Skip to main content

Live data report

The State of MCP Exposure

AI agents talk to your systems over the Model Context Protocol. When an MCP server runs without authentication, any agent - or any stranger - can list and often call its tools. This page tracks how exposed that surface really is, using real scans, updated hourly.

Vysiro data last updated August 24, 2026. Domains are never stored - only anonymized counts.

What Vysiro is seeing

MCP checks run
134

Real MCP exposure checks run through Vysiro (a domain can be checked more than once).

No authentication
0%

of the 0 checks that found an MCP endpoint had at least one that answered with no auth.

llms.txt secret leaks
0%

of the 47 checks that found an llms.txt saw a credential-shaped string leak.

Methodology: each figure is a tally of real scans run through the Vysiro MCP Exposure Checker. A domain is counted once per check; only booleans are stored (endpoint found, auth required, llms.txt present, leak found). No hostnames, no named servers.

Unauthenticated = anyone can call your tools

An MCP server with no auth lets any client enumerate every tool and, in many cases, execute them - read files, hit internal APIs, move data. It's an open door with your agent's permissions.

llms.txt is read by assistants - and by attackers

Teams paste internal URLs and, occasionally, live keys into llms.txt. AI assistants ingest and repeat it. A leaked secret here is a secret in every model's context.

The wider picture (2026)

Independent researchers spent 2026 measuring this surface. These figures are theirs, cited in full - context for why we started tracking it.

Is your AI surface exposed?

Check your domain in seconds. Free, no signup, and your result joins this anonymized count so the picture keeps getting sharper.

Check my domain