Scan of 7,749 MCP manifests: 33% blocked before attachment
BackBond scanned 7,749 public MCP server manifests (130,322 tool definitions) and found 33% matched at least one high-severity rule and would be blocked, 39% needed review, and 28% had no blocking finding. Prompt-injection patterns were rare at 1.2%, while the dominant risk was combining network, destructive and write tools in one manifest.
- 33% of 7,749 manifests blocked, 39% flagged for review, 28% clean
- 27% ship a network tool accepting an arbitrary URL with no allowlist
- 22% pair a fetch-shaped tool with destructive or privileged scope
- Manifests with more than 25 tools are blocked 85% of the time
Read next
Science