← Back to Playbooks
Agent Operations

MCP Management-Surface Defaults (Registry ≠ Trust)

Public listing answers existence, not trust — auth on by default

Operator recipe for MCP gateway and registry posture when public listing answers existence, not trust. Ox Security scanned 15,465 MCP servers across three public registries (official MCP, Cline marketplace, GitHub MCP registry) with zero consistent checkable governance; tools/list is often unauthenticated by design. Ox infra snapshot on the primary: ~5,095 unique hostnames; 15.6% (796) outside the US including 19 China / 18 Russia; 2.3% no longer DNS-resolve; six domains unregistered/available at $4–12/yr; 0.45% home/consumer tunnels. Spec context: CIMD replaces DCR in MCP 2026-07-28; enterprise-managed auth Stable Jun 2026; auth.md covers agent registration; Airlock covers runtime intent. Bifrost case: CVE-2026-86242 (8.1, Sep 6) unauthenticated custom plugin registration; CVE-2026-90898 (9.8, Sep 14, JFrog) unauthenticated MCP stdio client registration at /api/mcp/client — spawns a command at registration before the MCP handshake; root cause management API auth disabled by default with Docker bound 0.0.0.0; fixed in transports/v2.0.0 and v2.1.0 with a setup token. Distinguish OAuth client registration (CIMD/DCR) from a gateway admin "register MCP client" management endpoint. Recipe: auth by default (no auth-off state); scope privileged management actions beyond "logged in"; intent/content check before spawn; registry listing ≠ trust. Primary: https://workos.com/blog/mcp-governance-gap.

Core Workflows (4)

Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.

01

Treat registry listing as existence, not trust

Led by: Registry Operator

Ox Security scanned 15,465 MCP servers across three public registries (official MCP, Cline marketplace, GitHub MCP registry) with zero consistent checkable governance. tools/list is often unauthenticated by design. Ox infra snapshot on the primary: ~5,095 unique hostnames; 15.6% (796) outside the US including 19 China / 18 Russia; 2.3% no longer DNS-resolve; six domains unregistered/available at $4–12/yr; 0.45% home/consumer tunnels. Registry listing ≠ trust.

Sub-Agents
Gateway Operator
Skills Required
MCP registriesOx Security scan
Human TouchpointDo not treat a public registry listing as a governance or trust signal
02

Auth by default — no auth-off state

Led by: Gateway Operator

Recipe: auth by default (no auth-off state). Bifrost root cause: management API auth disabled by default with Docker bound 0.0.0.0. Fixed in transports/v2.0.0 and v2.1.0 with a setup token.

Sub-Agents
Registry Operator
Skills Required
Management API authSetup token
Human TouchpointRefuse an auth-off default on the management surface; confirm bind address is not 0.0.0.0 without auth
03

Scope privileged management actions beyond logged in

Led by: Gateway Operator

Recipe: scope privileged management actions beyond "logged in". Distinguish OAuth client registration (CIMD/DCR) from a gateway admin "register MCP client" management endpoint. Spec context: CIMD replaces DCR in MCP 2026-07-28; enterprise-managed auth Stable Jun 2026; auth.md covers agent registration.

Sub-Agents
Authorization Operator
Skills Required
CIMDDCRMCP 2026-07-28
Human TouchpointDo not treat a logged-in session as enough for admin register-MCP-client actions
04

Intent and content check before spawn

Led by: Gateway Operator

Recipe: intent/content check before spawn. Airlock covers runtime intent. Bifrost CVE-2026-90898 (9.8, Sep 14, JFrog): unauthenticated MCP stdio client registration at /api/mcp/client — spawns a command at registration before the MCP handshake. CVE-2026-86242 (8.1, Sep 6): unauthenticated custom plugin registration.

Sub-Agents
Runtime Policy
Skills Required
AirlockIntent checkBifrost CVEs
Human TouchpointBlock unauthenticated registration that can spawn a command before the MCP handshake