MCP Security Index
Before you install an MCP server, see what it can do. AxioRank enumerates the tools each server declares (read-only, it never calls one) and grades the blast radius of what it can do: write, delete, execute, credential, and wildcard-scope capabilities. Scan a server not listed here.
Scan a server that is not listed
Scans a remote MCP server or agent card by URL. For a local stdio server, run npx @axiorank/mcpaudit.
28 servers in Productivity · 79 with flagged capabilities
- Atandem frumu-aiProductivity · 13 tools · no flagged capabilities
- AByteAsk-Embedded-MCP ByteAskProductivity · 3 tools · no flagged capabilities
- ABiel.ai TechDocsStudioProductivity · 1 tool · Tool input schema asks for a credential
- BApple Notes and Reminders dev-hitesh-guptaProductivity · 27 tools · Tool declares a high-privilege capability
- DNotion NotionProductivity · 24 tools · Tool declares a high-privilege capability
- FChronary ChronaryProductivity · 54 tools · Tool declares a high-privilege capability
- FMicrosoft 365 SofteriaProductivity · 188 tools · Tool declares a high-privilege capability
- –Linear LinearProductivity · scan pending
- –Atlassian (Jira & Confluence) AtlassianProductivity · scan pending
- –Google Drive Anthropic (MCP reference, archived)Productivity · scan pending
- –Gmail GongRzheProductivity · scan pending
- –Airtable domdomeggProductivity · scan pending
- –Obsidian MarkusPfundsteinProductivity · scan pending
- –Asana AsanaProductivity · scan pending
- –Canva CanvaProductivity · scan pending
- –Sanity SanityProductivity · scan pending
- –Google Calendar nspadyProductivity · scan pending
- –monday.com monday.comProductivity · scan pending
- –Todoist abhiz123Productivity · scan pending
- –ClickUp ClickUpProductivity · scan pending
- –Webflow WebflowProductivity · scan pending
- –Google Sheets xing5Productivity · scan pending
- –Trello delorenjProductivity · scan pending
- –cobbles Yu1586Productivity · scan pending
- –OneLore SolidKeyABProductivity · scan pending
- –Parallel Task MCP parallel-webProductivity · scan pending
- –plori plori-aiProductivity · scan pending
- –ponlo-ai ClaudioGodoyBProductivity · scan pending
How the grades work
A grade measures blast radius: how much a server could do if it were compromised or misinstructed, based on the capabilities it declares (write, delete, execute, credential access, wildcard scope). It is not a vulnerability assessment and not a judgment of the vendor. Lower is better: A is 0 to 19, up to F at 80 and above. The scan is read-only. It lists tools and never calls one.
Run a server? You can scan it yourself and embed your grade. See something off? Every server page links a re-scan.
Govern the MCP servers your agents use
AxioRank is the security gateway for AI agents: allowlist servers, block risky tool calls, and get an audit trail of every action.
Start free