MCP security, in live numbers
An MCP server gets your agent's trust and often your credentials. These are the counts from our scans of every public server, updated after each scan run (last: 2026-09-27). Free to cite with a link.
- 36,367
- MCP servers listed, from the official registry
- 34,271
- graded by our scanner (94.2%)
- 62.4%
- of graded servers are A or B
- 10.9%
- of graded servers are D or F: significant or critical findings
- 2,318
- remote servers not answering (10.3% of 22,465 remote)
- 114
- grades lost to a rescan (downgraded or revoked), all public
The risks, in plain words
Tool poisoning. A server describes its tools in text the model reads. A description can carry instructions the user never sees, such as reading a file and passing it along. Our scan reads every tool description for them.
Too much access. A server that can send, delete, buy or post acts with your permissions. We count its write tools and show them on every listing.
No authentication. A remote server that answers anyone lets anyone use whatever it connects to. The grade checks that a remote endpoint asks for credentials.
Abandoned code and lookalikes. An unmaintained package, or one published under a name close to a real brand, is where supply-chain attacks land. The grade weighs maintenance and whether the publisher owns the name.
Servers that vanish. A remote endpoint that stops answering breaks every agent that depends on it. We check each one about four times a day.
Skills with hidden text. Agent skills are instructions an agent follows. Invisible Unicode characters, encoded payloads and lines like "do not tell the user" are what our skill scan looks for.
Before you connect a server
- Check its grade and read the findings, not just the letter.
- Prefer a remote server from the brand's own domain, with OAuth.
- Give it the narrowest token you can, and never a personal admin key.
- Look at its write tools; turn off the ones you do not need in your client.
- Check it is still answering: a dead server is replaced faster than it is fixed.
Method: the rubric and how we rank. The full write-up: State of MCP security, September 2026.