What is a malicious MCP server?

What one can do, how it reaches you, what the official registry looks like — and six checks to do by hand before you add one.

The short answer. An MCP server is a program your AI agent calls for tools. A malicious one is a server whose code, launch command or remote endpoint does something other than what its listing says — and your agent calls it with your permissions and your credentials. Nobody can tell you a server is safe. You can tell, in a few minutes, whether it is trustworthy enough to add.

What an MCP server can do

A local server is a process on your machine. The launch line in your agent's settings — npx, uvx, docker run or a binary — runs every time a session starts, as you, with your files, your SSH keys and your cloud credentials in reach. A launch line that downloads something and pipes it into a shell runs whatever that URL serves that day.

A remote server is an endpoint someone else runs. It receives every tool call your agent makes to it, and any token you put in its headers or environment. There is no code for you to read, only a host to trust.

Either kind writes text your model reads. Tool names, descriptions and results go into the agent's context. A server can put instructions there that you never see on screen and the agent may follow.

How a malicious one reaches you

A fake server, found by an assistant. In the FakeGit campaign Island documented in July 2026, over 800 repositories posed as AI Skills or MCP servers, and more than 600 listings for them were placed in public MCP and Skill directories — LobeHub, Glama, MCP.so and MCP Market. Assistants that search those directories surfaced them; AgentBaiting is Island's name for that technique. The payload was not in the source tree: it was a ZIP attached to a release, and the install steps pointed at it.

A registry that takes what it is given. OX Security submitted a proof-of-concept malicious MCP server to eleven public registries; nine accepted it without review (Cloud Security Alliance, April 2026).

A launch line that fetches and runs. A repository can check in an MCP settings file whose command downloads and executes something the moment a trusting editor or agent opens the folder — the shape check C20 looks for.

A package that changes after you added it. A launch line with no version — npx -y @scope/server — starts whatever the latest release is, every session. What you read last month is not necessarily what runs today.

What the official registry looks like

We enumerated every record in the official Model Context Protocol registry on 17 September 2026 and counted what is there. The census has the full distribution and the method; the figures that matter for this question are below. It names no servers and no publishers, and neither does this page.

What the census countedServersShare
Servers in the registry (latest version of each)33,033100%
Declare no source repository at all7,61323.0%
Offer a remote URL only — nothing to inspect18,75856.8%
Offer neither a package nor a remote4321.3%

Publication is concentrated: the median namespace publishes one server, and the most servers backed by a single repository within one namespace is 375. A monorepo of connectors is an ordinary pattern, and bulk registration is not a vulnerability — but the registry's own metadata cannot tell 375 independent servers from one repository registered 375 times, and neither can a person browsing it.

One more result, because it is the opposite of what we expected: none of the 7,600 FakeGit repositories, and none of their accounts, appear among the 20,379 repositories behind registry servers. The campaign's fake MCP servers went through third-party directories and chat surfaces, not the protocol's own registry. A registry listing is therefore not a sign of malice — and it is not a review either.

Six checks, by hand

1. Does it declare a source repository? No repository means no code to read and no history to judge. Treat it as a remote you are trusting on the listing's word.

2. Who owns that repository, and since when? Read the owner's Joined date before the README. An account and a repository created in the same month is the FakeGit shape.

3. Read the launch line. A curl or wget piped into sh, bash or node is the pre-trust execution class. Prefer a package you can name and pin.

4. Pin the version. npx -y @scope/server@1.2.3 or uvx server==1.2.3, so a new release cannot change what starts.

5. For a remote: is the host the vendor's own? Match the URL against the vendor's own website and documentation before you give it a token. A lookalike domain with a working endpoint is cheap.

6. Do not run a README's install steps verbatim. A ZIP link in the install instructions of a supposed MCP server was the delivery path in 211 FakeGit repositories.

What RepoGates does with the same questions

For an MCP server, the instrument RepoGates has today is the repository behind it, which the census shows reaches at most 76.8% of the registry. Within that:

What it covers, and what it cannot

A registry listing is not yet assessed as its own thing — its status, namespace verification, the package or image it launches and the secrets it asks for are on the roadmap, and nothing here claims that coverage before it ships with its false-positive run. A remote-only server has no code in the picture at all. Nothing RepoGates does observes what a server does once it runs.

RepoGates gates browser downloads — Download ZIP, release assets, Save-Link-As. It does not see git clone, package managers or curl — outside Claude Code with the RepoGates plugin, whose hook refuses a clone or install that names a blocked repository on the command line, before it runs. The hook sees Bash tool calls in that one client and nothing else: it does not see claude mcp add as a server yet, a server added by editing a settings file, or a call an agent makes to a remote MCP server. The MCP server is a check an agent can be told to call; an agent that never calls it is not stopped.

Questions

Is a server in the official MCP registry safe? A listing is not a review. In our census of 17 September 2026, 23.0% of the registry's 33,033 servers declared no source repository and 56.8% were remote-only, so there was no code to read. Publishing there says who registered a name, not what the server does.

Can RepoGates tell me an MCP server is safe? No, and nothing honest can. It scores the repository behind a server, flags a launch line that fetches and runs something, and records when an MCP directory sent you to a repository. It does not observe what a server does once it runs, and a registry listing is not yet assessed as its own thing.

Does the Claude Code plugin see claude mcp add? Not today. The hook reads Bash tool calls in Claude Code, and it does not resolve the command after claude mcp add to a server yet. It does resolve an npx package named on the command line to the repository that package declares.

Connect your AI agents The registry census

The repository checks, the check-up and the plugin run on the paid plans; C22 runs in the browser extension. Numbers on this page: the RepoGates census of the official MCP registry, 17 September 2026; Island, 20 July 2026; BleepingComputer, 21 July 2026; Cloud Security Alliance on OX Security's registry submissions, April 2026 — linked from the AgentBaiting page.