What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

BackBond reports that 33% of 7,749 distinct public MCP tool manifests matched at least one high-severity rule in its Agent Scan 0.6.3, ruleset 2.0.2. That is a vendor-reported static scan of saved tool metadata—not evidence that a server is vulnerable, has been exploited, or behaves as its description claims.

What BackBond collected

BackBond says it queried public registry endpoints that answered unauthenticated requests on August 31, 2026. It reports reaching 8,147 endpoints and collecting 7,749 distinct manifests containing 130,322 tool definitions. The company saved the responses to MCP’s tools/list request; it says it did not run server code or invoke any tools. The collection details are in BackBond’s account of the scan.

This is a snapshot of the endpoints the collector could reach without authentication, not a census of all MCP servers. BackBond also says TLS verification was disabled during collection, so it cannot vouch for the authenticity of every endpoint. Those limits matter when interpreting the results.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to read the 33% figure

Using Agent Scan 0.6.3 with ruleset 2.0.2, BackBond classified 28% of manifests as having no blocking finding, 39% as needing review, and 33% as matching at least one high-severity rule that its pre-attachment gate would block. These are the scanner’s reported categories for this corpus and version—not rates for the whole MCP ecosystem.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

A block means metadata matched a fixed rule. It does not confirm a vulnerability, an incident, or that the server actually performs the action described by its tools. Ari Katz, identified in the article as a BackBond team member, puts the distinction plainly: “It’s a metadata match against a fixed rule, not a vulnerability, not an incident, not a claim that the server does what its description says.”

Which metadata patterns stood out

BackBond’s reported matches point more often to combinations of capabilities and the destinations or inputs they accept than to instructions embedded in tool descriptions.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Reported pattern Share of manifests What the match describes
Arbitrary URL-like destinations without a schema allowlist 27% A tool’s metadata describes network destinations without an allowlist in its input schema.
Fetch-shaped tool alongside a destructive or privileged tool 22% The manifest contains both kinds of tools; the result concerns their presence together, not proof they were used in sequence.
Persistent-write tool accepting untrusted content 21% The metadata indicates a write capability that can take untrusted content.
Untrusted input reaching a shell or code executor 3.5% The scanner matched a metadata pattern connecting untrusted input with execution.

These percentages are BackBond’s rule matches over the manifests it scanned; they should not be read as confirmed behavior or as mutually exclusive categories. One manifest can contain multiple tools and can match more than one pattern.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prompt-steering descriptions were less common

BackBond says 91 manifests, or 1.2%, contained descriptions that tried to steer the model, while 10 included language explicitly forcing invocation. In this scan, those text patterns were reported less often than network, write, and cross-tool capability patterns. That comparison describes this scanner’s metadata findings only; it does not establish which kind of issue is more consequential in operation.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why metadata is an incomplete view

The scanner can evaluate what manifests declare, but declarations are not the same as implementation or runtime behavior. BackBond reports that 68% of manifests were only partially analyzable from static metadata, and 10% had at least one tool without an input schema. Those gaps limit what the scan can establish about allowed inputs and actual effects.

Scanner version also changes the result. On the same files, BackBond reports 3,477 blocks with version 0.5.15 and 2,532 with version 0.6.x after tightening rules. A headline rate therefore needs its scanner and ruleset version alongside it; these figures are not interchangeable measurements of a changing server population.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How manifest size relates to the reported block rate

BackBond reports that 13% of manifests with five or fewer tools were blocked, compared with 85% of manifests containing more than 25 tools. The median manifest had seven tools, and the largest had 1,082. The higher rate among larger manifests is an association in this scan, not evidence that size causes unsafe behavior. More tools may create more combinations for fixed rules to match, but the reported analysis does not test that explanation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a user can take from the scan

The results are best treated as a reminder to inspect capabilities before attaching a server, not as a blacklist or a security verdict. A tool manifest can help identify what a server claims it can do and what inputs it says it accepts; it cannot, by itself, verify implementation, provenance, or runtime behavior.

  • Review network destinations and whether inputs constrain them to an expected set.
  • Look at the full tool set, especially where fetching or untrusted input appears alongside persistent writes, privileged actions, or execution tools.
  • Check whether each tool declares an input schema, while remembering that a schema does not prove the server enforces it.
  • Use the scanner version and rule set when comparing findings or rates.
  • For stronger assurance, evaluate evidence beyond the manifest, such as implementation and behavior under controlled testing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.