MCP Security Index
Weekly, independent, read-only security scans of well-known public MCP servers. Letter grades only — findings are visible in each report, exploit details never published. Updated ….
Methodology: the same free scanner anyone can run — protocol, transport, auth, tool-hygiene and disclosure checks mapped to the MCP specification, NSA/CISA MCP guidance (June 2026) and OWASP. Read-only: no tool is ever executed. Vendors: fix and re-scan any time — the index refreshes weekly. Contact
support@codeflowops.com.