The Model Context Protocol is becoming the HTTP of AI integration. Every major agent framework uses it. MCP servers connect LLMs to databases, APIs, email services, file systems - anything the model needs to act on. The security model around these servers is roughly where npm was in 2014: install what you want, trust the metadata, hope nobody's lying.

On February 2, Koi Security published an audit of 2,857 skills on ClawHub, the package registry for the OpenClaw agent framework. They found 341 malicious skills, 335 of them delivering Atomic Stealer, a commodity macOS infostealer, through skills masquerading as crypto trading tools. The attack chain uses typosquatting, fake prerequisites, and social engineering to get users to execute shell commands that exfiltrate wallet keys, SSH credentials, and browser passwords. That's 12% of audited packages confirmed malicious, and this was one research team's first pass at one registry.

This is not novel. It is npm's left-pad era with higher stakes, because MCP servers execute with the privileges of the agent, and agents increasingly act on behalf of users. OWASP published a Top 10 specifically for MCP. Supply chain attacks are #4. Tool poisoning - where an attacker manipulates tool metadata to redirect agent behavior - is #3. If your organization uses MCP servers, apply the same SCA discipline you'd apply to npm: pin versions, audit dependencies, run a registry allowlist, and assume every unvetted tool is hostile until proven otherwise.