Which MCP servers are actually safe to install?
A safety-graded, freshness-verified shortlist — explicitly not another 20,000-server dump. Automated scanning, a human-reviewed top tier, and a published false-positive rate.
71%of audited servers scored an F — see the findingsFinding
71%1
of servers scored an F in an independent audit of 100 packages — zero scored an A.
Finding
41%2
of servers in the official MCP registry run with zero authentication.
Finding
43%3
of tested servers show a command-injection risk pattern.
- 1.Independent audit of 100 packages, 2026 — including reference implementations from Anthropic and Microsoft.
- 2.Large-scale scan of the official MCP registry, 2026.
- 3.Independent 2026 audit data.
Full methodology and citation index on the Methodology page.
Four dimensions, graded independently
Never a single opaque number. Every listing shows evidence for each finding, dated and sourced.
Chain of custody
How a grade gets published
Every server, every sync, no exceptions — not a one-time review that goes stale.
Designed, not live yet- 1
Sync
Nightly pull from the MCP registry and each server's own package registry (npm, PyPI).
- 2
Dual scan
Two independent open-source scanners run against every server, every sync.
- 3
Reconcile
Agreements publish automatically. Scanner disagreements are flagged, never hidden.
- 4
Human review
The top 100 by adoption get a version-locked review on top of the automated pass.
- 5
Publish
A dated, versioned grade goes live — and gets re-checked on the very next sync.
Appendix A
Frequently asked questions
A.1 How do I know if an MCP server is safe to use?
Check its Safety, Freshness, Maintenance, and Provenance grades individually — never a single opaque score. aimcplist runs two independent open-source scanners against each server, reconciles disagreements, and human-reviews the top 100 by adoption before publishing a grade.
A.2 What percentage of MCP servers are vulnerable?
Independently measured audits put it high: 43% of tested servers show command-injection risk, 36.7% show SSRF exposure, and 41% of servers in the official registry run with zero authentication. See the Methodology page for full sourcing.
See the full research roundupA.3 How do I audit an MCP server before installing it?
At minimum: check declared vs. actual permissions, confirm the package's provenance attestation matches its source repository, and verify the maintainer namespace. aimcplist runs this process for the top 500 servers by adoption so you don't have to do it by hand.
A.4 What is MCP tool poisoning?
An attack where a tool's name, description, or parameters carry hidden instructions aimed at the AI model reading them, not the human approving the tool — invisible in a rendered summary but processed as real instructions by the model. Related but distinct: a rug pull, where a tool turns malicious after approval rather than from the start. aimcplist hashes every tool definition and re-checks it on every sync to catch both.
Read the full explainerA.5 Is it safe to install MCP servers from a general directory like mcp.so?
General directories index servers automatically without a safety review — useful for discovery, not for a safety judgment. Cross-check anything you find there against a graded listing here before installing, especially for servers with shell, file, or network access.
Recently graded
Not another server dump
General-purpose directories index tens of thousands of servers automatically. aimcplist covers 3618 well — four things at once, none of which a snapshot directory can offer:
Automated scanning
Two independent OSS scanners, every server, every sync.
Human-reviewed top tier
The top 100 by adoption get a version-locked human review.
Published false-positive rate
Measured and disclosed — not a marketing claim.
Longitudinal history
Answers “is this server getting worse?” — no snapshot directory can.
