MCP Observatory

Independent safety audit of the MCP server ecosystem · by PulseFeed

Thousands of MCP servers ship with almost no vetting — and a bad one can run arbitrary code on your machine or exfiltrate data. Before you connect your AI agent to an MCP server, check it. We audit maintenance, install-script risk, provenance, abandonment and liveness.

4814servers audited
4131safe
261caution
417avoid

Verdicts

safe
4131
caution
261
avoid
417
unknown
5

npm servers get deep signals; remote servers get liveness + HTTPS only (can't fully verify a black-box remote).

Top safety flags

downloads_unknown
1994
no_repo
523
install_script
406
unpopular
153
abandoned
150
no_license
76
heavy_deps
31
unreachable
11

install_script = arbitrary code on npm i; abandoned = stale; unreachable = dead remote.

Top trusted MCP servers

ServerTypenpm dl/wkTrust
@modelcontextprotocol/sdknpm74,981,440100
ainpm34,162,045100
@ai-sdk/mcpnpm5,569,610100
@storybook/mcpnpm2,709,647100
@storybook/addon-mcpnpm2,854,283100
mcporternpm454,576100
@assistant-ui/reactnpm2,351,184100
mcp-handlernpm1,473,697100
@copilotkit/aimocknpm675,944100
fallownpm1,691,728100
mcp-remotenpm716,048100
@langchain/mcp-adaptersnpm323,425100
add-mcpnpm219,983100
evenpm1,358,143100
@modelcontextprotocol/servernpm10,001,814100
Check any MCP server: GET /mcp/verify?package=<npm-name> — free. Returns a safety verdict, score and flags (install scripts, abandonment, provenance, license, repo).
📊 Read the State of MCP Security report — how much of the ecosystem runs arbitrary code on install, updated daily. Building on MCP and want an API + CI check? Get early access →

Methodology: PulseFeed discovers servers from the official MCP registry, audits each via npm metadata (install scripts, provenance, license, downloads, freshness) and liveness for remotes. Same independent-audit approach as our x402 trust oracle. Machine-readable: /mcp.json. Updated daily.