A security firm scanned 25,000 AI-agent servers and found exploitable holes in nearly three-quarters. That's the same protocol now connecting AI tools to Procore and Revit.
Enkrypt AI's scan of 25,000 Model Context Protocol servers found more than 143,000 vulnerabilities, affecting 73% of them — and Anaconda just bought the company that found it. MCP is the same connector standard Autodesk and Procore are building AI integrations on.
A cybersecurity firm spent two months scanning 25,000 live servers running the Model Context Protocol — the standard that lets AI agents connect to real software — and found exploitable vulnerabilities in 73% of them. The company, Enkrypt AI, just got acquired. The protocol it tested is the same one Autodesk and third-party developers are using to wire AI agents into Procore and Revit.
What Enkrypt AI actually found
Anaconda announced its acquisition of Enkrypt AI on August 4, 2026, folding in a company that had spent the run-up to the deal auditing the AI ecosystem's newest piece of plumbing: MCP servers, which let an AI agent read files, query databases, or trigger actions in outside software instead of just answering questions in a chat window. Enkrypt scanned more than 268,000 individual tools across 25,000 of these servers and found over 143,000 vulnerabilities — affecting roughly three out of every four servers tested. Enkrypt characterized the findings as exploitable weaknesses already sitting in production, not lab conditions.
Why this is a construction problem
MCP isn't an abstraction for construction software anymore. Autodesk publishes its own MCP server for the Platform Services data model, giving developers a standard way to point an AI agent at Revit and BIM project data. Separately, systems integrator AMC Bridge has demonstrated an MCP connector linking Autodesk Platform Services and Procore, aimed at letting an AI agent pull data across both platforms at once. That's exactly the kind of independently built, early-stage connector Enkrypt's scan describes — stood up fast by a vendor or an internal IT team, wired to real project data, and never audited.
A GC's VDC coordinator experimenting with an AI assistant that reads model data, or an IT department that connected an AI tool to Procore through a third-party integration, is running the same class of software Enkrypt found broken most of the time.
What to check before you connect one
| Question | Why it matters |
|---|---|
| Who built the MCP server — a major vendor, a systems integrator, or an internal script? | Enkrypt's scan covered the broad population of live servers, most of which aren't from platform vendors with dedicated security teams |
| What project data can it reach — cost data, drawings, schedules, RFIs? | A vulnerable server exposes whatever it was built to touch; scope the connection to the minimum the task needs |
| Has it been through any security review, or just a functional test? | "It works" and "it's been checked for command injection and auth bypass" are different bars, and Enkrypt's numbers say most deployed servers haven't cleared the second one |
| Is it internet-facing, or limited to your internal network? | Exposure surface matters as much as the vulnerability itself |
The takeaway
MCP is becoming the standard way AI agents plug into construction software, and that's a real capability — not something to avoid. But Enkrypt's scan is the first hard data point on how those connectors actually hold up in the wild, and the number is bad: about three in four had exploitable holes. If your firm, or a vendor pitching you an AI add-on, has built an MCP connector to Procore, Revit, or your project data, ask who's audited it before you trust it with anything sensitive.
Forward this to whoever in your shop is evaluating an AI add-on for Procore or Autodesk this quarter.
Friday one chart — every week, one piece of data that should change a decision on your project.
- What is MCP and why does it matter for construction software?
- MCP (Model Context Protocol) is the standard that lets an AI agent connect to outside software and pull or act on real data instead of just chatting. Autodesk publishes an official MCP server for its Platform Services data model, and third-party developers have built proof-of-concept MCP connectors linking AI tools to Procore — meaning it's becoming the plumbing behind AI features in construction software, not just a developer curiosity.
- What did Enkrypt AI's scan actually find?
- In the two months before its acquisition by Anaconda (announced August 4, 2026), Enkrypt AI scanned more than 268,000 tools across 25,000 live MCP servers and found over 143,000 exploitable vulnerabilities, affecting 73% of the servers it tested. Enkrypt said these were real, exploitable weaknesses, not theoretical risks.
- Does this mean Procore's or Autodesk's built-in AI features are unsafe?
- Not directly. Enkrypt's scan covered the general population of live MCP servers across the internet, not a specific audit of Autodesk or Procore's own infrastructure. The relevance is that MCP is the same open standard those platforms are building on, and the scan shows most independently deployed MCP servers running today have real security gaps — a risk category worth knowing about before your firm or a vendor stands one up.
- Who is most exposed at a GC or design firm?
- Anyone who has connected an AI agent to project software through a custom or third-party MCP server — a VDC team piping model data into an AI assistant, an IT department that stood up an internal connector to Procore, or a vendor's early-stage AI add-on built on MCP. A vulnerable server can expose whatever project, financial, or model data it was built to access.
- Why did Anaconda buy Enkrypt AI?
- Anaconda, which already owns AI development tools Outerbounds and Kilo Code, acquired Enkrypt AI to add red-teaming, runtime guardrails, and compliance automation across its platform — covering AI systems from development through production. The deal was announced August 4, 2026; terms weren't disclosed.