Live Data

Ecosystem Dashboard

Aggregated security posture across every MCP server we've discovered. Updates every 5 minutes.

41,408Total Servers
20,240 (49%)Scanned
3,009Critical Findings

Findings by Severity 8,640

Critical
3,009
High
2,522
Medium
2,476
Low
535
Informational
98

Cross-server toxic flowconfig-scoped

Individual server scores on this registry are intrinsic - each measures one server on its own. Compositional risk is different: a private-data reader on one server and an external-egress sink on another are each harmless alone but can form a toxic flow once wired into the same client config. That is a config-scoped property of the wiring, never a score against any one server.

We do not publish a registry-wide co-existence count here. A cross-server flow is only real once specific servers share one config, so an ecosystem-wide number would be hypothetical - and we will not print a figure the data does not support.

Category Breakdown

Recently Discovered10

Scan Coverage

20,240 / 41,408 scanned (49%)

21,168 servers awaiting scan

Detection Rules184

184 rules across 21 categories — every server is evaluated against all applicable rules.

ADescription Analysis9
BSchema Analysis7
CCode Analysis17
DDependency Analysis7
EBehavioral Analysis7
FEcosystem Context8
GAdversarial AI7
H2026 Attack Surface3
IProtocol Surface17
J2026 Threat Intelligence9
KCompliance & Governance20
LSupply Chain Advanced16
MAI Runtime Exploitation9
NProtocol Edge Cases15
OData Privacy Attacks7
PInfrastructure Runtime10
QCross-Ecosystem Emergent7
RMCP Apps & UI1
SAsync Task Lifecycle2
TTransport Core2
USchema Auth4

OWASP MCP Top 10 Coverage

Detection rules mapped to all 10 OWASP MCP categories. Every server is evaluated against each category on every scan.

MCP01Prompt Injection
MCP02Tool Poisoning
MCP03Command Injection
MCP04Data Exfiltration
MCP05Privilege Escalation
MCP06Excessive Permissions
MCP07Insecure Configuration
MCP08Dependency Vulnerabilities
MCP09Logging & Monitoring
MCP10Supply Chain