MCP Management-Surface Defaults (Registry ≠ Trust)
Public listing answers existence, not trust — auth on by default
Operator recipe for MCP gateway and registry posture when public listing answers existence, not trust. Ox Security scanned 15,465 MCP servers across three public registries (official MCP, Cline marketplace, GitHub MCP registry) with zero consistent checkable governance; tools/list is often unauthenticated by design. Ox infra snapshot on the primary: ~5,095 unique hostnames; 15.6% (796) outside the US including 19 China / 18 Russia; 2.3% no longer DNS-resolve; six domains unregistered/available at $4–12/yr; 0.45% home/consumer tunnels. Spec context: CIMD replaces DCR in MCP 2026-07-28; enterprise-managed auth Stable Jun 2026; auth.md covers agent registration; Airlock covers runtime intent. Bifrost case: CVE-2026-86242 (8.1, Sep 6) unauthenticated custom plugin registration; CVE-2026-90898 (9.8, Sep 14, JFrog) unauthenticated MCP stdio client registration at /api/mcp/client — spawns a command at registration before the MCP handshake; root cause management API auth disabled by default with Docker bound 0.0.0.0; fixed in transports/v2.0.0 and v2.1.0 with a setup token. Distinguish OAuth client registration (CIMD/DCR) from a gateway admin "register MCP client" management endpoint. Recipe: auth by default (no auth-off state); scope privileged management actions beyond "logged in"; intent/content check before spawn; registry listing ≠ trust. Primary: https://workos.com/blog/mcp-governance-gap.
Core Workflows (4)
Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.
Treat registry listing as existence, not trust
Led by: Registry OperatorOx Security scanned 15,465 MCP servers across three public registries (official MCP, Cline marketplace, GitHub MCP registry) with zero consistent checkable governance. tools/list is often unauthenticated by design. Ox infra snapshot on the primary: ~5,095 unique hostnames; 15.6% (796) outside the US including 19 China / 18 Russia; 2.3% no longer DNS-resolve; six domains unregistered/available at $4–12/yr; 0.45% home/consumer tunnels. Registry listing ≠ trust.
Auth by default — no auth-off state
Led by: Gateway OperatorRecipe: auth by default (no auth-off state). Bifrost root cause: management API auth disabled by default with Docker bound 0.0.0.0. Fixed in transports/v2.0.0 and v2.1.0 with a setup token.
Scope privileged management actions beyond logged in
Led by: Gateway OperatorRecipe: scope privileged management actions beyond "logged in". Distinguish OAuth client registration (CIMD/DCR) from a gateway admin "register MCP client" management endpoint. Spec context: CIMD replaces DCR in MCP 2026-07-28; enterprise-managed auth Stable Jun 2026; auth.md covers agent registration.
Intent and content check before spawn
Led by: Gateway OperatorRecipe: intent/content check before spawn. Airlock covers runtime intent. Bifrost CVE-2026-90898 (9.8, Sep 14, JFrog): unauthenticated MCP stdio client registration at /api/mcp/client — spawns a command at registration before the MCP handshake. CVE-2026-86242 (8.1, Sep 6): unauthenticated custom plugin registration.