, and system access.
The agent skill and MCP ecosystem shipped with none of the supply-chain controls open source spent 15 years building: no mandatory authentication, no cryptographic signing, no provenance verification, no publisher vetting.
Nine of eleven MCP marketplaces accepted unvetted proof-of-concept malware with zero review.
A fake agent skill passed both Cisco's and NVIDIA's scanners and reached approximately 26,000 corporate agents.
OX Security found more than 10 critical CVEs in Anthropic's own MCP SDKs, affecting 200,000 servers.
The proof-of-concept malware was accepted by about 82 percent of the MCP marketplaces tested.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single secondary source, no primary research linked
Every claim traces to one multi-topic security podcast summary. The structural assertions about runtime privilege inheritance and missing signing/provenance controls are internally consistent and uncontested, but the three quantitative findings carry no named researcher, methodology, marketplace list, CVE identifiers, or vendor confirmation, and no second publisher corroborates them.
Deployment scale disclosed; mitigating controls essentially absent
The source discloses real deployment footprint — a planted skill reaching roughly 26,000 corporate agents and 200,000 MCP servers exposed via SDK CVEs — which indicates agent skills and MCP servers are in live enterprise use. Adoption of the countervailing controls is reported as near zero: no mandatory authentication, signing, provenance verification, or publisher vetting, and nine of eleven marketplaces performing no review. Both sides of the figure rest on one uncorroborated source, so the value stays modest.
Alarming specifics outrun the sourcing behind them
The mechanism claims are plausible and modest, but the headline numbers — an 82 percent marketplace pass rate, a scanner bypass reaching ~26,000 corporate agents, 10+ critical CVEs across 200,000 servers — are presented as settled 'killer data points' while resting on a single podcast mention with no linked research, no CVE identifiers, and no vendor response. Positive gap reflects that assertion strength exceeds verifiable evidence, not that the underlying risk is fictional.
Security-media urgency plus vendor-research amplification
The sole outlet is a security trade podcast whose audience and format reward urgent framing, and the cited findings originate with commercial security vendors — OX Security's CVE research, and scanner performance attributed to Cisco and NVIDIA — that all sell into the agent supply-chain security market the story argues is missing. Anthropic, whose SDKs are implicated, is given no voice, so no counter-incentive is represented.
Directionally credible, numerically unverified
One publisher, one segment, three unlinked quantitative findings, and no primary advisories or vendor statements. Confidence is high enough that the structural risk description is real and consequential, and low on every specific figure until the underlying research and CVE records surface.
science
OX Security says MCP command execution is a design choice, so server owners own the risk1 distinct publisher
build
Agent Plugins 1.0.0 standardises file paths. Anthropic still owns the behaviour.1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026