npm/@modelcontextprotocol/server-everything
graded version 2026.7.4 · litmus-v16 · 2026-07-15
Adoption 76/100 · 244K npm/mo · as of 2026-07-21
npm/@modelcontextprotocol/server-everything is graded F by polygraph under litmus-v16, as of 2026-07-15. The grade is a dated, reproducible observation of behavior, not a guarantee.
Graded under litmus-v16; the current methodology is litmus-v17. A re-run may change the grade.
Self-reported “MCP server that exercises all the features of the MCP protocol” — the package’s own registry description, not part of the grade.
- C-01 Tool-output injection
- pass
- C-02 Permission / egress overreach
- pass
- C-03 Sensitive-data handling
- fail
- C-04 Adversarial-input handling
- pass
tool-defs fingerprint · 0xde448d…7993f
Why F: Disqualifying failure in C-03 — active injection or data leak harms an agent that trusts this server.
Guided remediation — the specific changes that clear this grade. Shipped a fix? Request a re-grade — the harness re-runs against the new version.
Watch for new-version regrades
This grade is a snapshot of 2026.7.4. Get an email when npm/@modelcontextprotocol/server-everything ships a new version and polygraph re-runs the litmus on it — one message per new version, one-click unsubscribe.
Monitor this serverAdoption signals
The 76 / 100 adoption score blends the raw signals below — downloads, stars, dependents and release velocity — normalized across every tracked server. It measures reach, not safety; the litmus grade is the safety verdict. See the methodology.
- npm downloads (30d)
- 243,541
- GitHub stars
- 88,691
- Forks
- 11,262
- Contributors
- 426
- Dependents (deps.dev)
- 5
- Last published
- 2026-07-04
Reproduce this grade
The harness is open and deterministic. Re-run it against the same server and compare the grade and fingerprint — a false grade is falsifiable, not merely disputable.
npx -p @polygraphso/litmus polygraphso-litmus npm/@modelcontextprotocol/server-everythingEmbed this badge
Drop it in a README, docs site, or package page. It always shows the current published grade and links back here.
[](https://www.polygraph.so/mcp/npm/@modelcontextprotocol/server-everything)<a href="https://www.polygraph.so/mcp/npm/@modelcontextprotocol/server-everything"><img src="https://www.polygraph.so/api/badge?server=npm/@modelcontextprotocol/server-everything" alt="polygraph grade"></a>[](https://www.polygraph.so/mcp/npm/@modelcontextprotocol/server-everything)Questions
- What does polygraph's F grade mean for npm/@modelcontextprotocol/server-everything?
- It’s a behavioral grade on an A–F scale. polygraph connected to npm/@modelcontextprotocol/server-everything the way an agent would, exercised its tools, and watched what it did — whether it tried to hijack the caller, send data off-box, leak planted secrets, or mishandle adversarial input. F is where that evidence placed it. It describes behavior on the day it ran, not a guarantee.
- What did polygraph test?
- Four probe categories, run against the live server in a sandbox: C-01 tool-output injection, C-02 permission and egress overreach, C-03 sensitive-data handling, and C-04 adversarial-input handling. The full battery is in the methodology.
- How do I reproduce this grade?
- Run
npx -p @polygraphso/litmus polygraphso-litmus npm/@modelcontextprotocol/server-everything. The harness is open and deterministic, so anyone can re-run it against the same server and disprove a false grade — reproducibility is what the grade rests on. - Can a server pay polygraph for a better grade?
- No. Independence is disclosure-based: material support must be publicly registered, and no graded party gets review or approval rights over its letter. The grade is set by the evidence, not the relationship.