Vibe Coding
MCPPrivacyDetector: Taint Analysis of 10,000+ MCP Servers Finds Credential and PII Leakage Above 10%
Researchers ran cross-language static and taint analysis across more than 10,000 real-world MCP servers and found credentials, API keys, and PII leaking through tool handlers at rates exceeding 10%. The framing matters: the leakage is protocol-induced, not just sloppy implementation — MCP's handler contract encourages passing raw environment and response data back through the tool boundary. It corroborates last week's 9,695-server audit from a completely different methodology.
Source
↳ Follow the thread