@nottiboy1337/mcp-open-registry-poc
v1.0.0
Published
PoC: Open Registry supply chain — unvetted server listing (security research)
Downloads
15
Readme
Open Registry Supply Chain PoC
Benign PoC for the Open Registry Supply Chain Risk finding: anyone with npm + GitHub can publish an MCP server to the open registry (registry.modelcontextprotocol.io) with no pre-publication review.
- Package:
@nottiboy1337/mcp-open-registry-poc - MCP name:
io.github.NOTTIBOY137/open-registry-poc - Server: Minimal benign MCP stdio server (one tool, no sensitive behavior).
Follow STEP_BY_STEP.md to run the exploit and prove unvetted listing.
