polygraph.so

The MCP Security Index

Every grade we publish — MCP servers tested for behavior and ordered by adoption, Agent Skills scanned for safety. What each one does, not what its README claims.

107 MCP servers graded, ranked by adoption · 13 live endpoints (hosted, egress unverified) · 110 skills scanned · adoption data as of 2026-08-26. A grade is a measurement, not a guarantee; you can re-run the open harness yourself.

Request a gradeNot up yet? Add it to the bench — free, and we email you when it publishes.
Grade
120 servers
#ServerGradeChecksAdoption
1npm/@playwright/mcpA01020304100/10024.6M npm/mo
2npm/@modelcontextprotocol/server-filesystemA0102030489/1002.09M npm/mo
3npm/@modelcontextprotocol/server-everythingF0102030486/100652K npm/mo
4npm/@upstash/context7-mcpA0102030486/1004.1M npm/mo
5npm/firecrawl-mcpA0102030480/100492K npm/mo
6npm/n8n-mcpA0102030480/100642K npm/mo
7npm/@modelcontextprotocol/server-sequential-thinkingA0102030479/100508K npm/mo
8npm/@modelcontextprotocol/server-memoryA0102030478/100375K npm/mo
9npm/@modelcontextprotocol/server-githubA0102030478/100510K npm/mo
10npm/@notionhq/notion-mcp-serverA0102030477/100746K npm/mo
11npm/@21st-dev/magicA0102030474/100188K npm/mo
12npm/exa-mcp-serverA0102030474/100115K npm/mo
13npm/@modelcontextprotocol/server-puppeteerA0102030471/100109K npm/mo
14npm/tavily-mcpA0102030470/100122K npm/mo
15npm/@netlify/mcpA0102030467/10067.1K npm/mo
16npm/@negokaz/excel-mcp-serverA0102030467/10060K npm/mo
17npm/mcp-server-kubernetesA0102030466/10063.8K npm/mo
18pypi/mcp-server-timeA0102030463/100830K pypi/mo
19npm/open-websearchA0102030462/10017.5K npm/mo
20npm/@browserbasehq/mcpA0102030461/10020.7K npm/mo
Page 1 of 6

pass fail not runC-01 tool-output injection · C-02 egress overreach · C-03 sensitive-data handling · C-04 adversarial-input handling

Ranked by the adoption score (0–100, shown at right above monthly downloads) — a composite of downloads (npm / PyPI), GitHub stars, dependents and release velocity. It measures reach, not safety: the litmus grade is the only safety verdict. Grades come from the open litmus harness; you can request a grade for a server, or read the methodology.

Index data is published under CC BY 4.0: reuse it freely, with attribution to polygraph.so.