CanopiiCanopiiAll serversEnterprise →

Live edition

The MCP Security Index

We independently scanned 17,395 Model Context Protocol servers. 11% scored D or F, 0% ship committed secrets, and 32% declare no authentication at all.

Recomputed continuously · captured · scoring rubric v2.9.0 · methodology

Baseline edition. This is the first month we have recorded, so there is nothing to compare against yet. Month-over-month deltas appear in the next edition.

Graded D or F
11%

1,913 of 17,395 scanned servers carry a failing or near-failing security grade.

Committed secrets
0%

Live credentials found in published source — an attacker can use these as-is.

No declared auth
32%

No OAuth 2.1 or protected-resource metadata gating who may invoke the server's tools.

Graded A
39%

6,707 servers verifiably pass the controls that apply to them.

Grade distribution

The median MCP server scores 88/100. Half the corpus falls between 80 and 91.

17,395 scored servers

A6,707 · 39%B8,342 · 48%
C504 · 3%
D980 · 6%
F862 · 5%
5,441 unverifiable
Score distribution summary
Mean score81
Median score88
25th percentile80
75th percentile91
Lowest score11
Highest score100

Popularity does not mean safety

Adoption and security posture move independently. The most-installed servers are not the safest ones.

By GitHub stars

CohortserversAverage scoreGraded D/F
1,000+ stars220
72
24%
100–999 stars910
79
13%
10–99 stars2,025
79
12%
Under 10 stars12,503
84
5%

By monthly downloads

CohortserversAverage scoreGraded D/F
100k+/month37
80
14%
10k–100k/month76
75
17%
1k–10k/month1,136
83
9%
Under 1k/month5,636
86
4%

Biggest score drops

Servers whose score fell on their most recent scan, over the last 30 days. Rubric-driven changes are excluded — only real movement appears here.

ServerChangeGradeCauseWhen
n-memoryio.github.menot-you/n-memory951580AFRescan of the same version
auvik-mcpio.github.wyre-technology/auvik-mcp931677AFNew release 1.4.01.4.2
misakanetio.github.Ikalus1988/misakanet931776AFRescan of the same version
flameoxio.github.morluto/flameox921775AFNew release 0.1.90.1.10
mcpproxy-goio.github.smart-mcp-proxy/mcpproxy-go901674AFNew release 0.52.10.53.0
fiatdock-mcpcom.fiatdock/fiatdock-mcp891673BFNew release 1.4.01.6.0
iqms-mcpio.github.wyre-technology/iqms-mcp891772BFNew release 1.2.71.2.9
meraki-mcpio.github.wyre-technology/meraki-mcp861571BFNew release 1.1.11.1.2
exomemio.github.Artexis10/exomem861670BFNew release 0.49.00.50.0
ironscales-mcpio.github.wyre-technology/ironscales-mcp841569BFNew release 1.2.01.2.1

Authentication and live exposure

We reached 4,683 live MCP endpoints. Of those, 2% declared that authentication was required and then served their tool surface to an anonymous caller.

Live endpoints probed
4,683

Servers we connected to and spoke MCP with directly.

Auth declared but not enforced
2%

Of probed endpoints — documented auth that anonymous callers get straight past.

Tool-poisoning markers
1%

Hidden instructions found in tool descriptions, which hijack the calling agent.

Attack surface and ecosystem

More exposed tools means more ways to be wrong. Ecosystem mix shows where the risk concentrates.

By number of exposed tools

CohortserversAverage scoreGraded D/F
No tools4,393
81
5%
1–5 tools5,465
83
9%
6–20 tools4,977
82
12%
20+ tools2,560
75
20%

By package ecosystem

CohortserversAverage scoreGraded D/F
repo / remote-only7,314
76
17%
npm6,968
85
5%
pypi2,804
81
8%
mcpb199
86
4%
nuget84
88
5%
cargo26
83
8%

What the ecosystem fails most

Every control in the catalog, ranked by failure rate within each domain. Failure rates are a share of servers where the control actually applied and could be evaluated.

Code safety

ControlFailure rateFailedWarnedEvaluated
No command-injection sinksGuardcode.no_command_injection
4%
59712616,596
No dynamic code executionGuardcode.no_code_eval
1%
2053116,596
No unsafe deserializationGuardcode.no_unsafe_deserialize
1%
92916,596
No path traversalGuardcode.no_path_traversal
0%
02,99816,596
No SSRF sinksGuardcode.no_ssrf
0%
05,55016,596

Secrets & credentials

ControlFailure rateFailedWarnedEvaluated
No committed secretsGuardsecrets.no_committed_secrets
0%
0016,596
Credentials sourced from environmentsecrets.from_env
0%
05,52316,596

Dependencies & supply chain

ControlFailure rateFailedWarnedEvaluated
No install/post-install scriptsGuardsupply.no_install_scripts
5%
33306,957
Package name not typosquattingGuardsupply.not_typosquatting
0%
709,744
No known-vulnerable dependenciessupply.no_known_vulns
0%
03,19412,375
Dependencies pinned (lockfile)supply.deps_pinned
0%
012,11816,596
Published with provenancesupply.provenance
0%
05,4646,957
Established maintainersupply.maintainer_established
0%
08,7309,744

Tool integrity

ControlFailure rateFailedWarnedEvaluated
No over-broad / destructive toolsGuardtool.no_destructive_scope
2%
277013,002
Tool descriptions free of injection markersGuardtool.no_injection_markers
2%
202013,002
No risky post-publish tool changes (rug-pull)Guardtool.no_rug_pull
0%
47784,848
Strict tool input schemastool.schemas_strict
0%
011,12212,491

Auth & transport

ControlFailure rateFailedWarnedEvaluated
Remote endpoints use TLSGuardtransport.uses_tls
0%
006,676
Authentication declaredauth.declared
0%
05,5866,676
Execution sandboxingdeploy.sandboxed
0%
013,13016,596
Live endpoint reachabledynamic.reachable
0%
000
Authentication enforceddynamic.auth_enforced
0%
000
No bind-all / exposed debugtransport.no_bind_all
0%
02,50316,596

Maintenance & governance

ControlFailure rateFailedWarnedEvaluated
Repository not archivedGuardmaint.not_archived
1%
197015,658
Actively maintainedmaint.actively_maintained
0%
060215,658
Declares a licensegov.declares_license
0%
03,43815,658
Has a security policygov.security_policy
0%
013,82416,596
Signed releasesgov.signed_releases
0%
000
Adoption & popularityreputation.adoption
0%
08,46916,604

How much we could verify

Absence of evidence is not safety. A partially-scannable server cannot present a high score, so confidence caps it.

CohortserversAverage scoreGraded D/F
High (80%+ verified)14,291
84
7%
60–80% verified2,305
77
4%
40–60% verified1
60
0%
Low (under 40% verified)798
40
100%

A further 5,441 listed servers declare no public repository or their source cannot be retrieved. They are listed without a score rather than given an invented one.

How to read these numbers

How often does the MCP Security Index update?
The live page recomputes from the database continuously; a permanent edition is frozen at the end of every calendar month at /mcp-security-index/YYYY-MM. Servers themselves are re-ingested and re-scanned every six hours, so a score change shows up on the live page the same day.
What does a D or F grade actually mean?
Grades come from a 0–100 score: A is 90 and up, B 75–89, C 60–74, D 40–59, F below 40. A confirmed security flaw caps the score outright — a server with a verified command-injection sink cannot exceed 20 no matter how good the rest of it is — so D and F overwhelmingly indicate a specific, evidenced problem rather than a general lack of polish.
Are month-over-month deltas comparing the same servers?
No. Distribution deltas cover the whole corpus, which grows as new servers are ingested, so part of any shift is composition rather than servers changing. The 'biggest score drops' section is the cohort-stable view: those are specific servers that were re-scanned and scored lower than before.
Why are some listed servers not scored at all?
If a server declares no public repository, or its source cannot be retrieved because it is private, moved, or removed, there is nothing to verify. Those are listed as unverified with no score rather than given an invented number, and they are excluded from every percentage on this page.
What counts as 'no authentication'?
A server that declares no authentication mechanism — no OAuth 2.1, no protected-resource metadata — so nothing gates who may invoke its tools. Separately, among servers whose live endpoints we probed, some declare that auth is required and then serve their full tool surface to an anonymous caller; that is reported as 'auth declared but not enforced'.
Can I use these numbers in my own work?
Yes. The full dataset behind each edition is downloadable as JSON and CSV from the page itself. Cite the Canopii Trust Index and link to the specific monthly edition you used, so the numbers you quoted remain verifiable.

Take the data

Every number on this page is downloadable. Attribution to the Canopii Trust Index is all we ask.

Looking for a specific server? Browse the full directory — every server page shows its complete control checklist with the evidence behind each result.