AI

143,000 vulnerabilities in 25,000 MCP servers. The company that counted them just got bought.

Enkrypt AI spent two months scanning 268,000 of the tools AI agents call and found holes in 73% of the servers hosting them. Anaconda acquired the company for an undisclosed sum. It’s vendor data — and it’s still the most specific public measurement of the layer agents actually run on.

N Noah · The Sharp Brief · August 5, 2026 · 4 min read
An open server rack in a dark data center aisle with loose network cables exposed

Anaconda — the company most data teams know as the thing that installs their Python packages — announced Tuesday that it has acquired Enkrypt AI, a startup that red-teams AI models and agents before they ship. Terms were not disclosed.

The acquisition is not the interesting part. The number Enkrypt brought with it is. In the two months leading up to the announcement, the company says it scanned more than 268,000 tools — the individual functions an AI agent is allowed to call — across 25,000 Model Context Protocol servers. It found more than 143,000 vulnerabilities. Seventy-three percent of the servers had at least one.

MCP is the plumbing — the open standard that lets an agent reach out of the chat window and touch a real system: your CRM, your file store, your calendar, your payments dashboard. Every one of those connections is a server somebody stood up fast, usually one team, almost never with a security review attached. Enkrypt’s scan is the first published attempt to measure how much of that layer is load-bearing and unexamined at once.

Consider the source, then consider the number

This is a security vendor publishing a scary statistic about the problem it sells the fix for, on the day it got acquired for building that fix. That deserves the obvious discount. “Vulnerability” is doing heavy lifting — the disclosure doesn’t break the 143,000 into severity tiers, and a permissive scope on a read-only tool is not the same animal as a prompt-injection path to a wire transfer.

Apply the discount and the number is still bad. Even if most findings are low severity, 73% means the base rate of “this server has something wrong with it” is a coin flip that lands heads three times in four. Nobody else has published a competing census, and in the absence of a neutral measurement, the vendor’s is the one the market prices on.

Why a package manager is buying a red team

Anaconda has now bought three companies into the same thesis: Outerbounds for orchestration, Kilo Code for agentic engineering, and now Enkrypt for security and compliance. CEO David DeSanto’s framing is that enterprises are already running AI applications that “contain exploitable vulnerabilities and weaknesses” and cannot easily see them.

Translation: the company that spent a decade curating which open-source packages you were allowed to install has decided the same job now exists one layer up, for models, agents, and MCP servers. Enkrypt brings pre-deployment red-teaming across more than 300 attack categories, runtime guardrails that run inside a customer’s own environment, and compliance automation mapped to the NIST AI Risk Management Framework and the EU AI Act. It is already an OpenAI compliance integration partner; Anaconda says the same model-agnostic support is planned for Anthropic.

Our take: Agent security keeps getting sold as a model problem — can it be jailbroken, will it say something terrible. That framing is comfortable because it puts the risk inside somebody else’s lab. Enkrypt’s scan points somewhere worse: the risk is in the connectors, and the connectors are yours. You wrote them. You deployed them. Nobody audited them, because six months ago they didn’t exist. It is the pattern of every dependency layer that ever mattered — npm, Docker images, CI runners — where adoption outruns scrutiny for exactly one cycle, and the correction shows up as an acquisition spree. That cycle just ended.

What to watch

The short version: enterprises spent 2026 wiring agents into everything on the theory that the hard safety problem lived inside the model. The scan says it lives in the 268,000 small functions the model is allowed to call — and that almost nobody has looked at them.

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook (PDF) lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.