polygraph.so

The MCP Security Index

Every grade we publish — MCP servers tested for behavior and ordered by adoption, Agent Skills scanned for safety. What each one does, not what its README claims.

107 MCP servers graded, ranked by adoption · 13 live endpoints (hosted, egress unverified) · 110 skills scanned · adoption data as of 2026-10-10. A grade is a measurement, not a guarantee; you can re-run the open harness yourself.

Run the harnessHosted grading is discontinued. Grade a server locally with the open harness.
Grade
120 servers
#ServerGradeChecksAdoption
1npm/@playwright/mcpA01✓02✓03✓04✓100/10032.1M npm/mo
2npm/@modelcontextprotocol/server-filesystemA01✓02✓03✓04✓87/1002.61M npm/mo
3npm/@modelcontextprotocol/server-everythingF01✓02✓03✕04✓82/1001.17M npm/mo
4npm/@modelcontextprotocol/server-memoryA01✓02✓03✓04✓82/100657K npm/mo
5npm/@upstash/context7-mcpA01✓02✓03✓04✓80/1003.31M npm/mo
6npm/firecrawl-mcpA01✓02✓03✓04✓79/100497K npm/mo
7npm/@modelcontextprotocol/server-sequential-thinkingA01✓02✓03✓04✓78/100541K npm/mo
8npm/@modelcontextprotocol/server-githubA01✓02✓03✓04✓76/100526K npm/mo
9npm/@notionhq/notion-mcp-serverA01✓02✓03✓04✓75/100807K npm/mo
10npm/n8n-mcpA01✓02✓03✓04✓74/100429K npm/mo
11npm/exa-mcp-serverA01✓02✓03✓04✓73/100243K npm/mo
12npm/@modelcontextprotocol/server-puppeteerA01✓02✓03✓04✓72/100139K npm/mo
13npm/@netlify/mcpA01✓02✓03✓04✓70/100165K npm/mo
14npm/tavily-mcpA01✓02✓03✓04✓68/10095.9K npm/mo
15npm/@21st-dev/magicA01✓02✓03✓04✓67/100123K npm/mo
16npm/open-websearchA01✓02✓03✓04✓67/10038.7K npm/mo
17npm/@coding-solo/godot-mcpA01✓02✓03✓04✓64/10025K npm/mo
18npm/mcp-server-kubernetesA01✓02✓03✓04✓63/10042.6K npm/mo
19npm/@negokaz/excel-mcp-serverA01✓02✓03✓04✓62/10041.9K npm/mo
20npm/@microsoft/clarity-mcp-serverA01✓02✓03✓04✓61/10039.4K npm/mo
Page 1 of 6

✓ pass✕ fail– not runC-01 tool-output injection · C-02 egress overreach · C-03 sensitive-data handling · C-04 adversarial-input handling

Ranked by the adoption score (0–100, shown at right above monthly downloads) — a composite of downloads (npm / PyPI), GitHub stars, dependents and release velocity. It measures reach, not safety: the litmus grade is the only safety verdict. Grades come from the open litmus harness; you can run it yourself for a server, or read the methodology.

Index data is published under CC BY 4.0: reuse it freely, with attribution to polygraph.so.