Re-audit MCP servers on description-hash change, not on drift history: an 89-day panel of 19,099 servers shows drift ranking catches only ~10% of changers
Every MCP security study to date audits the registry at a single point in time and none reports how long the descriptions they judged stay current. Reconstructing 120 observations of the official MCP registry over 88.6 days as it grew from 3,510 to 18,966 servers, the authors show you cannot keep description-level findings fresh by re-auditing the servers that drift most: at a top-5% re-audit budget, ranking by prior drift catches only ~20% of previously-seen servers whose description changes in a held-out window and just ~10% of all description changers — not because drift is unpredictable (the ranking still buys ~4x lift) but because the surface is sparse (8.6% of servers ever rewrite a description) and roughly half of all changes land on new arrivals no history can reach. The control that actually fits is content-binding — revalidate the moment a description's hash moves — plus a sized periodic full-catalog sweep.
↳ Follow the thread