NVD logged CVEs for four MCP servers in about 35 hours, each because every tool it exposes needs no authentication. A fifth MCP flaw, LiteLLM's authentication bypass, is already on CISA's exploited-vulnerabilities list.
Reality
- Evidence62
- Adoption58
- Hype gap−6
- Incentives45
- Confidence52
Plain Claude Code, with no MCP server or skill, matched AWS's and draw.io's official diagram tools in a five-setup test published on dev.to. Every setup improved as the author kept adding instructions, and the finding covers one architecture on Claude Opus 5, graded by the author.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
ChatGPT has accepted MCP Events in all plans since OpenAI's DevDay on 29 September 2026, delivered only by HMAC-signed webhook. Swapping a polling tool for events means running subscription storage and callback checks against an experimental spec.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence70
A developer's GraphRAG build turns Thailand's 96-section PDPA into a 190-node graph so an agent can walk from Section 26 to the fines that cite it. The published part argues the vector-search gap from vocabulary and reports no measured recall figures.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+15
- Incentives25
- Confidence45
DoorDash built a shared Agent Gateway that checks permissions, manages credentials, filters which tools agents see, forwards calls and logs them. MCP settles how tools are listed and called, but deciding who may call which tool, and with whose account, was work DoorDash still had to build.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence45
CData's Connect AI Gateway, now in early access, holds AI agents to each user's own permissions down to specific rows and columns. Teams deploying agents can now buy that control, though the accuracy claims behind it come from CData's own tests.
Reality
- Evidence35
- Adoption8
- Hype gap+35
- Incentives70
- Confidence40
Authorizer, a self-hosted open-source auth server, drops files a user may not see before an AI assistant's vector search scores them. Teams can run that check inside their own login server, though its limits on AI agents rest on the maintainers' word.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
QRFLOW.codes' developer refused both fixes a security report proposed for open OAuth client registration, saying either would lock Claude and ChatGPT out. The exposure turned out to be a consent screen showing attacker-chosen app names, now handled by trusting redirect hosts.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence50
Backstage's catalog is now something coding agents call at runtime, and the AiResource kind added in v1.54 records which tools a given agent may use. Platform teams still have to work out what checks that record.
Reality
- Evidence34
- Adoption45
- Hype gap+42
- Incentives72
- Confidence40
A dev.to post says the 2026-07-28 specification dropped the initialize flow and Mcp-Session-Id, so MCP requests can land on any instance. The refund agent it walks through still breaks on the second pod.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives25
- Confidence40
One machine sent the same twelve research questions through eight free servers, three times about an hour apart on 2026-09-15. The rule that caught most of the failures was the one for empty bodies.
Reality
- Evidence62
- Adoption52
- Hype gap+10
- Incentives65
- Confidence58
Claude Code screens MCP output for character length before it counts tokens, so a dev.to test measured a result at roughly twice the documented 25,000-token cap sitting in the conversation untouched. The docs describe the same guard in two units.
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap−5
- Incentives35
- Confidence62
Bitdefender's free macOS beta attaches to Claude Desktop, Cursor, Codex and OpenCode as an MCP server, covers only the requests those tools route through it, and drops the container when the prompt ends.
Reality
- Evidence46
- Adoption12
- Hype gap+18
- Incentives76
- Confidence52
A Magic: The Gathering rules agent works out which source is entitled to settle a question before it answers. Its evaluation pits 496 structured documents against a single BM25 pass over the same corpus, graded blind.
Reality
- Evidence45
- Adoption12
- Hype gap−10
- Incentives65
- Confidence50
A consultancy's account of production MCP work on Django client apps calls the protocol a transport layer. Its sample server calls django.setup(), imports the Order model, and dispatches tool calls on a string.
Reality
- Evidence60
- Adoption25
- Hype gap+12
- Incentives55
- Confidence55
A read-only MCP server with four Iceberg tools ran against six live catalogs off a single environment variable. Three of the tools worked on pyiceberg alone, and the fourth needed a storage package for the object store.
Reality
- Evidence70
- Adoption25
- Hype gap+5
- Incentives30
- Confidence62
A Thai-language walkthrough estimates 15 to 20 MCP calls to build a ceramics studio site on WordPress.com. Counting each documented operation, including one status update per item to publish, gets to 22.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap−10
- Incentives28
- Confidence42
The expanded partnership also makes Salesforce capabilities callable from Gemini Enterprise with no connector to build, because both sides implement the open Model Context Protocol. Teams already on Agentforce get that part without new work.
Reality
- Evidence30
- Adoption25
- Hype gap+35
- Incentives85
- Confidence45
OpenAI's plugin docs define one root manifest and a single directory shared by ChatGPT and Codex, while the built-in scaffold still writes the older .codex-plugin layout and an MCP file that needs converting.
Reality
- Evidence62
- Adoption28
- Hype gap+10
- Incentives78
- Confidence52
The MCP spec mandates OAuth 2.1 with PKCE, dynamic client registration and metadata discovery for remote servers. The one-hour tokens and customer-facing audit logs procurement asks about come from a guide's own bar.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence48
Earlier coverage
- Foundry's Toolbox pins the MCP allow-list that a server can otherwise redefine at any time
Build · September 17, 2026 · 1 publisher
- The default MCP deployment buys a Kubernetes operational surface for request/response traffic
Build · September 17, 2026 · 1 publisher
- Mapbox's Agent Toolkit lets a model add a stop to a route the driver is already driving
Build · September 17, 2026 · 1 publisher
- Eight MCP servers per session push the p90 connect wait to 35.5 seconds
Build · September 15, 2026 · 1 publisher
- A $4 rewrite of MCP tool descriptions moved Toolmetry's SQLite success from 34% to 100%
Build · September 15, 2026 · 1 publisher
- MCP's Python SDK 2.0 yields two values where wrapper libraries still unpack three
Build · September 13, 2026 · 1 publisher
- Leaving readOnlyHint unset is what makes a missing destructiveHint default to true
Build · September 12, 2026 · 1 publisher
- Salesforce exposes its platform to coding agents through more than 60 new MCP tools
Product · September 11, 2026 · 1 publisher
- Renaming FastMCP to MCPServer closes stdio before an unpinned server finishes its handshake
Build · September 11, 2026 · 1 publisher
- A caching proxy handed one caller's poisoned MCP instructions to a client that never connected
Build · September 11, 2026 · 1 publisher
- A hand audit of 45 register questions found 34 hedges and three confabulations
Build · September 10, 2026 · 1 publisher
- MCP's stateless revision moves session continuity into a string the model repeats back
Build · September 6, 2026 · 1 publisher
- Empty tax IDs turned a risk check into eleven clean sellers
Build · September 2, 2026 · 1 publisher
- MapMcp publishes your whole tool list before you add a single auth check
Build · September 2, 2026 · 1 publisher
- Curator approval gates every record AWS Agent Registry shows a consumer
Build · August 31, 2026 · 1 publisher
- A read-only MCP key drops the write tools out of tools/list
Build · August 30, 2026 · 1 publisher
- Auto-approving read_resource moves MCP's retrieval decision into the model
Build · August 29, 2026 · 1 publisher
- MCP's 2026-07-28 revision relocates client capabilities from the handshake into every request
Build · August 29, 2026 · 1 publisher
- Agents climbed from 3% to 50% of the work created in Linear in four quarters
Invest · August 28, 2026 · 1 publisher
- AWS wires Bedrock Guardrails into the hook that fires before a Strands agent calls a tool
Build · August 27, 2026 · 1 publisher
- Lovable will hand your published app to any AI assistant as a set of callable tools
Product · August 27, 2026 · 1 publisher
- Nutanix puts agent token quotas and a single-control-plane claim into Enterprise AI 2.8
Product · August 26, 2026 · 1 publisher
- AWS puts the trace waterfall inside the tool response, betting verification is the slow part
Build · August 25, 2026 · 1 publisher
- MCP's empty-string cursor: the null check that hides most of a tool catalog
Build · August 24, 2026 · 1 publisher
- AWS's phone-ordering host is really an MCP wiring diagram with no retry button
Build · August 24, 2026 · 1 publisher
- MCP standardizes the tool call, not the authority to cause the effect
Build · August 24, 2026 · 1 publisher
- A 200 Is Not A Row Count: How Agents Inherit Open Data's Silent Caps
Build · August 23, 2026 · 1 publisher
- A SKILL.md layer quietly rerouted an agent off the MCP tools it was given
Build · August 22, 2026 · 1 publisher
- MCP's roadmap fast-tracks five priorities and quietly queues everything else
Build · August 22, 2026 · 1 publisher
- EDR sees the file write, not the reason: the case for an agent-native detection layer
Build · August 21, 2026 · 1 publisher
- The agent did not fail, the client did: 90 logged MCP trials and a validator that ate the calls
Build · August 21, 2026 · 1 publisher
- MCP is a discovery layer, and your exposure list is a governance decision
Build · August 21, 2026 · 1 publisher
- Twin1's $20M bet: the unit of enterprise AI is one employee, not the org
Product · August 20, 2026 · 1 publisher
- MCP 2026-07-28 drops the `result` wrapper, and your unit tests will not notice
Build · August 20, 2026 · 1 publisher
- Binance gives agents a trading seat, and gives users the permission slip
Product · August 20, 2026 · 1 publisher
- x-mcp-header is a wire contract: one bad annotation invalidates the whole MCP tool
Build · August 19, 2026 · 1 publisher
- Amazon Q executed code from any repo you opened, and it is not the only one
Build · August 19, 2026 · 1 publisher
- Salesforce turns 200-plus Data 360 APIs into MCP endpoints, and governance into a grant decision
Product · August 19, 2026 · 1 publisher
- Kubernetes MCP servers hide the delete tool; hiding is not removing
Build · August 18, 2026 · 1 publisher
- Foundry IQ knowledge bases ship as MCP servers, and four behaviours break naive clients
Build · August 18, 2026 · 1 publisher