MCP Security Index
Before you install an MCP server, see what it can do. AxioRank enumerates the tools each server declares (read-only, it never calls one) and grades the blast radius of what it can do: write, delete, execute, credential, and wildcard-scope capabilities. Scan a server not listed here.
Scan a server that is not listed
Scans a remote MCP server or agent card by URL. For a local stdio server, run npx @axiorank/mcpaudit.
32 servers in Data · 79 with flagged capabilities
- AQdrant QdrantData · 2 tools · no flagged capabilities
- AHugging Face Hugging FaceData · 4 tools · no flagged capabilities
- AAmazon Redshift AWS LabsData · 7 tools · no flagged capabilities
- AMySQL (benborla) Ben BorlaData · 0 tools · no flagged capabilities
- AMicrosoft Clarity MicrosoftData · 3 tools · no flagged capabilities
- ACouchbase CouchbaseData · 21 tools · no flagged capabilities
- AClickHouse ClickHouseData · 3 tools · Tool input schema asks for a credential
- APinecone Developer PineconeData · 9 tools · Tool declares a high-privilege capability
- AAmazon DynamoDB AWS LabsData · 8 tools · Tool input schema asks for a credential
- ANeo4j Cypher Neo4j LabsData · 3 tools · Tool declares a high-privilege capability
- AAmazon Aurora PostgreSQL AWS LabsData · 7 tools · Tool declares a high-privilege capability
- BSQLite Model Context ProtocolData · 6 tools · Tool declares a high-privilege capability
- Bmcp-analytics embeddedlayersData · 17 tools · Tool declares a high-privilege capability
- CSupabase SupabaseData · 29 tools · Tool declares a high-privilege capability
- CTiDB PingCAPData · 7 tools · Tool declares a high-privilege capability
- DChroma ChromaData · 13 tools · Tool declares a high-privilege capability
- DRedis RedisData · 53 tools · Tool declares a high-privilege capability
- DMemory (Knowledge Graph) Anthropic (MCP reference)Data · 9 tools · Tool declares a high-privilege capability
- FMongoDB MongoDBData · 25 tools · Tool declares a high-privilege capability
- –PostgreSQL Anthropic (MCP reference, archived)Data · scan pending
- –Neon NeonData · scan pending
- –Elasticsearch ElasticData · scan pending
- –Snowflake Snowflake LabsData · scan pending
- –Prisma Postgres PrismaData · scan pending
- –MotherDuck and DuckDB MotherDuckData · scan pending
- –Google BigQuery ergutData · scan pending
- –Cloudflare GraphQL Analytics CloudflareData · scan pending
- –AutoRFP.ai AutoRFPData · scan pending
- –Kubit Kubit-AIData · scan pending
- –matih-mcp matih-labsData · scan pending
- –rolli-mcp rolliincData · scan pending
- –omni-datastream autonomous-computerData · scan pending
How the grades work
A grade measures blast radius: how much a server could do if it were compromised or misinstructed, based on the capabilities it declares (write, delete, execute, credential access, wildcard scope). It is not a vulnerability assessment and not a judgment of the vendor. Lower is better: A is 0 to 19, up to F at 80 and above. The scan is read-only. It lists tools and never calls one.
Run a server? You can scan it yourself and embed your grade. See something off? Every server page links a re-scan.
Govern the MCP servers your agents use
AxioRank is the security gateway for AI agents: allowlist servers, block risky tool calls, and get an audit trail of every action.
Start free