Snapshot of the MCP server ecosystem as of 2026-08-12 · by PulseFeed · see the live report →
263 of 2622 MCP servers ship an install/postinstall script — arbitrary code runs on your machine at npm i, before you've even used the tool. Some are legitimate native builds, but each is an unreviewed code-execution vector — and 285 of all audited servers publish no repository to inspect at all. A bad MCP server can read your files, env vars and keys the moment it's connected.
npm servers get deep signals; remote servers get liveness + HTTPS only.
| Server | Verdict | Flags |
|---|---|---|
| ai.agenticshelf/graffeo | avoid | unreachable |
| ai.agenticshelf/mcp | avoid | unreachable |
| ai.agenticshelf/puroair | avoid | unreachable |
| ai.alpic.test/test-mcp-server | avoid | unreachable |
| ai.autorfp/mcp | avoid | unreachable |
| ai.baselight/baselight | avoid | unreachable |
| ai.buyersense/buyersense | avoid | unreachable |
| ai.clarid/compliance | avoid | unreachable |
| ai.com.mcp/hapi-mcp | avoid | unreachable |
| ai.com.mcp/skills-search | avoid | unreachable |
| ai.dynamicfeed/dynamic-feed | avoid | unreachable |
| agentdb | avoid | install_script |
| Date | Audited | Install-script | Avoid | Abandoned |
|---|---|---|---|---|
| 2026-08-12 | 2622 | 263 | 274 | 107 |
| 2026-08-11 | 2431 | 249 | 260 | 101 |
| 2026-08-10 | 2259 | 236 | 247 | 97 |
| 2026-08-09 | 2251 | 235 | 246 | 97 |
| 2026-08-08 | 1208 | 142 | 150 | 46 |
| 2026-08-07 | 1207 | 142 | 150 | 45 |
| 2026-08-06 | 1205 | 142 | 150 | 44 |
| 2026-08-05 | 1198 | 142 | 150 | 44 |
| 2026-08-04 | 1176 | 138 | 146 | 44 |
| 2026-08-03 | 1161 | 138 | 147 | 44 |
| 2026-08-02 | 1155 | 137 | 145 | 43 |
| 2026-08-01 | 1152 | 136 | 144 | 43 |
| 2026-07-31 | 1150 | 136 | 144 | 43 |
| 2026-07-30 | 1138 | 136 | 147 | 43 |
Methodology: PulseFeed discovers MCP servers from the official MCP registry and npm, then audits each independently — install/postinstall scripts (code execution on install), abandonment, provenance, license, repository, download volume, and liveness for remote servers. Verdict = safe / caution / avoid. This report is generated automatically from that data and updates daily. Install scripts are not inherently malicious (native builds use them) but every one is an unreviewed code-execution vector worth checking. Same independent-audit approach as our x402 trust oracle.
Check any server free: GET /mcp/verify?package=<npm-name> · Machine-readable: /mcp-report.json · Live observatory: /mcp · /llms.txt