MCP Security Index

Weekly, independent, read-only security scans of well-known public MCP servers. Letter grades only — findings are visible in each report, exploit details never published. Updated .

ServerGradeScoreTools visibleReport
Loading…
Methodology: the same free scanner anyone can run — protocol, transport, auth, tool-hygiene and disclosure checks mapped to the MCP specification, NSA/CISA MCP guidance (June 2026) and OWASP. Read-only: no tool is ever executed. Vendors: fix and re-scan any time — the index refreshes weekly. Contact support@codeflowops.com.
Scan your own MCP server →