aimcplist
ServersMethodologyBlogClaim your server
Browse graded servers

Learn

MCP security concepts

Reference explainers on the attack patterns aimcplist grades for — what they are, how they actually happen, and how to check for them yourself.

What is MCP tool poisoning?

A tool's own description can carry instructions a user never sees — and an AI model reads it anyway.

Read more

What is an MCP rug pull attack?

The tool you approved isn't always the tool you're still running.

Read more

Are MCP servers vulnerable to SSRF?

A tool that fetches a URL on your behalf can be tricked into fetching the wrong one.

Read more

How do I know if an MCP server is abandoned?

A server that still installs fine can still be running code nobody's maintaining anymore.

Read more

MCP server security checklist

The specific things to actually check before you let a model call an MCP server's tools.

Read more

How do I vet MCP servers for enterprise use?

The individual-developer checklist isn't enough once a tool is running against production systems and real customer data.

Read more
aimcplist

A safety-graded, freshness-verified shortlist of MCP servers — not another server dump.

Resources

BlogResearchLearn

Legal & trust

MethodologyVulnerability Disclosure PolicyDispute ProcessTermsPrivacy
Grades are generated by a versioned, published methodology — see the Methodology page for the current ruleset version and measured false-positive rate.