State of MCP Security · 2026-09-12

Snapshot of the MCP server ecosystem as of 2026-09-12 · by PulseFeed · see the live report →

3860▲326
servers audited
3234▲313
safe to install
365▲10
avoid (9%)

Headline: how many run code the moment you install them?

9%▲10

354 of 3860 MCP servers ship an install/postinstall script — arbitrary code runs on your machine at npm i, before you've even used the tool. Some are legitimate native builds, but each is an unreviewed code-execution vector — and 422 of all audited servers publish no repository to inspect at all. A bad MCP server can read your files, env vars and keys the moment it's connected.

Install-script exposure over time

354 80 354 07-0808-1009-12

Verdicts

safe
3234
caution
256
avoid
365
unknown
5

npm servers get deep signals; remote servers get liveness + HTTPS only.

Top safety flags

Servers to avoid (sample)

ServerVerdictFlags
ai.agenticshelf/graffeoavoidunreachable
ai.agenticshelf/mcpavoidunreachable
ai.agenticshelf/puroairavoidunreachable
ai.alpic.test/test-mcp-serveravoidunreachable
ai.autorfp/mcpavoidunreachable
ai.baselight/baselightavoidunreachable
ai.buyersense/buyersenseavoidunreachable
ai.clarid/complianceavoidunreachable
ai.com.mcp/hapi-mcpavoidunreachable
ai.com.mcp/skills-searchavoidunreachable
ai.dynamicfeed/dynamic-feedavoidunreachable
agentdbavoidinstall_script

Daily archive

DateAuditedInstall-scriptAvoidAbandoned
2026-09-123860354365131
2026-09-113836353364131
2026-09-103793351362129
2026-09-093701347358129
2026-09-083640345356129
2026-09-073545344355128
2026-09-063538343354128
2026-09-053534344355127
2026-09-043517344355127
2026-09-033490342353124
2026-09-023456340351124
2026-09-013350333344122
2026-08-313299332343122
2026-08-303272330341121

Methodology: PulseFeed discovers MCP servers from the official MCP registry and npm, then audits each independently — install/postinstall scripts (code execution on install), abandonment, provenance, license, repository, download volume, and liveness for remote servers. Verdict = safe / caution / avoid. This report is generated automatically from that data and updates daily. Install scripts are not inherently malicious (native builds use them) but every one is an unreviewed code-execution vector worth checking. Same independent-audit approach as our x402 trust oracle.
Check any server free: GET /mcp/verify?package=<npm-name> · Machine-readable: /mcp-report.json · Live observatory: /mcp · /llms.txt