major labs
Report · Q3 security re-base · State of MCP

Measured consistently, the agentic web did not get safer this quarter

The first fresh deep scan since Q2. Where the method held steady, MCP security slipped or stalled: risky-code prevalence ticked up, and four in five sensitive servers still ship no authentication. Telling maintainers barely helped.

One number is a re-base, not a delta — read before the composite

The supply-chain scanner changed method this quarter, so its exposure rate is not comparable to Q2 and its apparent improvement is a measurement artifact, not a real-world gain. Because that pillar feeds the composite Trust Index, we are withholding the composite this quarter rather than let a re-based pillar inflate it. The two pillars measured the same way as Q2 — code safety and identity — are reported as clean deltas below.

By the numbers

37.5%
ship a risky pattern
up from 35.4%
78.6%
sensitive, no auth
flat from 79.8%
67
high-severity servers
up from 55
2 of 47
warned servers fixed
6 got worse

Security & supply chain as of 2026-09-05, identity as of 2026-08-29. 2,408 servers deep-scanned, firsthand and aggregate-only. Live at majorlabs.co/security.

Finding 1 · code safety

More servers scanned, a higher share at risk

We deep-scanned 2,408 maintained servers, 407 more than Q2. The share carrying at least one risky code pattern rose to 37.5 percent from 35.4, and the count at high severity climbed to 67 from 55. Growth is not diluting the risk; it is adding to it. The dominant pattern, by a wide margin, is server-side request forgery surface: 818 of the flagged servers.

Deep-scan severity, 2,408 servers

Each server counted once at its highest severity.

Low 1,506Elevated 835High 67
Finding 2 · identity

Four in five sensitive servers still have no authentication

Of 2,330 servers scanned for identity posture, 733 touch sensitive data over the network. Of those, 576 show no authentication in source — 78.6 percent, essentially unchanged from 79.8 in Q2. This is the authorization gap agentic commerce keeps colliding with, and a full quarter of attention has not moved it. A server that handles sensitive data and checks nobody's identity is the failure mode a signed mandate is supposed to prevent.

Identity posture, 2,330 servers
No sensitive data1,377
Sensitive, no auth576
Auth, no sensitive220
Sensitive, with auth157
Of every server that touches sensitive data, only 157 authenticate and 576 do not. The ratio has not improved. Identity is still the pillar the ecosystem is not building.
Finding 3 · remediation

We told 47 maintainers. Two fixed it. Six got worse.

This is the finding no one else can make, because it needs a cohort tracked over time. In Q2 we flagged 47 high-risk servers to their maintainers through coordinated disclosure, then re-scanned the same 47 this quarter. Two fully fixed the issue. Four reduced it. Thirty-five were unchanged. Six got worse. Net, the cohort did not improve. Disclosure is necessary and it is not sufficient; a warning that a stranger has to act on, unpaid and unenforced, mostly does not get acted on.

The 47-server disclosure cohort, re-scanned 2026-08-29
Unchanged35
Got worse6
Reduced risk4
Fully fixed2
Scorecard

The two clean pillars, Q2 to Q3

Measured the same way both quarters
PillarQ2Q3Direction
Risky-pattern share35.4%37.5%worse
High-severity servers5567worse
Sensitive, no auth79.8%78.6%flat
Servers deep-scanned2,0012,408wider
Supply-chain exposure75.2%36.2%*re-based
Composite Trust Index38withheldsee note

*Supply-chain method changed this quarter; the two figures are not comparable and the pillar is excluded from any delta claim.

Method, and why the composite is withheld

Every figure is a firsthand, read-only deep scan of maintained public MCP servers, aggregate-only, no per-server findings published. Code safety and identity were measured with the same instrument as Q2, so their movement is a real delta. The supply-chain scanner changed method this quarter, so its exposure rate is a re-baseline: 75.2% → 36.2% reflects how we measure, not what maintainers did.

The composite Trust Index equal-weights the three pillars. With one pillar re-based, the composite would move for a reason that is not real, so we withhold it for one quarter rather than publish a number we would have to caveat. From next quarter, all three pillars share a stable method and the composite resumes as a clean series.

Cite: Major Labs (2026). The State of MCP — Q3 Security Re-base. majorlabs.co/reports/state-of-mcp-security-q3.