MCP Observatory

Independent safety audit of the MCP server ecosystem · by PulseFeed

Thousands of MCP servers ship with almost no vetting — and a bad one can run arbitrary code on your machine or exfiltrate data. Before you connect your AI agent to an MCP server, check it. We audit maintenance, install-script risk, provenance, abandonment and liveness.

4360servers audited
3708safe
257caution
390avoid

Verdicts

safe
3708
caution
257
avoid
390
unknown
5

npm servers get deep signals; remote servers get liveness + HTTPS only (can't fully verify a black-box remote).

Top safety flags

downloads_unknown
1796
no_repo
479
install_script
379
unpopular
146
abandoned
142
no_license
68
heavy_deps
28
unreachable
11

install_script = arbitrary code on npm i; abandoned = stale; unreachable = dead remote.

Top trusted MCP servers

ServerTypenpm dl/wkTrust
@modelcontextprotocol/sdknpm40,131,965100
ainpm18,077,596100
@ai-sdk/mcpnpm2,807,887100
@storybook/mcpnpm1,596,608100
@storybook/addon-mcpnpm1,463,451100
mcporternpm422,750100
@assistant-ui/reactnpm1,319,267100
mcp-handlernpm736,707100
@copilotkit/aimocknpm1,201,032100
fallownpm820,628100
mcp-remotenpm778,299100
@langchain/mcp-adaptersnpm200,676100
add-mcpnpm101,915100
evenpm668,693100
@modelcontextprotocol/servernpm4,209,166100
Check any MCP server: GET /mcp/verify?package=<npm-name> — free. Returns a safety verdict, score and flags (install scripts, abandonment, provenance, license, repo).
📊 Read the State of MCP Security report — how much of the ecosystem runs arbitrary code on install, updated daily. Building on MCP and want an API + CI check? Get early access →

Methodology: PulseFeed discovers servers from the official MCP registry, audits each via npm metadata (install scripts, provenance, license, downloads, freshness) and liveness for remotes. Same independent-audit approach as our x402 trust oracle. Machine-readable: /mcp.json. Updated daily.