[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86130-en":3,"doc-seo-86130-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86130,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability","Model Context Protocol (MCP) enables LLM-based agents to interact with external tools and services, yet MCP servers are increasingly used for security-sensitive actions. When large-scale runtime MCP servers are unavailable, assessments often rely on scanners over limited cases, leaving reliability uncertain. This study introduces MCPZoo, a multi-agent framework that converts in-the-wild repositories into validated runtime services, enabling ecosystem-scale measurement.","Rethinking MCP Security: A Large-Scale Study of Runtime MCP Servers and Security Scanner Reliability  \nPei Chen† Baichao An† Mengying Wu† Binwang Wan† Geng Hong†B Jinsong Chen†  \nXudong Pan†‡ Jiarun Dai† Min Yang†B  \n†Fudan University,‡Shanghai Innovation Institute  \n{peichen19, bcan20, ghong, xdpan, jrdai, [m_yang}@fudan.edu.cn](m_yang}@fudan.edu.cn), {wumy21, bwwan25, [jschen23}@m.fudan.edu.cn](jschen23}@m.fudan.edu.cn)  \nBCo-corresponding authors  \nShanghai, China  \narXiv :2607 . 1 1086v 1 [ cs .CR] 13 Jul 2026  \nAbstract  \nThe Model Context Protocol (MCP) has rapidly established itself as a standard interface for enabling LLM-based agents to interact with external tools and services. As MCP servers are increasingly entrusted with security-sensitive operations, understanding their real-world risks has become critical. In practice, due to the absence of large-scale runtime MCP servers, such understanding largely relies on security scanners applied to a small number of cases, yet the reliability of these assessments remains unclear.  \nIn this study, we revisit how MCP security is measured. We present MCPZoo, the largest collection of MCP servers for dynamic analysis to date. MCPZoo is constructed through a multi-agent framework for transforming in-the-wild static repositories into dynamic services. The framework emulates how human experts build, diagnose, and iteratively repair deployment and runtime defects by combining environment inference with feedback-driven refinement. To ensure practical interactivity at runtime, the servers are validated via real protocol interactions. As a result, MCPZoo contains 64,611 unique MCP servers (113,927 in total), with more than 37,288 supporting dynamic analysis. Leveraging MCPZoo, we conduct the first ecosystem-scale measurement of MCP serversand the scanners that analyze them. While existing scanners report that 96.89% of servers are risky, we find that these signals are unreliable. In particular, manual validation shows that less than 50% of sampled alerts are true positives, and scanner outputs exhibit clear inconsistency across scanners. Overall, MCPZoo enables large-scale, reproducible measurement of MCP server security and exposes limitations of current scanning practices. We further release a public query interface to support practical risk assessment of MCP servers.  \nKeywords  \nModel Context Protocol, MCP Servers, Agent Security, Reliability  \n1 Introduction  \nAs Large Language Models (LLMs) evolve into autonomous agents, their ability to act in the real world increasingly relies on structured access to external tools. The Model Context Protocol (MCP) provides a standardized interface for such interactions, leading to a rapidly growing ecosystem of MCP servers. These servers expose powerful capabilities, including file access, network communication, and system-level operations, making them a critical control point for real-world actions. This shift introduces new security risks. Unlike traditional components, MCP servers directly execute  \nactions on behalf of agents, so a single unsafe interaction may trigger unintended data flows or system-level effects. While prior work has identified risks such as prompt injection and unsafe tool invocation [55, 62, 67], it remains unclear how these risks manifest in the real-world MCP ecosystem.  \nProblem. Despite these concerns, we still lack a clear understanding of how secure the MCP ecosystem actually is in practice. Existing evidence is largely derived from isolated case studies or automated scanners, without systematic validation at scale. As a result, it remains unclear whether reported risks reflect real vulnerabilities, or artifacts of measurement methods.  \nAt the core of this gap lies a fundamental limitation: MCP servers are not readily measurable at scale. First, many security-relevant behaviors only emerge during runtime interactions between agents and servers, making static analysis insufficient. Second, real-world MCP server","cbCaiulIs7u2lk0B","https://ap.wps.com/l/cbCaiulIs7u2lk0B","pdf",970610,4,1,18,"English","en",105,"# Introduction\n# MCPZoo\n## Dataset Construction\n## Runtime Validation\n# Ecosystem Measurement\n## Security Behavior in Practice\n## Scanner Reliability Findings","[{\"question\":\"What problem does the study address about MCP security measurement?\",\"answer\":\"It highlights that current evidence is based on small isolated cases or automated scanners without systematic large-scale validation, so reported risks may not match real vulnerabilities.\"},{\"question\":\"How does MCPZoo enable runtime security analysis?\",\"answer\":\"It uses a fully automated multi-agent framework to transform fragmented public repositories into dynamic services, iteratively build and deploy servers, and validate them through real protocol-level interactions.\"},{\"question\":\"What do the findings say about the reliability of existing security scanners?\",\"answer\":\"Although scanners report that 96.89% of servers are risky, manual validation shows that less than 50% of sampled alerts are true positives, and scanner outputs are inconsistent across scanners.\"}]",1784208733,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"rethinking-mcp-security-a-large-scale-study-of-runtime-mcp-servers-and-security-scanner-reliability","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/rethinking-mcp-security-a-large-scale-study-of-runtime-mcp-servers-and-security-scanner-reliability/86130/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the study address about MCP security measurement?","Question",{"text":75,"@type":76},"It highlights that current evidence is based on small isolated cases or automated scanners without systematic large-scale validation, so reported risks may not match real vulnerabilities.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does MCPZoo enable runtime security analysis?",{"text":80,"@type":76},"It uses a fully automated multi-agent framework to transform fragmented public repositories into dynamic services, iteratively build and deploy servers, and validate them through real protocol-level interactions.",{"name":82,"@type":73,"acceptedAnswer":83},"What do the findings say about the reliability of existing security scanners?",{"text":84,"@type":76},"Although scanners report that 96.89% of servers are risky, manual validation shows that less than 50% of sampled alerts are true positives, and scanner outputs are inconsistent across scanners.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]