Automated + human-reviewed grading

Which MCP servers are actually safe to install?

A safety-graded, freshness-verified shortlist — explicitly not another 20,000-server dump. Automated scanning, a human-reviewed top tier, and a published false-positive rate.

71%of audited servers scored an F — see the findings
ASSESSMENT #AIM-2026-000147Sample listing

ai.adeu/adeu

ai.adeu/adeu

Automated DOCX Redlining Engine

B

85/100

BFreshness

Last commit: 2026-08-18T08:46:27Z

AMaintenance

4 human contributor(s).

BProvenance

Registry namespace verified.

Verified 2026-08-19 · Ruleset v0.1.0 · Automated

Finding

71%1

of servers scored an F in an independent audit of 100 packages — zero scored an A.

Finding

41%2

of servers in the official MCP registry run with zero authentication.

Finding

43%3

of tested servers show a command-injection risk pattern.

  1. 1.Independent audit of 100 packages, 2026 — including reference implementations from Anthropic and Microsoft.
  2. 2.Large-scale scan of the official MCP registry, 2026.
  3. 3.Independent 2026 audit data.

Full methodology and citation index on the Methodology page.

Four dimensions, graded independently

Never a single opaque number. Every listing shows evidence for each finding, dated and sourced.

§1
Safety

Dangerous capability surface, static scan findings, declared vs. actual permissions, known CVEs.

§2
Freshness

Last commit, last release, issue response time, and whether the endpoint is live right now.

§3
Maintenance

Contributor count, bus factor, release cadence, issue close rate.

§4
Provenance

Verified namespace, vendor-official vs. third-party, and a valid package-provenance attestation.

Read the full methodology

Chain of custody

How a grade gets published

Every server, every sync, no exceptions — not a one-time review that goes stale.

Designed, not live yet
  1. 1

    Sync

    Nightly pull from the MCP registry and each server's own package registry (npm, PyPI).

  2. 2

    Dual scan

    Two independent open-source scanners run against every server, every sync.

  3. 3

    Reconcile

    Agreements publish automatically. Scanner disagreements are flagged, never hidden.

  4. 4

    Human review

    The top 100 by adoption get a version-locked review on top of the automated pass.

  5. 5

    Publish

    A dated, versioned grade goes live — and gets re-checked on the very next sync.

Appendix A

Frequently asked questions

A.1 How do I know if an MCP server is safe to use?

Check its Safety, Freshness, Maintenance, and Provenance grades individually — never a single opaque score. aimcplist runs two independent open-source scanners against each server, reconciles disagreements, and human-reviews the top 100 by adoption before publishing a grade.

A.2 What percentage of MCP servers are vulnerable?

Independently measured audits put it high: 43% of tested servers show command-injection risk, 36.7% show SSRF exposure, and 41% of servers in the official registry run with zero authentication. See the Methodology page for full sourcing.

See the full research roundup

A.3 How do I audit an MCP server before installing it?

At minimum: check declared vs. actual permissions, confirm the package's provenance attestation matches its source repository, and verify the maintainer namespace. aimcplist runs this process for the top 500 servers by adoption so you don't have to do it by hand.

A.4 What is MCP tool poisoning?

An attack where a tool's name, description, or parameters carry hidden instructions aimed at the AI model reading them, not the human approving the tool — invisible in a rendered summary but processed as real instructions by the model. Related but distinct: a rug pull, where a tool turns malicious after approval rather than from the start. aimcplist hashes every tool definition and re-checks it on every sync to catch both.

Read the full explainer

A.5 Is it safe to install MCP servers from a general directory like mcp.so?

General directories index servers automatically without a safety review — useful for discovery, not for a safety judgment. Cross-check anything you find there against a graded listing here before installing, especially for servers with shell, file, or network access.

Not another server dump

General-purpose directories index tens of thousands of servers automatically. aimcplist covers 3618 well — four things at once, none of which a snapshot directory can offer:

01

Automated scanning

Two independent OSS scanners, every server, every sync.

02

Human-reviewed top tier

The top 100 by adoption get a version-locked human review.

03

Published false-positive rate

Measured and disclosed — not a marketing claim.

04

Longitudinal history

Answers “is this server getting worse?” — no snapshot directory can.

Maintainer channel

Maintain an MCP server?

Think a grade is wrong? Fixed a vulnerability? Verified maintainers can dispute a finding or trigger a re-scan after shipping a fix — no waiting for the next sync cycle.