Independent safety audit of the MCP server ecosystem · by PulseFeed
Thousands of MCP servers ship with almost no vetting — and a bad one can run arbitrary code on your machine or exfiltrate data. Before you connect your AI agent to an MCP server, check it. We audit maintenance, install-script risk, provenance, abandonment and liveness.
npm servers get deep signals; remote servers get liveness + HTTPS only (can't fully verify a black-box remote).
install_script = arbitrary code on npm i; abandoned = stale; unreachable = dead remote.
| Server | Type | npm dl/wk | Trust |
|---|---|---|---|
| @modelcontextprotocol/sdk | npm | 74,981,440 | 100 |
| ai | npm | 34,162,045 | 100 |
| @ai-sdk/mcp | npm | 5,569,610 | 100 |
| @storybook/mcp | npm | 2,709,647 | 100 |
| @storybook/addon-mcp | npm | 2,854,283 | 100 |
| mcporter | npm | 454,576 | 100 |
| @assistant-ui/react | npm | 2,351,184 | 100 |
| mcp-handler | npm | 1,473,697 | 100 |
| @copilotkit/aimock | npm | 675,944 | 100 |
| fallow | npm | 1,691,728 | 100 |
| mcp-remote | npm | 716,048 | 100 |
| @langchain/mcp-adapters | npm | 323,425 | 100 |
| add-mcp | npm | 219,983 | 100 |
| eve | npm | 1,358,143 | 100 |
| @modelcontextprotocol/server | npm | 10,001,814 | 100 |
GET /mcp/verify?package=<npm-name> — free. Returns a safety verdict, score and flags (install scripts, abandonment, provenance, license, repo).Methodology: PulseFeed discovers servers from the official MCP registry, audits each via npm metadata (install scripts, provenance, license, downloads, freshness) and liveness for remotes. Same independent-audit approach as our x402 trust oracle. Machine-readable: /mcp.json. Updated daily.