CanopiiCanopiiAll serversEnterprise →

Security scores for every MCP server.

Continuously scanned for tool poisoning, prompt injection, supply-chain, and credential risk. One score per version — before your agents connect.

Browse all 21,212 servers →

The MCP ecosystem, scored

Every server independently scanned and scored for security — here's how the ecosystem looks so far.

17,395
Servers scored
39%
Rated A · strong posture
1,842
High-risk (D/F)
4,683
Live-verified endpoints

Grade distribution

17,395 scored servers
A6,707 · 39%B8,342 · 48%
C504 · 3%
D980 · 6%
F862 · 5%
5,441 unverifiable
See the full MCP Security Index

Scan from your terminal

canopii is the open-source CLI behind the Trust Index — the same scoring engine, run locally against any GitHub repo, npm/PyPI package, or live MCP endpoint. Free, no account.

$npx canopii scan --github <repo>
Star on GitHub

Need API access?

Check any MCP server's security score from your own tools — CI gates, procurement review, agent allow-lists. Key-authenticated, rate-limited.

Top scored

Needs review

Recently scanned

View all →