MCP servers that fail: no over-broad / destructive tools
238 of the 11,636 Model Context Protocol servers where this control could be evaluated fail it — that is 2% of the evaluated corpus on the Canopii Trust Index.
- Servers failing
- 238
- Failure rate
- 2%
- Average score when failing
- 53/100
Why this matters
Tools exposing arbitrary shell or bulk-delete grant outsized blast radius.
How to pass it
Scope tools narrowly; avoid arbitrary command execution and destructive defaults.
Control id tool.no_destructive_scope — a guard control, so a confirmed failure caps the server's score at the medium ceiling no matter what else passes.
Affected servers
Each server's own page shows the evidence behind this result.
MCP tools for CRUMB artifacts and Logisim-evolution analysis and non-interactive simulation.
MCP relay server for Claude Desktop <-> Claude Code communication
MCP server for MQTT 5.0 brokers (publish, subscribe, topic discovery).
MCP server for the Eclipse Ditto digital twin HTTP API (things, policies, connections, more).
MCP server for Azure IoT Hub: device registry, twins, methods, jobs, messaging.
Self-hosted technical SEO audit MCP. 50+ checks, WAF detection, ephemeral. Built on LibreCrawl.
Drive a running OrcaSlicer with AI: load models, tune settings, slice, and analyze results
MCP server giving AI agents eyes and hands inside Android devices via ADB
MCP server for VRChat friends, worlds, groups, events, notifications, and VRCX history.
MCP server for AWS IoT Core: device registry, shadows, jobs, rules, messaging.
Operate local-ydb deployments through local or SSH-backed MCP tools.
MCP server for Zabbix monitoring and automation
Manage Cosmic CMS content, media, object types, and AI generation from any MCP client.
MCP server for ChipsNews — manage news sources, articles, and triggers
Causal root-cause analysis MCP server -- 56 tools across graphs, RCA models, PyRCA.
Debug microcontrollers via OpenOCD: flash, breakpoints, memory, registers and variables.
MCP server for database connectivity. Multi-DB (PostgreSQL, MySQL, SQLite), 19 tools.
Control a Mineflayer Minecraft bot with 120+ MCP tools: move, mine, craft, fight, build, and see.
Structured Docker operations (ps, images, logs, build) as typed JSON.
50 tools to manage Rundeck jobs, executions, projects, nodes, and system via MCP
Connect AI assistants to your Vaiz workspace: tasks, projects, boards, documents and milestones.
MCP server for Android device control via ADB and scrcpy
Pre-execution governance for AI agents. Validates tool calls before they execute.
Markdown memory for AI agents. Files you can read, edit, grep, and commit. Not a database.
Reads a boat's Signal K data and helps an AI assistant design and install KIP dashboards.
Full-featured ADB MCP server — 204 tools across 45 modules, from UI to baseband.
iOS leak/perf debugging via MCP: memgraph cycles, .trace analysis, SourceKit-LSP bridging.
Token-efficient SSH MCP with hash-verified files and persistent tmux sessions. 14 tools.
45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
Coolify 4.1.x MCP server — deploy, diagnose, and manage apps, services, and databases
MCP server for executing shell commands on remote hosts via SSH.
Persistent memory MCP server for Claude Code, Cursor, and GitHub Copilot.
Dynamically expose tools from proxied servers based on an Agent Persona
Your clipboard, but Claude can read it. Type-classified, secret-encrypted. macOS + Linux.
AI agent discovery, marketplace, messaging, and payments on Nostr - no platform, no middleman
MCP server for Obsidian vaults - AI tools with consistent canonical context. Local-first.
MCP State Sidecar: durable state persistence for multi-agent AI workflows
Autonomous MCP agent for grad school applications: prof discovery, cold emails, SOP, tracking.
Local-first nutrition MCP for AI agents: food, barcode, photo, intake, hydration, goals.
Unified MCP & Skill management gateway, shared across AI agents, 99% context token savings
No-KYC offshore hosting an AI agent runs end-to-end: no-email signup, crypto, domain, VPS, deploy.
A sandboxed, agentic workspace providing secure filesystem, bash, and uv-powered Python execution.
MCP server bridging AI assistants to OpenAI Codex CLI for code analysis and review
Crypto MCP — 99 tools across news, market, on-chain, sentiment, indicators, agent generation.
Your team's knowledge, always in context. SOPs, coding standards, and workflows for Claude.
Secure MCP SSH automation server with policy controls, resources, prompts, stdio, and HTTP.
Control macOS system settings, apps, windows, audio, displays, screenshots, and Focus mode via MCP.
Deploy and manage Bult apps from AI coding agents.
Android MCP server for AI-assisted development. Build, test, emulate, and automate.
Fail-closed Cedar policy gate + Ed25519 signed receipts for agent tool calls. Denies on any error.
MCP server for Android emulator automation via ADB.
MTG card prices, deck analysis, and investment intelligence — 19 tools over the Mythic Index API.
MCP server giving AI agents safe access to filesystem, databases, processes, and APIs.
Screen-reader navigation cost analyzer. Scores AT user effort to find, reach, and operate content.
Private AI context layer for semantic code search, dependency graphs, memory, and workspaces.
MCP server for Dynadot domain registrar — domain search, registration, DNS, and transfers
HYTHE — coordination bus + shared truth for AI agent fleets — self-hosted MCP server + stdio bridge.
Local-first MCP server: version-correct library docs, code map, and offline drift for your repo.
Persistent, shared memory for AI agents — facts, checkpoints, semantic search.
Coordination bus + shared truth for AI agent fleets — self-hosted MCP server + stdio bridge.
MCP server for SendGrid — global transactional + marketing email (Twilio-owned)
Author verifiable eval records through a draft→review→revise→submit loop with enforced graders.
A Model Context Protocol server for use with Tauri v2 applications
AI-controlled algorithmic trading engine exposing 40 MCP tools across 9 namespaces.
MCP server for JavaScript reverse engineering and browser debugging.
AI agent dating — personality matching, compatibility scoring, and real conversations on inbed.ai
An MCP server that provides access to common Cisco Modeling Labs (CML) operations.
Persistent memory and session intelligence for AI coding assistants. Zero config.
Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.
Build, deploy, drive and debug Android apps: Gradle, emulators, adb, logcat, UI automation
A Model Context Protocol server for use with Tauri v2 applications
MCP for the Opendock Neutron API.
MCP server exposing 100+ IT tools and utilities for developers and system administrators.
Extract reusable component libraries and design tokens from Vue applications
UX toolkit: 28 knowledge resources, 23 analysis tools & 4 workflow prompts for any MCP client
Database management — query, schema inspection, migrations for PostgreSQL, MySQL, SQLite.
Zaai Dev brand brief + captured design references for MCP-compatible AI tools.
MCP server for JavaScript reverse engineering and browser debugging.
MCP server for MDMA — exposes spec, prompts, docs, and package metadata to AI assistants.
Manage TrueTick Minecraft servers from AI: start/stop, live TPS, console, files, backups, mods.
MCP Server for Optics Design System documentation and token usage.
Hosted memory for AI agents that learns and forgets — one key across Claude, Cursor & ChatGPT.
MCP server for the Krónan grocery store API (Iceland)
Manage adaptive cron jobs and HTTP endpoint scheduling via AI assistants.
Official MCP Server for Mailtrap
Persistent semantic memory for SQL databases. Postgres, MySQL, MSSQL, SQLite.
Unofficial Proton Mail MCP — send, read, search & organize email over SMTP and IMAP
Control Android devices and emulators via ADB — screenshots, UI automation, and logcat.
An MCP server that provides a local, persistent, self-maintaining knowledge base for AI agents
Pare Docker ג€” Structured Docker operations (ps, images, logs, build, compose) as typed JSON.
260 MCP tools across 49 domains. AI Flywheel, quality gates, research, web scraping.
Dynamic context loading for AI assistants with TDD workflow and AST analysis
MCP server for App Store Connect & Google Play Console — iOS/Android app management
Secure Firecracker microVM sandboxes for AI agents: network policy, PII & injection guardrails.
Control Windy Word voice-to-text from any MCP agent — 60 tools across 12 categories.
Agent-safe fleet management for independent Solana validators and RPC nodes
Log amateur-radio QSOs to N3FJP logging software over its TCP API.
Incorporate a Delaware C-Corp from your agent — docs, cofounder e-sign, human-reviewed filing.
AI control of Android/iOS devices. Screenshots, UI tree, AI vision, Flutter, video. 49 tools.
A post-mortem succession protocol for AI agents. Black Box, handoff, time-locks.
This control is one of 29 in the published rubric — see how scoring works or how the ecosystem fails every other control.