← Back to brief
ResearchOfficialPreprintarXiv Software Engineering

Large-Scale Study Finds Inconsistent Human Oversight in Model Context Protocol Applications

A study of 1,723 Model Context Protocol (MCP) applications on GitHub finds that while most use configuration files and official SDKs, only about a third require human approval before tool execution. The analysis also notes a lack of standard naming conventions for configuration files, and that most applications allow LLMs to invoke enabled tools without additional checks. These findings highlight variability in safety-related practices across the MCP application ecosystem.

Why it matters: The inconsistent implementation of human oversight in MCP applications raises concerns about the safety and control of autonomous AI agents using these tools.

Full story at: arXiv Software Engineering