# Researchers found that 1 in 5 MCP access policies came back broken or missing

DevFeed: [Researchers found that 1 in 5 MCP access policies came back broken or missing](<https://devfeed.tech/articles/researchers-found-that-1-in-5-mcp-access-policies-came-back-broken-or-missing-8481.md>)

Original publisher: [Read original article](<https://thenewstack.io/mcp-vibe-coding-security/>)

Author: Shawn Petty

Published: 2026-09-10T15:00:00Z

Content type: opinion

Language: en

Sources: [The New Stack](<https://devfeed.tech/sources/the-new-stack.md>)

Topics: [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [contributed-cloudbolt](<https://devfeed.tech/tags/contributed-cloudbolt.md>), [github](<https://devfeed.tech/tags/github.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [model-context-protocol-mcp](<https://devfeed.tech/tags/model-context-protocol-mcp.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [security](<https://devfeed.tech/tags/security.md>), [vibe-coding](<https://devfeed.tech/tags/vibe-coding.md>)

## AI overview

The article argues that MCP deployments need stronger authorization and narrower credentials. It highlights prompt-injection risks in tool descriptions, broad default scopes, and limited OAuth use among MCP servers.

## Source excerpt

Bob from finance built a scheduling tool last month. He described it to an AI assistant on a Sunday afternoon, The post Researchers found that 1 in 5 MCP access policies came back broken or missing appeared first on The New Stack.