Product1 distinct publisher3 min readPublished
A census scored 19 widely deployed servers on three disclosure questions drawn from the MCP spec, and the most common answer in every column was undocumented. That is the position agent teams are reviewing from.
The Product Desk · Product desk
science
OX Security says MCP command execution is a design choice, so server owners own the risk1 distinct publisher
security
Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success1 distinct publisher
build
MCP is four trust boundaries, and credentials only close one of them1 distinct publisher
security
The credential store nobody inventoried: MCP servers now hold the keys to everything they touch1 distinct publisher
Compiled by The Product DeskSomething wrong?How this is made
An engineer asks a coding agent for the current syntax of a library call. The agent queries an MCP documentation server, gets text back, folds it into context, and carries on. That is the shape of the request that carried the Context7 flaw: according to the audit, a free-text "Custom AI Instructions" feature served through the MCP server let unsanitised content reach connected coding agents during what looked like a routine library-documentation lookup [9]. From the operator's chair, nothing in that exchange looks like an attack.
The spec gives you better vocabulary for this than most rollout checklists do. The 2026-07-28 revision defines three server primitives with a control hierarchy attached: prompts are user-controlled to invoke, resources are application-controlled, tools are model-controlled [15]. Read those definitions closely and there are seven separate routes by which server-originated text can reach a model's context [16]. The census turns three of them into questions a reviewer can actually ask a vendor page: is there a server-level instructions field, is there a free-text instruction surface someone can configure, and does the vendor warn that tool output may carry embedded instructions [5].
Nineteen servers against three questions is 57 documentation cells [19], and the modal value in every column is undocumented [6]. Teams often assume they reviewed the MCP server because they read the tool list. But the tool list contains tool names and descriptions, which are one of several surfaces alongside the optional instructions field, resource content, prompt templates, and the tool results themselves [2].
The caveat carries more weight than the tally. Undocumented means the vendor's own public docs do not disclose the surface, not that the surface is absent from the running code, and only a code-level audit could separate the two [7]. A server that genuinely does not use an instructions field and a server that uses one silently land in the same cell. That is the authors' actual finding [4]. They call it a census rather than a ranking because a reviewer cannot evaluate a surface a vendor never mentions [6].
Severity travels badly here too. The same Context7 flaw sits 2.6 points apart depending on which CVSS framework you read [20], and as of the audit's retrieval date of 2026-08-22 the advisory documented no public fix, which the authors state as an absence of documentation rather than a claim about later releases [14].
The forcing function is cheap to run against whatever is already in your config. Score the three census questions from the vendor's documentation alone for each MCP server you have connected, and any cell you cannot resolve stays visible as a dated unknown rather than a guess [18]. Any server that returns silence on all three gets treated as though the answer to all three is yes: scoped credentials that cannot reach an environment file, and output a human reads before it becomes a file operation. The tradeoff is not hidden. You will over-restrict servers that were clean, and you will pay for it in manual steps the demo never had. The alternative is granting file and credential access on the strength of documentation that, by this census's count, mostly declines to say what it puts in your agent's context [3].
Ranked by verification strength, evidence, and original report placement.
The audit examined 19 widely deployed MCP servers against the Model Context Protocol specification's own definitions to record what each server's current documentation discloses.
MCP servers can put text into an agent's context through several distinct surfaces: tool descriptions, an optional server-level instructions field, resource content, prompt templates, and the tool results themselves.
Almost none of the ecosystem's most widely deployed MCP servers document which of those context-injection surfaces they actually use.
The authors describe the result as a census, not a ranking.
For each server the audit recorded three things: whether its documentation discloses a server-level instructions field, whether it discloses a user- or vendor-configurable free-text instruction surface, and whether it carries an explicit warning that content returned by its tools could contain embedded instructions.
The modal answer across all three columns is undocumented, which the authors treat as the finding itself, because a security reviewer cannot evaluate a surface a vendor never mentions.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two grades of proof under one headline
The vulnerability half is quotable by anyone: NVD's description appears verbatim, with the CWE class, the crediting researcher, the affected range 0 through 2.1.2, both CVSS scores and a VulnCheck advisory carrying a retrieval date. The census half rests on one team reading 19 vendor doc pages, and the methodology section breaks off mid-sentence in what we have, so the rows are asserted rather than shown. Strong where it borrows outside records, self-certified where the finding actually lives.
Protocol everywhere, disclosure nowhere
MCP itself is plainly in use — 19 servers described as widely deployed, Context7 as widely installed, a revision shipped in July. The practice this story is about has barely any uptake: silence is the modal entry in every column, and the specification asks for nothing better, leaving transparency to individual maintainers. The one place adoption could be measured against a deadline, a published fix for the Context7 flaw, was still empty four days after disclosure.
Hedged below its own finding
The piece keeps trimming its own claim: census not ranking, documentation not code, absence of a documented fix rather than an assertion about later releases, and both CVSS numbers instead of the frightening one. It even declines to make Context7 the villain. A finding this blunt, delivered with that much throat-clearing, lands slightly under its evidence rather than over it — the risk is that readers under-react to the blank cells, not that they over-read them.
Auditing a field it also publishes guides for
digitalapplied.com is scoring an ecosystem it covers commercially: the piece routes readers to its own companion census on coding-agent data terms and its stateless-core migration guide, and the reproducible-method framing is itself a recurring franchise. That pull is toward publishing more scorecards, not toward flattering any vendor — no relationship with Upstash, Noma Security or VulnCheck is claimed or disclosed either way, and the one question left implicit is why Context7 is the illustration while the 19 named servers get columns.
Verifiable at the edges, single-sourced at the core
One publisher, one retrieval date, nobody yet checking the table. The identifier, weakness class, scores and version range would hold up against a public lookup tomorrow; the ecosystem-wide conclusion would wobble if a single maintainer produced a doc page the auditors missed. Middling is the honest reading until a second party reruns a column.