What is the registry-runtime gap in MCP?
Publication and evidence links for the Registry-Runtime Gap study.
- Collection
- research
- Updated
- 2026-07-30
- min read
- 4
- Version
- v1
Registry presence and declared metadata do not guarantee that an MCP endpoint is reachable, interoperable or behaving as described at observation time.
- Observed
- 2026-07-23 14:08 UTC
- Claim strength
- measured
- Dataset scope
- 31,407 discovered public MCP endpoint records; 152,781 repeated observations; 4,162 enumerable tool surfaces; 78,041 declared tools; 78.2% overall annotation coverage; 30,641 potentially state-changing tools, 7,618 of which lack measured annotations. Collected 2026-06-18T09:50:05.293Z to 2026-07-23T14:08:37.499Z (35 days).
- Methodology
- External, credential-free observation of publicly reachable MCP endpoints — protocol
initialize,tools/list, and schema inspection — aggregated without altering or otherwise interacting with any target beyond a read-only capability probe. Full method, exclusions and denominators are recorded in the published preprint. - Limitations
- Correction status
OPEN_PARTIAL_REPRODUCTION_REMAINING: the discovered-endpoint-record count reproduces as 31,408 rather than 31,407 (an open, unresolved off-by-one), and the state-changing-tools-without-annotation figures areNOT_REPRODUCIBLEbecause exact classifier provenance was not retained. The study's author is SaSame-affiliated and SaSame's own Observatory produced the observations (disclosed conflict of interest). This is a measurement, not a safety, security or endorsement verdict.
Measured — backed by a specific dated observation or dataset
Publication
DOI 10.5281/zenodo.21513720 records the published preprint, "The Registry-Runtime Gap in Agentic AI: A 35-Day Measurement of 31,407 Public Model Context Protocol Endpoint Records," version 1.0.0, published 2026-07-23.
| Metric | Published value |
|---|---|
| Discovered endpoint records | 31,407 |
| Repeated observations | 152,781 |
| Enumerable tool surfaces | 4,162 |
| Declared tools | 78,041 |
| Overall annotation coverage | 78.2% |
| Potentially state-changing tools | 30,641 |
| State-changing tools without annotations | 7,618 |
Measurement window: 2026-06-18T09:50:05.293Z to 2026-07-23T14:08:37.499Z (35 days). This is a registry-runtime measurement, not a security, safety or endorsement verdict — see the Boundary section below.
Evidence boundary
Core measurements are retained while one published-versus-retained endpoint count remains explicitly marked as an open mismatch.
Correction status: OPEN_PARTIAL_REPRODUCTION_REMAINING. An independent reproduction re-run returns 31,408 discovered endpoint records rather than the published 31,407 (an unresolved off-by-one, classified as a dedup/stale-projection ambiguity), and the state-changing-tools-without-annotation figures do not currently reproduce because the original classifier's exact provenance was not retained. The published v1.0 figures remain citable — no silent replacement is permitted — but the study is not treated as fully closed until this gap is resolved.
The study's author is SaSame S.R.L.-affiliated and SaSame's own Observatory produced the underlying observations. This conflict of interest is disclosed rather than obscured: the publication explicitly serves public understanding, methodology transparency, and SaSame's own Factory evidence station — it is not an independent third-party audit, and it is not a safety or security certification of any specific server.
Examples
2- 01
A registry entry can exist while its runtime endpoint is unavailable or exposes a different capability surface.
- 02
Repeated observations (152,781), tool-surface counts (4,162), declared-tool counts (78,041) and the 78.2% coverage figure all reproduce exactly on independent re-run; the discovered-endpoint-record count and the state-changing-tool annotation counts do not, and both gaps are recorded on this page rather than silently fixed in a later revision.