MCP Security Index
Before you install an MCP server, see what it can do. AxioRank enumerates the tools each server declares (read-only, it never calls one) and grades the blast radius of what it can do: write, delete, execute, credential, and wildcard-scope capabilities. Scan a server not listed here.
Scan a server that is not listed
Scans a remote MCP server or agent card by URL. For a local stdio server, run npx @axiorank/mcpaudit.
44 servers in Dev tools · 79 with flagged capabilities
- APuppeteer Anthropic (MCP reference, archived)Dev tools · 7 tools · no flagged capabilities
- AE2B Code Interpreter E2BDev tools · 1 tool · no flagged capabilities
- AContext7 UpstashDev tools · 2 tools · no flagged capabilities
- AJetBrains IDEs JetBrainsDev tools · 0 tools · no flagged capabilities
- AMarkItDown MicrosoftDev tools · 1 tool · no flagged capabilities
- An8n czlonkowskiDev tools · 7 tools · no flagged capabilities
- ACircleCI CircleCIDev tools · 13 tools · no flagged capabilities
- A21st.dev Magic 21st.devDev tools · 4 tools · no flagged capabilities
- Aclarx-cloud Gernika-LabsDev tools · 3 tools · no flagged capabilities
- Axmp4, Semantic Code Intelligence 0ics-srlsDev tools · 16 tools · no flagged capabilities
- AGit Anthropic (MCP reference)Dev tools · 12 tools · Tool declares a high-privilege capability
- ASnyk SnykDev tools · 13 tools · Tool declares a high-privilege capability
- BFilesystem Anthropic (MCP reference)Dev tools · 14 tools · Tool declares a high-privilege capability
- BKawa Code MCP codeawarenessDev tools · 17 tools · Tool input schema asks for a credential
- CPlaywright MicrosoftDev tools · 24 tools · Tool declares a high-privilege capability
- DGrafana Grafana LabsDev tools · 65 tools · Tool declares a high-privilege capability
- DKubernetes Flux159Dev tools · 23 tools · Tool declares a high-privilege capability
- –GitHub GitHubDev tools · scan pending
- –Sentry SentryDev tools · scan pending
- –Browserbase BrowserbaseDev tools · scan pending
- –Apify Actors ApifyDev tools · scan pending
- –Figma Context (community) GLipsDev tools · scan pending
- –Docker MCP Gateway DockerDev tools · scan pending
- –Zapier ZapierDev tools · scan pending
- –GitLab Anthropic (MCP reference, archived)Dev tools · scan pending
- –ElevenLabs ElevenLabsDev tools · scan pending
- –Datadog GeLi2001Dev tools · scan pending
- –Azure DevOps MicrosoftDev tools · scan pending
- –Cloudflare Browser Rendering CloudflareDev tools · scan pending
- –New Relic New RelicDev tools · scan pending
- –SonarQube SonarSourceDev tools · scan pending
- –Cloudflare AI Gateway CloudflareDev tools · scan pending
- –Dynatrace DynatraceDev tools · scan pending
- –Postman PostmanDev tools · scan pending
- –Semgrep SemgrepDev tools · scan pending
- –Prometheus pab1it0Dev tools · scan pending
- –DeepL DeepLDev tools · scan pending
- –PagerDuty PagerDutyDev tools · scan pending
- –Axiom AxiomDev tools · scan pending
- –Weights and Biases Weights & BiasesDev tools · scan pending
- –Replicate deepfatesDev tools · scan pending
- –glimt hafDev tools · scan pending
- –Squad the-basilisk-aiDev tools · scan pending
- –Paper Lantern paperlantern-aiDev tools · scan pending
How the grades work
A grade measures blast radius: how much a server could do if it were compromised or misinstructed, based on the capabilities it declares (write, delete, execute, credential access, wildcard scope). It is not a vulnerability assessment and not a judgment of the vendor. Lower is better: A is 0 to 19, up to F at 80 and above. The scan is read-only. It lists tools and never calls one.
Run a server? You can scan it yourself and embed your grade. See something off? Every server page links a re-scan.
Govern the MCP servers your agents use
AxioRank is the security gateway for AI agents: allowlist servers, block risky tool calls, and get an audit trail of every action.
Start free