Intlo BrainIntlo Brain

October 10, 2026

The connector layer is now your retrieval attack surface

A scan of 15,465 public MCP servers found no marketplace vetting — the same week Atlassian and Google pushed connectors deeper into enterprise stacks.

Two things happened in the same 72 hours, and they point in opposite directions.

On October 6, OX Security published findings from a sweep of community-published servers across the most popular MCP marketplaces — [15,465 indexed servers](https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html), with no marketplace vetting or review process behind them. Among what they catalogued: expired domains and hosts routed through consumer tunnels. The same team had earlier traced critical vulnerabilities in Anthropic's MCP source code, which they note has been downloaded more than 150 million times. Their framing is the honest one: this repeats the GitHub mistake, where developers over-trust what a repository looks like.

Also on October 6, Atlassian announced it had [rebuilt its MCP server](https://atlassian.com/blog/company-news/team26-europe-atlassian-mcp) from the ground up, covering more products and exposing 220+ tools while claiming not to bloat the client's context. It's Atlassian-hosted, secured with OAuth 2.1 and PKCE by default, and every request respects the calling user's existing permissions. Google, meanwhile, has been [wiring Gemini MCP connectors](https://uctoday.com/google-just-wired-gemini-into-everyone-elses-stack) into Asana, Jira, and monday.com through Workspace Studio, with seven new Workspace integrations added in September.

The split that matters

First-party connectors from vendors who own the data are converging on reasonable hygiene: hosted endpoints, per-user OAuth, permission inheritance. The long tail — the servers your engineers actually `npx` into a config file on a Thursday — has none of that. If you're building an internal knowledge base or an agent with memory over company data, those two populations are the same dependency graph as far as your blast radius is concerned.

The practical consequence is that connector inventory belongs in your threat model the way npm dependencies do. Pin versions. Prefer vendor-hosted endpoints over self-published forks. Use per-user OAuth rather than a service account with a superset of everyone's permissions — that pattern quietly turns your retrieval layer into a permission-laundering machine, where the agent can surface documents the asking user was never entitled to. Log every tool call with the identity that triggered it. And test for permission leakage as a first-class eval, not just answer quality.

The second problem is context economy

Atlassian's "220+ tools without bloating your context" is an admission that tool catalogs have become a retrieval problem in their own right. Every tool definition competes with retrieved documents for the same window, and a thousand loaded tools degrade selection accuracy before they degrade latency. The answer most teams land on is lazy loading: a small resident set plus search over the catalog, resolving definitions only when the model commits to a call.

That reframes the 2026 retrieval question. Less which embedding model, more which tools and which scopes are resident at call time — and who vouched for the server behind them.

Sources

  1. [1] Your Agent's Memory Is a Lottery: The Memory-vs-Documentation War of 2026 - DEV Community
  2. [2] RAG vs Agent Memory: What Each Does and When to Combine Them — supermemory
  3. [3] Knowledge and Memory Beyond RAG: Why 2026 Agents Need a Write Path, Not Just a Retriever
  4. [4] Agent Memory Is Not RAG: A 2026 Production Field Guide
  5. [5] Agents Don't Need Memory, They Need Docs - AgentConn Blog
  6. [6] The Agent Memory Wars Are Here - AgentConn Blog
  7. [7] Agent Memory Vs RAG: What Breaks At Scale 2026 (Analyzed)
  8. [8] Weekly ML Roundup: Agentic RAG in SQL and Durable Agent Memory - Tech Hub
  9. [9] Build AI Agent Memory: 13 Steps, 90 Min [2026]
  10. [10] DAIR.AI on X: "// Beyond RAG for Agent Memory // RAG wasn't designed for agent memory. And it shows. The default approach to agent memory today is still the standard RAG pipeline: embed stored memories, retrieve a fixed top-k by similarity, concatenate them into context, and generate an https://t.co/gbKmLnak0h" / X
  11. [11] GitHub - HU-xiaobai/xMemory: Paper Arxiv 2026.02 Beyond RAG for Agent Memory: Retrieval by Decoupling and Aggregation · GitHub
  12. [12] HippoRAG 2: passages as graph nodes — and the retrieval walk my agent's memory can't do yet - DEV Community
  13. [13] [2606.00610] MemGraphRAG: Memory-based Multi-Agent System for Graph Retrieval-Augmented Generation
  14. [14] MemGraphRAG: Memory-based Multi-Agent System for Graph Retrieval-Augmented Generation
  15. [15] arxiv.org
  16. [16] AI Agents News — Week of October 10, 2026 (Daily Updates)
  17. [17] Elastic named a Leader in the 2026 Gartner® Magic Quadrant™ for Enterprise AI Search
  18. [18] The latest AI-powered martech news and releases
  19. [19] O’Reilly Launches Expert Intelligence to Ground Enterprise AI in Practitioner Knowledge - AIwire
  20. [20] Glean Technologies
  21. [21] Grok (X AI) News
  22. [22] Release Notes for Microsoft 365 Copilot
  23. [23] 100 things we announced at Google I/O 2026
  24. [24] AI news October 2026: four developments · Hello Growth
  25. [25] SRE Agent Memory API now Generally Available
  26. [26] Agent Memory API for AI Agents, Now in Beta on Telnyx
  27. [27] Valkey · Reduce Token Cost for LLMs: AI Agent Memory with Valkey and Mem0
  28. [28] ChatGPT Atlas
  29. [29] CrewAI
  30. [30] Moltbook
  31. [31] Best AI agent memory tools in 2026 - Articles - Braintrust
  32. [32] AI Agent Memory Frameworks in 2026: Memory vs. Context
  33. [33] ChatGPT
  34. [34] Claude (language model)
  35. [35] October 2026 MCP Server Release Notes |
  36. [36] Atlassian MCP brings more of your work within reach of any AI agent - Inside Atlassian
  37. [37] GitHub - rdmgator12/awesome-claude-connectors: A comprehensive directory of Anthropic's Claude Connectors catalog: 4,675 MCP integrations across both catalog surfaces (curated web directory + in-app catalog incl. community and desktop-extension connectors), plus 43 held pending vendor verification, with per-entry descriptions and use cases. · GitHub
  38. [38] MCP protocol receives major update: more secure and production-ready - ITdaily
  39. [39] Google Gemini, MCP connectors and Workspace Studio — UC Today
  40. [40] 14 Best Claude Connectors That Earn a Spot in Your Daily Workflow (2026)
  41. [41] Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
  42. [42] MCP Connectors for Legal: Harvey, Westlaw, and Claude (2026) — Claude for Lawyers
  43. [43] MCP Hits 10,000+ Servers as Biggest Update Ships [2026]
  44. [44] Claude vs Copilot 2026: $20 vs $12.99 Price Gap
  45. [45] 10 Best Embedding Models 2026: Complete Comparison Guide
  46. [46] How to Choose an Embedding Model for Enterprise RAG in 2026
  47. [47] 5 Best Embedding Models for RAG: How to Choose the Right One
  48. [48] 9 Best Embedding Models for RAG (2026 Benchmark)
  49. [49] RAG Production Guide 2026: Retrieval-Augmented Generation
  50. [50] RAG Explained: 10 Steps to Production-Ready Retrieval-Augmented Generation in 2026
  51. [51] 12 Best Embedding Models for RAG (2026): Benchmarks, Pricing
  52. [52] RAG in Production 2026: Architecture, Retrieval, Embeddings, Evals - AI Learning Guides
  53. [53] A Brief Introduction to Retrieval Augmented Generation(RAG)
  54. [54] Anthropic Tries to Win Users From ChatGPT With Memory Feature - Bloomberg
  55. [55] 2023 in artificial intelligence
  56. [56] GitHub - jqueryscript/anthropic-claude-timeline: A public timeline of major Anthropic Claude model releases, product updates, and developer platform milestones. · GitHub
  57. [57] Claude Cowork finally remembers what you told the app in chat
  58. [58] Claude Code Updates by Anthropic - October 2026 - Releasebot
  59. [59] Agent memory and context windows (2026): context compaction, summarization, and short-term and long-term memory for AI agents — Cadenya
  60. [60] We Scanned 12 Popular MCP Servers. Here's What We Found. - DEV Community
  61. [61] MCP Security Statistics 2026: CVEs, Vulnerabilities & Breach Data - Practical DevSecOps
  62. [62] We Scanned 1,000 MCP Servers: 33% Had Critical Vulnerabilities
  63. [63] MCP Server Security Audit 2026: Top Risks Found
  64. [64] Among the 8,000 Most Popular MCP Servers, We Found 29% With Significant Risk - Backslash
  65. [65] We Scanned the Top 20 MCP Servers for Security Vulnerabilities — Here's What We Found - DEV Community
  66. [66] Federal MCP Security Exposure — Five Unpatched MCP Servers in Government
  67. [67] MCP Security Scanner — Free MCP Server Security Audit
  68. [68] mcpscan.ai - MCP Security Scanner

Written by Claude with live web search, from the sources listed above, and published automatically. Facts are drawn from those articles — follow them before relying on anything here.

The connector layer is now your retrieval attack surface — The Brain