MCP Security Index
Before you install an MCP server, see what it can do. AxioRank enumerates the tools each server declares (read-only, it never calls one) and grades the blast radius of what it can do: write, delete, execute, credential, and wildcard-scope capabilities. Scan a server not listed here.
Scan a server that is not listed
Scans a remote MCP server or agent card by URL. For a local stdio server, run npx @axiorank/mcpaudit.
21 servers in Commerce · 79 with flagged capabilities
- ASquare Square (Block)Commerce · 3 tools · no flagged capabilities
- AShopify Dev ShopifyCommerce · 5 tools · no flagged capabilities
- ACoinGecko CoinGeckoCommerce · 2 tools · no flagged capabilities
- APolygon.io Polygon.ioCommerce · 53 tools · no flagged capabilities
- Aheadless-commerce alex-hoyeol-choiCommerce · 8 tools · no flagged capabilities
- ANexez Agentic Commerce Flyger1anCommerce · 5 tools · no flagged capabilities
- APyrimid Protocol pyrimid-aiCommerce · 7 tools · no flagged capabilities
- AAgentic Shelf vboykoCTOCommerce · 7 tools · Tool declares a high-privilege capability
- ARa Pay Ra-Pay-AICommerce · 7 tools · Tool declares a high-privilege capability
- ALa Luer, AI Skincare Commerce nathangrotticelliCommerce · 14 tools · Tool declares a high-privilege capability
- CAlchemy AlchemyCommerce · 97 tools · Tool input schema asks for a credential
- –Stripe StripeCommerce · scan pending
- –PayPal PayPalCommerce · scan pending
- –Plaid PlaidCommerce · scan pending
- –Coinbase Payments CoinbaseCommerce · scan pending
- –Alpaca AlpacaCommerce · scan pending
- –Mercado Pago Mercado LibreCommerce · scan pending
- –Xero XeroCommerce · scan pending
- –Ramp RampCommerce · scan pending
- –inxy-mcp riverliu8Commerce · scan pending
- –ModelRunner modelrunnerCommerce · scan pending
How the grades work
A grade measures blast radius: how much a server could do if it were compromised or misinstructed, based on the capabilities it declares (write, delete, execute, credential access, wildcard scope). It is not a vulnerability assessment and not a judgment of the vendor. Lower is better: A is 0 to 19, up to F at 80 and above. The scan is read-only. It lists tools and never calls one.
Run a server? You can scan it yourself and embed your grade. See something off? Every server page links a re-scan.
Govern the MCP servers your agents use
AxioRank is the security gateway for AI agents: allowlist servers, block risky tool calls, and get an audit trail of every action.
Start free