State of MCP Security · 2026-09-07

Snapshot of the MCP server ecosystem as of 2026-09-07 · by PulseFeed · see the live report →

3545▲246
servers audited
2924▲215
safe to install
355▲12
avoid (10%)

Headline: how many run code the moment you install them?

10%▲12

344 of 3545 MCP servers ship an install/postinstall script — arbitrary code runs on your machine at npm i, before you've even used the tool. Some are legitimate native builds, but each is an unreviewed code-execution vector — and 390 of all audited servers publish no repository to inspect at all. A bad MCP server can read your files, env vars and keys the moment it's connected.

Install-script exposure over time

344 80 344 07-0808-0709-07

Verdicts

safe
2924
caution
261
avoid
355
unknown
5

npm servers get deep signals; remote servers get liveness + HTTPS only.

Top safety flags

Servers to avoid (sample)

ServerVerdictFlags
ai.agenticshelf/graffeoavoidunreachable
ai.agenticshelf/mcpavoidunreachable
ai.agenticshelf/puroairavoidunreachable
ai.alpic.test/test-mcp-serveravoidunreachable
ai.autorfp/mcpavoidunreachable
ai.baselight/baselightavoidunreachable
ai.buyersense/buyersenseavoidunreachable
ai.clarid/complianceavoidunreachable
ai.com.mcp/hapi-mcpavoidunreachable
ai.com.mcp/skills-searchavoidunreachable
ai.dynamicfeed/dynamic-feedavoidunreachable
agentdbavoidinstall_script

Daily archive

DateAuditedInstall-scriptAvoidAbandoned
2026-09-073545344355128
2026-09-063538343354128
2026-09-053534344355127
2026-09-043517344355127
2026-09-033490342353124
2026-09-023456340351124
2026-09-013350333344122
2026-08-313299332343122
2026-08-303272330341121
2026-08-293256330341121
2026-08-283244330341121
2026-08-273211323334119
2026-08-263146318329119
2026-08-253083316327119

Methodology: PulseFeed discovers MCP servers from the official MCP registry and npm, then audits each independently — install/postinstall scripts (code execution on install), abandonment, provenance, license, repository, download volume, and liveness for remote servers. Verdict = safe / caution / avoid. This report is generated automatically from that data and updates daily. Install scripts are not inherently malicious (native builds use them) but every one is an unreviewed code-execution vector worth checking. Same independent-audit approach as our x402 trust oracle.
Check any server free: GET /mcp/verify?package=<npm-name> · Machine-readable: /mcp-report.json · Live observatory: /mcp · /llms.txt