In August 2026, researchers counted approximately 15,930 public Model Context Protocol servers across four registries. The protocol that won the interoperability standard for AI agents – 500 million-plus monthly SDK downloads, 75-plus connectors – is now embedded in federal government data infrastructure. The U.S. Census Bureau publishes an open-source MCP server on GitHub. The GPO GovInfo MCP server went into public preview in January 2026. The Centers for Medicare & Medicaid Services and the Department of the Treasury have MCP integrations in pilot.
None of these deployments have a dedicated security authorization framework. There is no FedRAMP baseline for MCP.
The compliance gap is structural, not accidental
Federal agencies adopted MCP for the same reason the private sector did: it works. The protocol gives AI agents a standardized way to query government data, run tools, and access services without custom model training. But adoption moved faster than the compliance layer.
The NIST AI Agent Standards Initiative, launched February 2026, is working toward an interoperability profile. The NCCoE’s COSAiS framework – control overlays for securing AI systems – extends SP 800-53 to AI use cases but remains in development. FedRAMP 20x Phase 3 is active, but MCP is treated as a target technology within these emerging frameworks, not a separately authorized protocol. Agencies deploying MCP today are operating in a gap between what the protocol enables and what federal security standards currently cover.
The vulnerability is in the specification, not the implementations
This week’s ClawSecure disclosure sharpens the problem. The security vendor tested three MCP platforms – Linear, Notion, and Dropbox Dash – and found that the flaw lives in the MCP protocol specification itself, not in any individual vendor’s code. When content is created in Notion or Linear, the platform’s MCP server automatically fetches attacker-controlled links. No AI model interaction is required. Anyone with write access can turn the platform into a data-leak channel.
This matters for federal deployments because the protocol’s maintainers have already made their position clear: Anthropic confirmed that the STDIO command-execution behavior – where MCP servers can execute operating system commands without sanitization – is intentional. They declined to modify the protocol, leaving remediation to downstream deployers. For federal agencies, that means patching individual implementations does not fix the underlying design.
The numbers behind the gap
The current state of MCP security is not encouraging. Only 8.5 percent of public MCP servers use OAuth authentication. An estimated 30 to 82 percent of public servers have exploitable flaws, according to multiple security researchers. A July 2025 internet scan found approximately 1,862 publicly accessible MCP servers responding to unauthenticated requests. Earlier this year, Bitsight identified over 30,000 publicly exposed AI agent instances – many using MCP – in sensitive sectors including government, healthcare, and finance.
The federal government has published guidance. The NSA and CISA joint cybersecurity information sheet on MCP, released June 2026, recommends authenticating every caller, authorizing individual tool invocations, and treating the protocol’s trust boundaries as real security boundaries. The GSA hosted an MCP Server and AI Agent Government Hackathon running September through November 2026. NIST’s AI Agent Standards Initiative targets its first interoperability profile for Q4 2026.
But guidance is not authorization. Until COSAiS or FedRAMP 20x provides a formal security baseline for MCP deployments, agencies are making individual risk decisions without a shared standard for what “secure” means.
What this means for builders
For infrastructure decision-makers inside and outside government, the implications are concrete. First, every MCP server should be treated as an untrusted endpoint that requires independent authentication and strict tool-invocation authorization – the protocol itself does not provide these guarantees. Second, custom middleware or wrappers are necessary to enforce security boundaries, because the protocol maintainers have declined to change the underlying STDIO behavior. Third, the compliance path is uncertain: until the NIST interoperability profile or FedRAMP baseline materializes, any MCP deployment in a federal environment carries unmitigated risk.
The protocol won the standards war. The next question is whether the government can secure what it adopted before the gap between deployment and compliance becomes a liability no amount of patching can close.
A note on verification
No confirmed breaches of federal MCP servers have been publicly documented. The risk described here is structural – stemming from the protocol’s design and the absence of a federal security baseline – rather than the result of a specific incident. ClawSecure is a commercial security vendor with a product to sell, and their findings should be contextualized accordingly. The company is collaborating with bipartisan congressional offices on a national standard for independent AI agent testing. No independent third-party replication of their platform-layer findings has been published at the time of reporting.
