State of MCP Security · 2026-09-09

Snapshot of the MCP server ecosystem as of 2026-09-09 · by PulseFeed · see the live report →

3701▲245
servers audited
3089▲245
safe to install
358▲7
avoid (10%)

Headline: how many run code the moment you install them?

9%▲7

347 of 3701 MCP servers ship an install/postinstall script — arbitrary code runs on your machine at npm i, before you've even used the tool. Some are legitimate native builds, but each is an unreviewed code-execution vector — and 404 of all audited servers publish no repository to inspect at all. A bad MCP server can read your files, env vars and keys the moment it's connected.

Install-script exposure over time

347 80 347 07-0808-0809-09

Verdicts

safe
3089
caution
249
avoid
358
unknown
5

npm servers get deep signals; remote servers get liveness + HTTPS only.

Top safety flags

Servers to avoid (sample)

ServerVerdictFlags
ai.agenticshelf/graffeoavoidunreachable
ai.agenticshelf/mcpavoidunreachable
ai.agenticshelf/puroairavoidunreachable
ai.alpic.test/test-mcp-serveravoidunreachable
ai.autorfp/mcpavoidunreachable
ai.baselight/baselightavoidunreachable
ai.buyersense/buyersenseavoidunreachable
ai.clarid/complianceavoidunreachable
ai.com.mcp/hapi-mcpavoidunreachable
ai.com.mcp/skills-searchavoidunreachable
ai.dynamicfeed/dynamic-feedavoidunreachable
agentdbavoidinstall_script, downloads_unknown

Daily archive

DateAuditedInstall-scriptAvoidAbandoned
2026-09-093701347358129
2026-09-083640345356129
2026-09-073545344355128
2026-09-063538343354128
2026-09-053534344355127
2026-09-043517344355127
2026-09-033490342353124
2026-09-023456340351124
2026-09-013350333344122
2026-08-313299332343122
2026-08-303272330341121
2026-08-293256330341121
2026-08-283244330341121
2026-08-273211323334119

Methodology: PulseFeed discovers MCP servers from the official MCP registry and npm, then audits each independently — install/postinstall scripts (code execution on install), abandonment, provenance, license, repository, download volume, and liveness for remote servers. Verdict = safe / caution / avoid. This report is generated automatically from that data and updates daily. Install scripts are not inherently malicious (native builds use them) but every one is an unreviewed code-execution vector worth checking. Same independent-audit approach as our x402 trust oracle.
Check any server free: GET /mcp/verify?package=<npm-name> · Machine-readable: /mcp-report.json · Live observatory: /mcp · /llms.txt