· via dev.to (home feed)
Scan of top 20 MCP servers finds steering text in tool descriptions, stalled spec migration
A static scan of the 20 most popular MCP servers found instruction-style text in 8 of them, permission claims in tool descriptions, and near-zero uptake of the July 2026 protocol revision.

What the scan covered
A dated static analysis of the 20 most-starred Model Context Protocol servers, published by Pennyforge on dev.to on 7 October 2026, found instruction-style steering text in the tool descriptions of 8 of the 20 repositories, permission claims in two of them, and essentially no migration to the protocol's breaking July 2026 revision.
The backdrop is steep adoption. According to the report, the official TypeScript/Python SDK logged 242 million npm downloads in the month before the scan, and GitHub now lists 33,674 repositories tagged mcp-server — for a protocol that only arrived in November 2024. In May 2026 the U.S. NSA published security design considerations for MCP and said the protocol's rapid spread had outpaced the development of its security model, a judgement Pennyforge says it agrees with.
How the analysis worked
The authors shallow-cloned 20 repositories on the day of the scan: five official or reference servers — modelcontextprotocol/servers (91.1k stars), upstash/context7 (62.8k), ChromeDevTools/chrome-devtools-mcp (53.1k), microsoft/playwright-mcp (37.9k) and github/github-mcp-server (33.4k) — plus the highest-starred third-party projects on GitHub's mcp-server topic. A local static analyzer then applied five heuristic signals: instruction patterns in tool descriptions ("you must", "always", "prefer", "call this before"), permission claims covering databases, credentials, environment variables, tokens, files and arbitrary commands, external URL inventories, spec-state markers, and last-push dates.
The report flags its own limits: these are pattern matches on source, not runtime tests; matches can be false positives; and stars measure attention, not adoption.
What the descriptions actually say
The scan logged 41 instruction-pattern matches across 8 repositories. Quoted examples include chrome-devtools-mcp telling an agent to "ALWAYS prefer this tool over multiple individual" calls, context7's "You MUST call this function before" certain operations, and comparable phrasing in mcp-use and n8n-mcp.
According to Pennyforge, none of these is obviously malicious — steering hints are often genuinely useful — but the pattern matters because agents read tool descriptions while humans usually don't. That asymmetry is the mechanism behind what Invariant Labs called "tool poisoning" when it released the first MCP scanner, mcp-scan, in April 2025.
Permission claims show up as well. The report card shows permission matches in just two repositories: the official reference repo, whose environment tool is described as returning all environment variables, and n8n-mcp, whose diagnostic tool says it can include full environment variables and API response details — meaning a single diagnostic call can hand the connected model a deployment's environment. Pennyforge frames this as a design choice it is flagging, not judging.
A breaking revision with no takers
The 2026-07-28 MCP revision removed the initialize handshake and Mcp-Session-Id sessions entirely: every request now carries protocol version and capabilities in _meta, and server/discover is the new front door. Ten weeks later, per the scan, 0 of the 20 repositories show a clean new-spec signal. Eleven show only old-spec markers, four show a mix, and five are indeterminate because they rely on SDKs with no direct RPC code. The 91,000-star official reference repository is itself still old-spec — which Pennyforge presents as a dated migration status rather than a criticism.
Directories aging faster than the ecosystem
Two of the original top-20 slots were already 404s on scan day: punkpeye/fetch-mcp and puppeteer-mcp/puppeteer-mcp had been renamed or moved. Their replacements include a 486-star puppeteer server last pushed in March 2025. tadata-org/fastapi_mcp, at 12k stars, has not been pushed since 24 November 2025 — 14 months. Meanwhile the original MCP scanner, Invariant Labs' mcp-scan, is now Snyk's agent-scan following an acquisition, so security tooling is consolidating even as the server ecosystem churns.
Why it matters
MCP tool descriptions are instructions the model obeys but the operator rarely inspects. Building a nutrition-label habit — reading descriptions before connecting an agent — is cheap and surfaces real exposure, such as tools that can return an entire environment in one call. The scan also documents the ecosystem's practical state: a breaking spec revision with near-zero uptake among the most visible projects, star-ranked directories pointing at moved or dormant repos, and the worst known CVEs (mcp-remote at CVSS 9.6; MCP Inspector below 0.14.1 at 9.4) sitting in glue packages outside the server repositories anyone bothers to inspect. Until the security model catches up with adoption, as the NSA effectively warned, dated snapshots like this one are the cheapest due diligence available.
- #mcp
- #security
- #ai-agents
- #static-analysis
- #developer-tools