Security scores for every MCP server.
Continuously scanned for tool poisoning, prompt injection, supply-chain, and credential risk. One score per version — before your agents connect.
Browse all 21,212 servers →The MCP ecosystem, scored
Every server independently scanned and scored for security — here's how the ecosystem looks so far.
Scan from your terminal
canopii is the open-source CLI behind the Trust Index — the same scoring engine, run locally against any GitHub repo, npm/PyPI package, or live MCP endpoint. Free, no account.
npx canopii scan --github <repo>Need API access?
Check any MCP server's security score from your own tools — CI gates, procurement review, agent allow-lists. Key-authenticated, rate-limited.
Top scored
Mock, record/replay, verify and chaos-test any HTTP, REST, gRPC or LLM dependency over MCP.
Rust release tooling — drop-in GoReleaser parity + Rust extras.
Manage Coder workspaces, templates, and cloud development environments
AI-driven penetration testing - 22 security tools behind safety-hardened MCP endpoints
Run and manage H Company's Computer-Use Agents from any MCP client.
Control Miro whiteboards with AI. 105 tools for boards, diagrams, mindmaps, comments, SVG.
Needs review
Agent runtime with typed memory, knowledge and code graphs, plus file and web tools
Let any LLM watch a video locally — and search everything it has ever watched.
MCTS (Model Context Threat Scanner) is a local-first security scanner for MCP servers -- static and live tool discovery, multiple analyzers, auditable risk scores, and JSON, SARIF, and HTML output. For authors and platform teams; CI-ready, no cloud API.
Cross-Code Organizer (formerly Claude Code Organizer): cross-harness config dashboard for Claude Code, Codex CLI, MCP servers, skills, memories, agents, sessions, security scanning, context budget, and backups.
Search and memory across your AI coding sessions — one index over Claude Code, Codex, and Pi. Fuzzy-find and resume from the CLI, give agents recall via MCP, and get usage reports.
The open-source memory and observability layer for AI agents — persistent memory, loop detection, hash-chained audit trails, and a live dashboard, automatic on pip install.
Recently scanned
View all →A Deception Security Layer for MCP Servers. It injects "ghost tools" (fake security-sensitive tools) that act as honeypots.
A comprehensive Model Context Protocol (MCP) server for market sizing analysis, TAM/SAM calculations, and industry research. Built with TypeScript, Express.js, and following the MCP specification.
Fully functional AI Logic Calculator utilizing Prover9/Mace4 via Python based Model Context Protocol (MCP-Server)- tool for Windows, Linux, Claude App etc
Official BlazeMeter MCP Server for AI-driven performance testing
🧪 Local dev stack for MCP and Agent Skills
Free, open-source MCP server giving AI assistants 17 weather tools — a one-call weather summary plus forecasts, alerts, air quality, marine, radar, lightning, rivers, wildfires, and historical data back to 1940. Ask by city name or coordinates. Built on free public APIs (NOAA, Open-Meteo). No API keys, no signup.