CanopiiCanopiiAll serversEnterprise →

Security scores for every MCP server.

Continuously scanned for tool poisoning, prompt injection, supply-chain, and credential risk. One score per version — before your agents connect.

Browse all 24,842 servers →

The MCP ecosystem, scored

Every server independently scanned and scored for security — here's how the ecosystem looks so far.

20,349
Servers scored
36%
Rated A · strong posture
2,454
High-risk (D/F)
4,572
Live-verified endpoints

Grade distribution

20,349 scored servers
A7,312 · 36%B10,054 · 49%
C529 · 3%
D1,589 · 8%
F865 · 4%
6,117 unverifiable
See the full MCP Security Index

Scan from your terminal

canopii is the open-source CLI behind the Trust Index — the same scoring engine, run locally against any GitHub repo, npm/PyPI package, or live MCP endpoint. Free, no account.

$npx canopii scan --github <repo>
Star on GitHub

Need API access?

Check any MCP server's security score from your own tools — CI gates, procurement review, agent allow-lists. Key-authenticated, rate-limited.

Top scored

Needs review

Recently scanned

View all →