Before Agents Connect: Measuring Pre-Runtime Security Signals in MCP Server Metadata
Abstract
Model Context Protocol (MCP) registries increasingly mediate how agent clients discover third-party tools, launch local servers, and connect to hosted endpoints. For many servers, registry metadata is the first evidence available before any code is installed or remote endpoint is contacted. This paper measures what security-relevant information is visible at that pre-runtime stage. We collect a frozen 2026-08-12 snapshot of 5,000 records from the official MCP Registry and build a conservative scanner over transport, package, repository, credential, and container-image fields. The rules report metadata-level risk signals rather than confirmed vulnerabilities: missing source provenance, remote endpoints without documented authentication headers, required secret-bearing configuration, package-version metadata gaps, credential-like variables not marked as secret, and OCI references without digest pinning. The scanner produces 6,119 deduplicated findings. Automated validation over 169 sampled findings confirms that each sampled row matches the intended registry condition, and a follow-up human audit of 18 rows finds no clear disagreement while identifying boundary cases in package-version and secret-marker rules. The two dominant patterns are remote endpoint records without authentication-header metadata (3,231) and records without repository metadata (2,411). Less frequent package and OCI findings remain directly actionable. These results show that lightweight registry linting can improve transparency and reproducibility before runtime security analysis, without executing third-party servers or probing remote endpoints.