polygraph.so

The MCP Security Index

Every grade we publish — MCP servers tested for behavior and ordered by adoption, Agent Skills scanned for safety. What each one does, not what its README claims.

107 MCP servers graded, ranked by adoption · 13 live endpoints (hosted, egress unverified) · 110 skills scanned · adoption data as of 2026-10-09. A grade is a measurement, not a guarantee; you can re-run the open harness yourself.

Run the harnessHosted grading is discontinued. Grade a server locally with the open harness.
Grade
120 servers
#ServerGradeChecksAdoption
1npm/@playwright/mcpA01✓02✓03✓04✓100/10030.6M npm/mo
2npm/@modelcontextprotocol/server-filesystemA01✓02✓03✓04✓87/1002.52M npm/mo
3npm/@modelcontextprotocol/server-everythingF01✓02✓03✕04✓82/1001.12M npm/mo
4npm/@modelcontextprotocol/server-memoryA01✓02✓03✓04✓82/100630K npm/mo
5npm/@upstash/context7-mcpA01✓02✓03✓04✓81/1003.1M npm/mo
6npm/firecrawl-mcpA01✓02✓03✓04✓79/100484K npm/mo
7npm/@modelcontextprotocol/server-sequential-thinkingA01✓02✓03✓04✓78/100521K npm/mo
8npm/@modelcontextprotocol/server-githubA01✓02✓03✓04✓76/100506K npm/mo
9npm/exa-mcp-serverA01✓02✓03✓04✓76/100239K npm/mo
10npm/@notionhq/notion-mcp-serverA01✓02✓03✓04✓75/100770K npm/mo
11npm/n8n-mcpA01✓02✓03✓04✓74/100420K npm/mo
12npm/@modelcontextprotocol/server-puppeteerA01✓02✓03✓04✓72/100133K npm/mo
13npm/@netlify/mcpA01✓02✓03✓04✓70/100155K npm/mo
14npm/tavily-mcpA01✓02✓03✓04✓68/10092.1K npm/mo
15npm/@21st-dev/magicA01✓02✓03✓04✓67/100121K npm/mo
16npm/open-websearchA01✓02✓03✓04✓66/10036.1K npm/mo
17npm/@coding-solo/godot-mcpA01✓02✓03✓04✓64/10023.9K npm/mo
18npm/mcp-server-kubernetesA01✓02✓03✓04✓63/10041.5K npm/mo
19npm/@negokaz/excel-mcp-serverA01✓02✓03✓04✓62/10040.3K npm/mo
20npm/@browserbasehq/mcp-server-browserbaseA01✓02✓03✓04✓62/10020.2K npm/mo
Page 1 of 6

✓ pass✕ fail– not runC-01 tool-output injection · C-02 egress overreach · C-03 sensitive-data handling · C-04 adversarial-input handling

Ranked by the adoption score (0–100, shown at right above monthly downloads) — a composite of downloads (npm / PyPI), GitHub stars, dependents and release velocity. It measures reach, not safety: the litmus grade is the only safety verdict. Grades come from the open litmus harness; you can run it yourself for a server, or read the methodology.

Index data is published under CC BY 4.0: reuse it freely, with attribution to polygraph.so.