CanopiiCanopiiAll serversEnterprise →

Security scores for every MCP server.

Continuously scanned for tool poisoning, prompt injection, supply-chain, and credential risk. One score per version — before your agents connect.

Browse all 28,871 servers →

The MCP ecosystem, scored

Every server independently scanned and scored for security — here's how the ecosystem looks so far.

23,754
Servers scored
33%
Rated A · strong posture
3,753
High-risk (D/F)
4,516
Live-verified endpoints

Grade distribution

23,754 scored servers
A7,897 · 33%B11,107 · 47%
C997 · 4%
D2,832 · 12%
F921 · 4%
6,741 unverifiable
See the full MCP Security Index

Scan from your terminal

canopii is the open-source CLI behind the Trust Index — the same scoring engine, run locally against any GitHub repo, npm/PyPI package, or live MCP endpoint. Free, no account.

$npx canopii scan --github <repo>
Star on GitHub

Need API access?

Check any MCP server's security score from your own tools — CI gates, procurement review, agent allow-lists. Key-authenticated, rate-limited.

Top scored

Needs review

Recently scanned

View all →