MCP Discovery — Authorized Inventory
MCP Discovery — Authorized Inventory
The previous page combined public-internet scanning instructions, obsolete protocol fingerprints, and insufficiently scoped statistics. The raw note is retained in dumpster/AI/2026-09-02-legacy-ai-fact-check/raw-mcp/ for provenance.
Key jargon
| Term | Meaning |
|---|---|
server/discover | Current RPC used to advertise supported protocol versions, capabilities, and server identity. S1 |
| Capability discovery | Learning which protocol features and server operations are available. S1 |
| Inventory | An authorized record of MCP clients, servers, owners, versions, transports, tools, and exposure. S1 |
| Exposure | Network or local reachability; exposure alone does not prove missing authentication or exploitability. S2 |
Current discovery model
The 2026-07-28 protocol introduced server/discover and per-request version/capability metadata. Older fingerprints based on initialize, session IDs, GET /sse, or /messages identify legacy implementations at best and are not reliable signatures for the current protocol. S1
flowchart LR
A["Authorized asset scope"] --> B["Find configured endpoints"]
B --> C["Call server discover or compatibility probe"]
C --> D["Record version capabilities owner and controls"]Diagram semantics checked against the 2026-07-28 specification on 2026-09-02.
Corrected research claim
Knostic reported 1,862 discovered internet-exposed MCP servers and manually verified a sample of 119; all 119 sampled servers exposed tool listings without authentication. It is incorrect to say that all 1,862 were manually verified or that all MCP servers lacked authentication. The measurement describes a dated discovery method and sample, not the present population. S2
Safe inventory procedure
- Obtain written scope and identify the asset owner.
- Prefer configuration, registry, process, and cloud-control-plane inventory over blind scanning.
- Query only approved endpoints and use the correct dated protocol method.
- Record authentication, authorization, audience binding, transport, data access, and tool consequences.
- Do not invoke tools merely to prove they exist; test effects only under an approved test plan.