MCP developers keep hitting the same 14 infrastructure gaps — boilerplate, context saturation, an untrusted tool plane, and no exactly-once tool calls

Asked (summary):

What are the most repeated unsolved infrastructure problems MCP developers face at scale — across server creation boilerplate, tool discovery and context saturation from thousands of tools, security and authorization, and reliability of tool calls? Name the sources for each problem.

Live-web research found 29 recurring MCP issue families, each described independently on at least two hosts; filtering toward broad, durable infrastructure root problems leaves a 14-problem shortlist across the four requested areas, backed by official MCP SEPs, SDK repositories, security research, academic papers, and production engineering posts current through 8 October 2026. Recurrence here means source breadth — how many independent hosts describe the same problem — not a scientific prevalence estimate.

The infrastructure gap map

Bar length = independent hosts describing the problem (the ranking signal); the lighter figure is source pages, which can inflate from mirrors and editions. Hover or tap a problem for its evidence. Amber rows are narrower framework-level symptoms, kept for completeness.

What the map cannot say alone

Context saturation has hard numbers: the GitHub MCP server alone spends over 4,600 tokens on 26 tool schemas, full catalogs can exceed 248k tokens, and Claude-3.5 tool-selection accuracy drops from 97.6 to 69.2 (single-turn) when the pool scales 40×. arxiv.org
Tool poisoning is practical, not theoretical: across 45 real MCP servers and 353 live tools, poisoned descriptions hit an average 36.5% attack success rate across 20 LLM agents, with optimized variants reaching 84.2% while evading detectors. arxiv.org
Reliability lacks a contract, not just code: MCP's idempotent tool annotations are advisory only, so a blind retry after a timeout can create duplicate tickets or records, and five independent hosts describe the same duplicate-side-effect and orphaned-work failure modes. tasks.extensions.modelcontextprotocol.io
Even the official task extension concedes the authorization gap: binding tasks to a session and auth context is only a SHOULD, so a guessed task ID can retrieve another caller's results after the original request completes. modelcontextprotocol.io

The 14 problems, with evidence, missing controls, and partial mitigations

Ranked within each area by independent hosts, then source pages. Every mitigation listed is partial — frameworks, retrieval schemes, gateways, policy engines, and idempotency keys are competing overlays, not one end-to-end standard.

Appendix: all 29 recurring issue families

The full candidate set behind the shortlist; every family was described independently on at least two hosts.

AreaProblem familyHostsPagesPrimary source

Method: synthesis of repeated published problem statements about MCP infrastructure, current through 2026-10-08, covering official MCP specifications/SEPs and SDK repositories, GitHub issues, production engineering posts, security research, academic papers, framework documentation, and industry writeups. 14 shortlisted problems (each on ≥2 independent hosts; ranked by independent hosts, then source-page count) drawn from 29 recurring families. Primary sources span 10 displayed hosts; no displayed primary URL backs more than 21.4% of shortlist rows. Counts measure source breadth, not developer prevalence, and this is not proof that every gap is unaddressed in every MCP revision. For space, cards show two evidence items, missing controls, and mitigations each, and up to six named sources per problem.

This report was generated automatically by Keenable SELECT at a user's request, from publicly available web sources linked herein. Keenable does not review, verify, or endorse its contents and makes no representation as to accuracy, completeness, or timeliness; AI-based extraction may contain errors. Nothing in this report is investment, legal, financial, or other professional advice. All trademarks and referenced content remain the property of their respective owners; no affiliation or endorsement is implied. To report an error, rights concern, or request removal: legal@keenable.ai.

Keenable SELECTAsk your own question
Made with Keenable SELECT