Stars Don’t Save You: Popularity Is Not Security in the MCP Ecosystem
Building on our previous research, we correlated the security issues identified in public MCP servers with metadata crawled from popular directories. We then analyzed whether indicators such as popularity, activity, and vetting serve as reliable metrics to infer the risk of adopting an MCP server.