I scanned every public MCP server for security bugs. Here's what I found.
The author developed MCPWatch, an open-source scanner to identify security vulnerabilities in public MCP servers on GitHub. Initial results uncovered critical flaws, including CVEs, prompt injection risks, and path traversal issues, highlighting the absence of a public security registry for MCPs.