MCP Discovery — Authorized Inventory

MCP Discovery — Authorized Inventory

Replacement notice

The previous page combined public-internet scanning instructions, obsolete protocol fingerprints, and insufficiently scoped statistics. The raw note is retained in dumpster/AI/2026-09-02-legacy-ai-fact-check/raw-mcp/ for provenance.

Key jargon

Term Meaning
server/discover Current RPC used to advertise supported protocol versions, capabilities, and server identity. S1
Capability discovery Learning which protocol features and server operations are available. S1
Inventory An authorized record of MCP clients, servers, owners, versions, transports, tools, and exposure. S1
Exposure Network or local reachability; exposure alone does not prove missing authentication or exploitability. S2

Current discovery model

The 2026-07-28 protocol introduced server/discover and per-request version/capability metadata. Older fingerprints based on initialize, session IDs, GET /sse, or /messages identify legacy implementations at best and are not reliable signatures for the current protocol. S1

flowchart LR
    A["Authorized asset scope"] --> B["Find configured endpoints"]
    B --> C["Call server discover or compatibility probe"]
    C --> D["Record version capabilities owner and controls"]

Diagram semantics checked against the 2026-07-28 specification on 2026-09-02.

Corrected research claim

Knostic reported 1,862 discovered internet-exposed MCP servers and manually verified a sample of 119; all 119 sampled servers exposed tool listings without authentication. It is incorrect to say that all 1,862 were manually verified or that all MCP servers lacked authentication. The measurement describes a dated discovery method and sample, not the present population. S2

Safe inventory procedure

  1. Obtain written scope and identify the asset owner.
  2. Prefer configuration, registry, process, and cloud-control-plane inventory over blind scanning.
  3. Query only approved endpoints and use the correct dated protocol method.
  4. Record authentication, authorization, audience binding, transport, data access, and tool consequences.
  5. Do not invoke tools merely to prove they exist; test effects only under an approved test plan.