We scanned 763 MCP servers. Here's what we found.

Most MCP servers ship with no input validation. A few have exploitable vulnerabilities. The real risk is in how tools combine.