Is it safe to install MCP servers?

LAST UPDATED 2026-08-10

Not automatically, and not never — it depends entirely on the specific server. Independent audits have found the majority of tested MCP servers carry real, unaddressed vulnerabilities (command injection, path traversal, SSRF), so installing one without checking it first is a real risk. A server that's actually been audited, kept current, and reviewed by a human is a different proposition than an unmaintained one nobody has looked at — the risk lives in the specific server, not in MCP as a category.

How aimcplist grades safety

Four independently scored dimensions, evidence for every finding, a published false-positive rate.

Read the methodology

Known MCP vulnerabilities

A dated, sourced index of publicly disclosed CVEs affecting MCP servers and tooling.

See the CVE index

How the real attacks work

Tool poisoning, rug pulls, SSRF, abandonment — what each attack actually looks like and how to check for it yourself.

Browse concept explainers

Where else to look

How aimcplist compares to Glama, mcp.so, and PulseMCP — and what none of them currently publish.

Compare MCP directories

The specific things to check yourself

Reading the full raw tool definitions (not your client's shortened summary), matching declared capability against actual capability, checking for a real provenance attestation, and checking freshness signals before trusting an old review — the full checklist is on its own page.

Read the full checklist