Security Audit Finds Anthropic's MCP Reference Servers Vulnerable, Introduces Hallucination-Based Vulnerabilities

✍️ OpenClawRadar📅 Published: March 30, 2026🔗 Source
Security Audit Finds Anthropic's MCP Reference Servers Vulnerable, Introduces Hallucination-Based Vulnerabilities
Ad

MCP Server Security Audit Results

A comprehensive security audit of 100 Model Context Protocol (MCP) server packages revealed significant security issues. The audit found that 71% of servers scored an F, with zero servers receiving an A grade. This includes Anthropic's own reference implementations that are often considered the "Gold Standard."

Hallucination-Based Vulnerabilities (HBVs)

The audit identified a new class of vulnerability called Hallucination-Based Vulnerabilities. When MCP tools have vague descriptions (like "manages files"), Claude is forced to guess parameters. This creates both security vulnerabilities and token waste as Claude enters "reasoning loops" trying to determine tool boundaries, burning through context windows and message limits.

Specific Findings

  • The Reference Trap: Official servers for GitHub and filesystems—the ones Anthropic recommends—scored 0/100 on baseline security tests. These servers allow "unbounded" inputs, meaning prompted agents can be tricked into deleting or exfiltrating data due to lack of internal safety guardrails.
  • RCE-Class Risks: The audit identified structural precursors to RCE vulnerabilities similar to CVE-2025-68143 that previously affected the ecosystem.
  • Authentication Limitations: Even with OAuth configured, poorly defined tools remain vulnerable. Sophisticated prompts can turn Claude into a tool for accidental or intentional data destruction.
Ad

Protection Recommendations

  • Audit your servers: Don't trust servers just because they're in Anthropic's official repository.
  • Harden your manifests: Ensure every tool has minLength, maxLength, and strict pattern regex in its JSON schema.
  • Run the Scanner: Use the open-source audit tool: npx @agentsid/scanner

Key Takeaway

Agentic setups are likely "vulnerable by default" because official templates prioritize flexibility over safety. Properly hardening tool definitions can both protect data and reduce token consumption by preventing unnecessary reasoning loops.

The full white paper and methodology are available at: https://github.com/stevenkozeniesky02/agentsid-scanner/blob/master/docs/state-of-agent-security-2026.md

📖 Read the full source: r/ClaudeAI

Ad

👀 See Also

Architectural fix for AI agent over-centralization: separating memory, execution, and outbound actions
Security

Architectural fix for AI agent over-centralization: separating memory, execution, and outbound actions

A developer realized their AI assistant was becoming an 'internal autocrat' by handling long-term memory, tool access, and autonomous decisions in one component. The solution involved separating the system into three roles: private controller, scoped workers, and outbound gate.

OpenClawRadar
820 Malicious Skills Found in OpenClaw's ClawHub Marketplace
Security

820 Malicious Skills Found in OpenClaw's ClawHub Marketplace

Security researchers identified 820 skills in OpenClaw's ClawHub marketplace containing confirmed malware including keyloggers, data-exfiltration scripts, and hidden shell commands. These skills can execute code and interact with the local environment, creating supply-chain security risks.

OpenClawRadar
Two Approaches to Reduce Data Leak Risk with AI Agents
Security

Two Approaches to Reduce Data Leak Risk with AI Agents

A Reddit post outlines two methods for developers to control where their AI agent data goes: using your own API keys directly with providers like OpenAI or Anthropic to cut out middlemen, or running open-source models locally with tools like Ollama and OpenClaw.

OpenClawRadar
AI-Automated Daily Security Audit for AI-Operated Store
Security

AI-Automated Daily Security Audit for AI-Operated Store

An AI-operated store runs a daily security audit autonomously without human scheduling or cron jobs. The AI agent checks for SSRF vulnerabilities, injection risks, and auth gaps, then generates a report for senior developer review.

OpenClawRadar