polygraph.so

The MCP Security Index

Every grade we publish — MCP servers tested for behavior and ordered by adoption, Agent Skills scanned for safety. What each one does, not what its README claims.

107 MCP servers graded, ranked by adoption · 13 live endpoints (hosted, egress unverified) · 110 skills scanned · adoption data as of 2026-08-21. A grade is a measurement, not a guarantee; you can re-run the open harness yourself.

Request a gradeNot up yet? Add it to the bench — free, and we email you when it publishes.
Grade
120 servers
#ServerGradeChecksAdoption
1npm/@playwright/mcpA01020304100/10026M npm/mo
2npm/@modelcontextprotocol/server-filesystemA0102030488/1002.01M npm/mo
3npm/@upstash/context7-mcpA0102030486/1004.11M npm/mo
4npm/@modelcontextprotocol/server-everythingF0102030484/100489K npm/mo
5npm/n8n-mcpA0102030481/100668K npm/mo
6npm/@modelcontextprotocol/server-sequential-thinkingA0102030479/100539K npm/mo
7npm/firecrawl-mcpA0102030479/100512K npm/mo
8npm/@modelcontextprotocol/server-memoryA0102030478/100395K npm/mo
9npm/@modelcontextprotocol/server-githubA0102030478/100526K npm/mo
10npm/@notionhq/notion-mcp-serverA0102030478/100780K npm/mo
11npm/@21st-dev/magicA0102030477/100215K npm/mo
12npm/exa-mcp-serverA0102030473/100107K npm/mo
13npm/@modelcontextprotocol/server-puppeteerA0102030471/100113K npm/mo
14npm/tavily-mcpA0102030470/100127K npm/mo
15npm/mcp-server-kubernetesA0102030467/10071.2K npm/mo
16npm/@netlify/mcpA0102030467/10066.2K npm/mo
17npm/@negokaz/excel-mcp-serverA0102030466/10061.1K npm/mo
18pypi/mcp-server-timeA0102030463/100820K pypi/mo
19npm/@antv/mcp-server-chartA0102030462/10036.3K npm/mo
20npm/open-websearchA0102030461/10016.7K npm/mo
Page 1 of 6

pass fail not runC-01 tool-output injection · C-02 egress overreach · C-03 sensitive-data handling · C-04 adversarial-input handling

Ranked by the adoption score (0–100, shown at right above monthly downloads) — a composite of downloads (npm / PyPI), GitHub stars, dependents and release velocity. It measures reach, not safety: the litmus grade is the only safety verdict. Grades come from the open litmus harness; you can request a grade for a server, or read the methodology.

Index data is published under CC BY 4.0: reuse it freely, with attribution to polygraph.so.