MCP Security Index
Before you install an MCP server, see what it can do. AxioRank enumerates the tools each server declares (read-only, it never calls one) and grades the blast radius of what it can do: write, delete, execute, credential, and wildcard-scope capabilities. Scan a server not listed here.
Scan a server that is not listed
Scans a remote MCP server or agent card by URL. For a local stdio server, run npx @axiorank/mcpaudit.
138 servers in Reference · 79 with flagged capabilities
- ASequential Thinking Anthropic (MCP reference)Reference · 1 tool · no flagged capabilities
- ATime Anthropic (MCP reference)Reference · 2 tools · no flagged capabilities
- AEverything (reference test server) Anthropic (MCP reference)Reference · 13 tools · no flagged capabilities
- AAWS Documentation (AWS Labs) AWS (awslabs)Reference · 5 tools · no flagged capabilities
- AWikipedia rudra-raviReference · 22 tools · no flagged capabilities
- AarXiv blazickjpReference · 14 tools · no flagged capabilities
- AMicrosoft Learn MicrosoftReference · 3 tools · no flagged capabilities
- ANASA ProgramComputerReference · 23 tools · no flagged capabilities
- AWeather TimLukaHorstmannReference · 2 tools · no flagged capabilities
- AABMeter abmeterReference · 0 tools · no flagged capabilities
- Aaviado-mcp kipmccReference · 9 tools · no flagged capabilities
- AInferventis MCP Server Bankee-aiReference · 20 tools · no flagged capabilities
- ABowmark MetroxeReference · 3 tools · no flagged capabilities
- Acanaryusers-mcp BrettonBReference · 3 tools · no flagged capabilities
- ACertScore MCP ergoveritas1-altReference · 11 tools · no flagged capabilities
- AMCP Registry Server modelcontextprotocolReference · 3 tools · no flagged capabilities
- AHAPI Strava MCP Server la-rebelionReference · 13 tools · no flagged capabilities
- Acreationloop-mcp marino129Reference · 4 tools · no flagged capabilities
- ADrillr, The financial MCP for AI agents Little-Grebe-IncReference · 9 tools · no flagged capabilities
- Adsght-landing michalstrnadelReference · 10 tools · no flagged capabilities
- Adocconvert filegraphReference · 9 tools · no flagged capabilities
- Agethal.ai acf5914932Reference · 7 tools · no flagged capabilities
- Aai-dossier imboard-aiReference · 10 tools · no flagged capabilities
- Ajedaai-lite ai-dev-dojoitReference · 5 tools · no flagged capabilities
- Ajoinmultiplayer.ai yukakustReference · 3 tools · no flagged capabilities
- ALicensy licensyaiReference · 9 tools · no flagged capabilities
- AMLP Tax Computation Engine luc253Reference · 6 tools · no flagged capabilities
- Amrmarket.ai codinghavenReference · 9 tools · no flagged capabilities
- ANinar AI Ninar-ctrlReference · 5 tools · no flagged capabilities
- Anocturnusai AuctalisReference · 0 tools · no flagged capabilities
- APreClick, An MCP-native URL preflight scanning service for autonomous agents. cybrlab-aiReference · 6 tools · no flagged capabilities
- AProxygate proxygate-officialReference · 7 tools · no flagged capabilities
- APubFi MCP helixboxReference · 3 tools · no flagged capabilities
- AReadyPermit, Property Zoning & Buildability Intelligence Galax-aiReference · 8 tools · no flagged capabilities
- ARiskState, Crypto Risk Engine likidodefiReference · 3 tools · no flagged capabilities
- Aagentberg AgentbergReference · 11 tools · Tool declares a high-privilege capability
- Aautonomad1 Autonomad1Reference · 8 tools · Tool declares a high-privilege capability
- Ablast-radius-live kipmccReference · 7 tools · Tool declares a high-privilege capability
- Abolthub signaltech-orgReference · 6 tools · Tool input schema asks for a credential
- Acallmcp CallMCPReference · 14 tools · Tool declares a high-privilege capability
- ALenny Rachitsky Podcast Transcripts MCP Server la-rebelionReference · 8 tools · Tool declares a high-privilege capability
- ALinkedIn MCP Server la-rebelionReference · 3 tools · Tool declares a high-privilege capability
- Agondola_api gondola-aiReference · 28 tools · Tool declares a high-privilege capability
- Areddit-insight archoorReference · 7 tools · Tool declares a high-privilege capability
- Badeu dealfluenceReference · 9 tools · Tool input schema asks for a credential
- Bcomputeback-mcp Autonomad1Reference · 28 tools · Tool declares a high-privilege capability
- BProofSlip Johnny-Z13Reference · 4 tools · Tool input schema asks for a credential
- BNefesh, Real-time Human State Awareness tomstuhlReference · 6 tools · Tool input schema asks for a credential
- Bnullary vzhigulinReference · 35 tools · Tool declares a high-privilege capability
- BDreamlit dreamlit-aiReference · 11 tools · Tool declares a high-privilege capability
- Bmarketintell ravidsrkReference · 17 tools · Tool input schema asks for a credential
- Bplith chicogonzalesReference · 15 tools · Tool input schema asks for a credential
- Bpresentations-ai-mcp-server slidecraft-inReference · 5 tools · Tool declares a high-privilege capability
- CODEI Zer0H1roReference · 7 tools · Tool input schema asks for a credential
- Cpig-gateway pictomancer.aiReference · 9 tools · Tool declares a high-privilege capability
- CSemantic Scholar hy20191108Reference · 33 tools · Tool declares a high-privilege capability
- CAutEng Document Publisher autengReference · 7 tools · Tool declares a high-privilege capability
- CCompeller yakoobReference · 30 tools · Tool declares a high-privilege capability
- DOpenAI Tools MCP Server la-rebelionReference · 9 tools · Tool declares a high-privilege capability
- DForkMate shawnazarReference · 12 tools · Tool declares a high-privilege capability
- DLudo AI Game Assets Ludo-AIReference · 32 tools · Tool declares a high-privilege capability
- DRetro Diffusion Pixel Art Retro-DiffusionReference · 20 tools · Tool declares a high-privilege capability
- DSpotify calebWeiReference · 47 tools · Tool declares a high-privilege capability
- DLithtrix, Identity, Memory & Trust for AI Agents lithtrixReference · 43 tools · Tool declares a high-privilege capability
- DPetstore MCP Server la-rebelionReference · 19 tools · Tool declares a high-privilege capability
- FRaven rhinocapReference · 27 tools · Tool declares a high-privilege capability
- FContabo (VPS) MCP Server la-rebelionReference · 124 tools · Tool declares a high-privilege capability
- –Google Maps Anthropic (MCP reference, archived)Reference · scan pending
- –YouTube ZubeidHendricksReference · scan pending
- –PubMed andybrandtReference · scan pending
- –lona mindsightventuresReference · scan pending
- –AgentDM: Agent to Agent Communication Platform agentdmaiReference · scan pending
- –AgentTrust, Identity & Trust for A2A Agents agenttrustReference · scan pending
- –Ambix ambix-aiReference · scan pending
- –Anki MCP Server ankimcpReference · scan pending
- –AnomalyArmor anomalyarmorReference · scan pending
- –ARPI MCP arpi-aiReference · scan pending
- –ctxl autoblocksaiReference · scan pending
- –ctxl autoblocksaiReference · scan pending
- –ctxl autoblocksaiReference · scan pending
- –auxen-mcp Samp2AlexReference · scan pending
- –Bareun, Korean NLP & Spell/Grammar Checking gih2yunReference · scan pending
- –basethread-mcp navbuildzReference · scan pending
- –BidDeed MCP breverdbidderReference · scan pending
- –bolthub Marketplace signaltech-orgReference · scan pending
- –Boolsai Directory Boolsai-aiReference · scan pending
- –Boolsai Grep Boolsai-aiReference · scan pending
- –Boolsai Scan Boolsai-aiReference · scan pending
- –Boolsai Signals Boolsai-aiReference · scan pending
- –China Marketing AI Intelligence MCP REPLACE_WITH_ORGReference · scan pending
- –circulara-core CircularRouteReference · scan pending
- –Cirra AI Salesforce Admin MCP Server cirra-aiReference · scan pending
- –Clarid Compliance clarid-aiReference · scan pending
- –Clarid HMDA Validator clarid-aiReference · scan pending
- –Cofound cofound-agentReference · scan pending
- –HAPI MCP Server larebelionReference · scan pending
- –Cookiy cookiy-aiReference · scan pending
- –Cosmonote cosmonoteReference · scan pending
- –cueapi-mcp cueapiReference · scan pending
- –DiagramZu yenchiehReference · scan pending
- –Apprise RMCP jmagarReference · scan pending
- –Gotify RMCP jmagarReference · scan pending
- –Soma jmagarReference · scan pending
- –Tailscale RMCP jmagarReference · scan pending
- –UniFi RMCP jmagarReference · scan pending
- –Yarr MCP jmagarReference · scan pending
- –TVWizard fizzious1Reference · scan pending
- –mcp-explorium explorium-aiReference · scan pending
- –Fodda Knowledge Graphs foddaReference · scan pending
- –Gemus Gemus-AIReference · scan pending
- –Perspective AI Perspective-AIReference · scan pending
- –Helixar Security Helixar-AIReference · scan pending
- –i18n-agent i18n-agentReference · scan pending
- –inflow inflowpayReference · scan pending
- –klavis Klavis-AIReference · scan pending
- –Kumbuka kumbuka-aiReference · scan pending
- –Lattiq x402 Trading Signals PoopsDavisReference · scan pending
- –LimitGuard Trust Intelligence JWconsultancy1234Reference · scan pending
- –Magic Insights andrewchmrReference · scan pending
- –MailJunky TheNightProjectReference · scan pending
- –marchward marchwardReference · scan pending
- –Marcora ccrompReference · scan pending
- –MarketTrace agent-feed MarketTraceReference · scan pending
- –Modulos Demo Booking ModulosReference · scan pending
- –monnet-mcp GregoireCasoettoReference · scan pending
- –nudg3-mcp NUDG3-AIReference · scan pending
- –Obris obris-devReference · scan pending
- –OrgGen AI ms-spownReference · scan pending
- –Outlit OutlitAIReference · scan pending
- –Outset Outset-AIReference · scan pending
- –packmind PackmindHubReference · scan pending
- –Liminality jaybro2042-altReference · scan pending
- –Primeta Primeta-AIReference · scan pending
- –pullpush-mcp Kaduno-systemsReference · scan pending
- –raisonnai raisonnaiReference · scan pending
- –RedditGrow Vico86Reference · scan pending
- –rail-score-mcp Responsible-AI-LabsReference · scan pending
- –ScamVerify Threat Verification scamverifyaiReference · scan pending
How the grades work
A grade measures blast radius: how much a server could do if it were compromised or misinstructed, based on the capabilities it declares (write, delete, execute, credential access, wildcard scope). It is not a vulnerability assessment and not a judgment of the vendor. Lower is better: A is 0 to 19, up to F at 80 and above. The scan is read-only. It lists tools and never calls one.
Run a server? You can scan it yourself and embed your grade. See something off? Every server page links a re-scan.
Govern the MCP servers your agents use
AxioRank is the security gateway for AI agents: allowlist servers, block risky tool calls, and get an audit trail of every action.
Start free