This repo hosts tooltrust.dev β the website and pre-scanned report data. If you want to scan your own MCP servers, go to tooltrust-scanner.
A public registry of AI agent tools, continuously scanned for prompt injection, data exfiltration, and privilege escalation by ToolTrust Scanner.
π¨ Supply-Chain Incident Coverage (March 2026)
ToolTrust now detects and blocks confirmed supply-chain incidents including the LiteLLM / TeamPCP compromise and the malicious axios npm publish (axios@1.14.1, axios@0.30.4). For npm-backed MCP servers, ToolTrust also scores dependency visibility, transitive lockfile evidence, lifecycle scripts, and IOC indicators such as plain-crypto-js.


π Security Registry
Top 50 by popularity. View all 1815 tools β Full Directory Β· data/reports/ Β· docs/tools/
| Tool |
Version |
Popularity |
Grade |
Key Findings |
Scanned |
| typescript-sdk |
2.0.0-beta.1 |
204.5M/mo |
A |
AS-014 |
Aug 22 |
| playwright-mcp |
0.0.79 |
26.0M/mo |
C |
AS-014 Γ24, π AS-002 Γ11, β‘ AS-006 Γ2, β‘ AS-011 Γ5 |
Aug 22 |
| ext-apps |
1.7.5 |
12.2M/mo |
A |
π AS-002, AS-014 Γ3 |
Aug 22 |
| chrome-devtools-mcp |
chrome-dev⦠|
7.9M/mo |
C |
AS-014 Γ29, π AS-002 Γ13, β‘ AS-011 Γ4, β‘ AS-006 |
Aug 22 |
| context7 |
1.0.30 |
4.1M/mo |
A |
AS-014 Γ2, π AS-002, β‘ AS-011 |
Aug 22 |
| upstash-context7-mcp |
1.0.30 |
3.4M/mo |
A |
AS-014 Γ2, π AS-002, β‘ AS-011 |
Jul 17 |
| mcp-server-filesystem |
typescript⦠|
2.0M/mo |
A |
π AS-002 Γ14, AS-014 Γ14, β‘ AS-011 |
Aug 22 |
| gemini-cli |
0.57.0-pre⦠|
1.7M/mo |
A |
AS-014 Γ56, π AS-002 Γ23, β‘ AS-011 Γ11 |
Aug 22 |
| cloudflare-containers |
0.3.2 |
1.6M/mo |
A |
π AS-002 Γ5, β‘ AS-011, AS-014 Γ7 |
Jun 22 |
| inspector |
2-alpha-15 |
944.1k/mo |
A |
AS-014 Γ2 |
Aug 22 |
| notion-mcp-server |
2.5.0 |
780.1k/mo |
A |
π AS-002 Γ24, β‘ AS-011 Γ24, AS-014 Γ24 |
Aug 22 |
| n8n-mcp |
2.73.0 |
668.4k/mo |
A |
AS-014 Γ23, π AS-002 Γ8, β‘ AS-011 Γ4 |
Aug 22 |
| agent-device |
0.20.10 |
590.9k/mo |
B |
AS-012, π AS-002, β‘ AS-011, AS-014 Γ5, ποΈ AS-010 |
Aug 22 |
| mcp-server-sequential-thinking |
typescript⦠|
539.2k/mo |
A |
AS-014 |
Aug 22 |
| mcp-server-github |
typescript⦠|
525.9k/mo |
A |
π AS-002 Γ24, AS-014 Γ26, β‘ AS-011 Γ18 |
Aug 22 |
| firecrawl-mcp-server |
3.2.1 |
512.2k/mo |
A |
π AS-002 Γ30, β‘ AS-011 Γ24, AS-014 Γ25 |
Aug 22 |
| cameroncooke-xcodebuildmcp |
2.3.2 |
468.8k/mo |
A |
AS-014 Γ71, π AS-002 Γ31, β‘ AS-011 Γ3 |
Jun 22 |
| azure-devops-mcp |
2.9.0 |
465.9k/mo |
B |
AS-012, AS-014 Γ9, π AS-002, β‘ AS-011 |
Aug 21 |
| figma-context-mcp |
0.13.2 |
351.8k/mo |
B |
AS-012, π AS-002 Γ7, AS-014 Γ7, β‘ AS-011 |
Aug 22 |
| qwen-code |
weaken-too⦠|
286.3k/mo |
A |
AS-014 Γ23, π AS-002, β‘ AS-011 |
Aug 22 |
| mcp-framework |
mcp-framew⦠|
248.4k/mo |
A |
AS-014 Γ3, π AS-002 Γ2, β‘ AS-011 |
Aug 10 |
| mcpb |
2.1.2 |
244.1k/mo |
C |
π AS-002 Γ2, β‘ AS-011 Γ2, AS-014 Γ10, β‘ AS-006 |
Aug 22 |
| desktopcommandermcp |
0.2.47 |
228.6k/mo |
B |
π AS-002 Γ19, AS-014 Γ26, β‘ AS-011 Γ8, π AS-003 |
Aug 22 |
| tavily-ai-tavily-mcp |
0.2.19 |
178.6k/mo |
A |
π AS-002 Γ7, β‘ AS-011 Γ5, AS-014 Γ5 |
Jun 22 |
| ms-365-mcp-server |
0.145.2 |
178.2k/mo |
A |
AS-014 Γ188, π AS-002 Γ229, β‘ AS-011 Γ182 |
Aug 22 |
| mcp-server-circleci |
0.20.0 |
149.4k/mo |
B |
π AS-002 Γ13, β‘ AS-011 Γ13, AS-014 Γ13, π AS-003 Γ2 |
Aug 22 |
| n8n-nodes-mcp |
0.1.37 |
133.5k/mo |
A |
AS-014 Γ27, π AS-002 Γ21, β‘ AS-011 Γ9, ποΈ AS-010 |
Aug 21 |
| tavily-mcp |
0.2.22 |
127.2k/mo |
A |
π AS-002 Γ7, β‘ AS-011 Γ5, AS-014 Γ5 |
Aug 22 |
| circleci-public-mcp-server-circleci |
0.15.1 |
126.3k/mo |
B |
π AS-002 Γ15, β‘ AS-011 Γ11, AS-014 Γ16, π AS-003 Γ2 |
Jun 22 |
| mcp-server-trello |
2.0.0-beta.0 |
123.3k/mo |
A |
π AS-002 Γ106, AS-014 Γ200, β‘ AS-011 Γ53, ποΈ AS-010 |
Aug 12 |
| mcp-server-cloudflare |
workers-ob⦠|
112.4k/mo |
C |
π AS-002 Γ2, β‘ AS-011 Γ2, AS-014 Γ2, β‘ AS-006 |
Aug 22 |
| exa-mcp-server |
3.4.1 |
106.5k/mo |
A |
π AS-002 Γ2, β‘ AS-011 Γ2, AS-014 Γ2 |
Aug 22 |
| mcp-server-brave-search |
typescript⦠|
101.5k/mo |
A |
π AS-002 Γ10, β‘ AS-011 Γ7, AS-014 Γ8, ποΈ AS-010 Γ2 |
Aug 22 |
| mobile-mcp |
1.0.2 |
99.3k/mo |
A |
π AS-002 Γ10, β‘ AS-011 Γ5, AS-014 Γ27 |
Aug 22 |
| brave-search-mcp-server |
2.1.3 |
97.4k/mo |
A |
π AS-002 Γ10, β‘ AS-011 Γ7, AS-014 Γ8, ποΈ AS-010 Γ2 |
Aug 22 |
| figma-console-mcp |
1.40.0 |
96.0k/mo |
A |
AS-014 Γ9, π AS-002, β‘ AS-011 |
Aug 22 |
| apify-mcp-server |
0.15.1 |
95.0k/mo |
C |
π AS-002 Γ16, β‘ AS-011 Γ7, AS-014 Γ16, β‘ AS-006 Γ2 |
Aug 22 |
| mcp-server-time |
typescript⦠|
89.8k |
A |
AS-014 Γ2 |
Aug 22 |
| mcp-searxng |
2.0.0 |
87.6k/mo |
A |
π AS-002 Γ4, β‘ AS-011 Γ3, AS-014 Γ4 |
Aug 22 |
| mcp-playwright |
1.0.12 |
84.9k/mo |
C |
π AS-002 Γ6, AS-014 Γ6, β‘ AS-011 Γ5, β‘ AS-006 |
Aug 21 |
| worldmonitor |
2.10.0 |
83.7k |
A |
π AS-002 Γ2, β‘ AS-011 Γ2, AS-014 Γ2 |
Aug 22 |
| context-mode |
1.0.169 |
82.0k/mo |
B |
AS-012, AS-014 Γ11, π AS-002 |
Aug 22 |
| claude-task-master |
0.20.0 |
80.6k/mo |
A |
π AS-002 Γ23, AS-014 Γ57, β‘ AS-011 Γ8, ποΈ AS-010 |
Aug 22 |
| ruflo |
3.38.16 |
79.5k/mo |
A |
π AS-002 Γ21, β‘ AS-011 Γ18, AS-014 Γ27 |
Aug 22 |
| agent-reach |
1.5.0 |
73.9k |
B |
AS-012, π AS-002, β‘ AS-011, AS-014 Γ5, ποΈ AS-010 |
Aug 22 |
| mcp-server-kubernetes |
4.1.4 |
71.2k/mo |
A |
AS-014 Γ22, π AS-002 Γ6, β‘ AS-011 Γ3 |
Aug 22 |
| headroom |
0.36.3 |
67.1k |
A |
π AS-002 Γ2, β‘ AS-011 Γ2, AS-014 Γ2 |
Aug 22 |
| mempalace |
3.7.1 |
58.5k |
A |
AS-014 Γ3, π AS-002 Γ2, β‘ AS-011 |
Aug 22 |
| mcp-server-mysql |
2.0.9 |
53.8k/mo |
A |
π AS-002 Γ4, AS-014 Γ4, β‘ AS-011 |
Aug 21 |
| magic-mcp |
0.1.1-beta.1 |
49.1k/mo |
A |
π AS-002 Γ4, AS-014 Γ4, β‘ AS-011 Γ2 |
Jul 24 |
βοΈ Grading System
| Grade |
Gateway Action |
Description |
| S π |
ALLOW |
Reserved for dynamic analysis |
| A |
ALLOW |
Minimal risk. Safe for production agents. |
| B |
ALLOW + rate limit |
Low risk. Minor issues, but generally safe. |
| C |
REQUIRE_APPROVAL |
Moderate risk. Remediation recommended. |
| D |
REQUIRE_APPROVAL |
High risk. Use only in isolated environments. |
| F |
BLOCK |
Critical risk. Do not use in agentic pipelines. |
Full methodology: docs/methodology.md
π Check Catalog
ToolTrust Scanner check IDs referenced in all reports:
| ID |
Severity |
Detects |
| π‘οΈΒ ASβ001 |
Critical |
Tool Poisoning β Adversarial prompts hidden in tool descriptions (ignore previous instructions, <INST>) |
| πΒ ASβ002 |
High/Low |
Permission Surface β exec, network, db, fs beyond stated purpose; over-broad input schema |
| πΒ ASβ003 |
High |
Scope Mismatch β Tool name contradicts its permissions (e.g. read_config with exec) |
| π¦Β ASβ004 |
High/Critical |
Supply Chain CVEs β Known CVEs in bundled dependencies via OSV |
| πΒ ASβ005 |
High |
Privilege Escalation β admin/:write OAuth scopes; sudo/impersonate in descriptions |
| β‘Β ASβ006 |
Critical |
Arbitrary Code Execution β evaluate_script, _evaluate suffix, execute javascript, page.evaluate() patterns |
| βΉοΈΒ ASβ007 |
Info |
Insufficient Tool Data β Tool lacks a valid description or schema |
| π¨Β ASβ008 |
Critical |
Known Compromised Package β Offline embedded blacklist of confirmed supply-chain attacks (LiteLLM 1.82.7/1.82.8, Trivy v0.69.4-v0.69.6, Langflow <1.9.0, Axios 1.14.1/0.30.4). Zero-latency, no network required. |
| π€Β ASβ009 |
Medium |
Typosquatting β Tool name within edit-distance 2 of a well-known MCP tool, suggesting impersonation |
| ποΈΒ ASβ010 |
Medium |
Secret Handling β Input params accepting API keys/passwords; credentials logged insecurely |
| β‘Β ASβ011 |
Low |
DoS Resilience β No rate-limit, timeout, or retry config on network/exec tools |
| πΒ ASβ012 |
High |
Rug-Pull β Tool set changed between scans of the same version without a version bump (directory pipeline only) |
| π₯Β ASβ013 |
High/Medium |
Tool Shadowing β Duplicate or near-duplicate tool name hijacks calls intended for a trusted tool |
| βΉοΈΒ ASβ014 |
Info |
Dependency Inventory Unavailable β MCP server exposed neither metadata.dependencies nor a repo_url, so supply-chain coverage is limited and must be treated as incomplete |
| β οΈΒ ASβ015 |
Medium/High |
Suspicious NPM Lifecycle Script β npm dependency publishes preinstall / postinstall / similar install-time scripts; severity rises for remote-fetch or inline-execution patterns |
| π¨Β ASβ016 |
Critical |
Suspicious NPM IOC Dependency β published npm metadata or install-time scripts reference a known malicious IOC package, domain, URL, or reviewed script pattern such as plain-crypto-js, even if the top-level package name is new |
| β οΈΒ ASβ017 |
Medium |
Suspicious Data Exfiltration Description β tool description explicitly suggests sending user data, content, or conversation history to external / remote endpoints, without classifying it as prompt injection |
| βΉοΈΒ ASβ018 |
Info |
Embedded MCP Server Detected β source-level MCP SDK usage was found, but tools could not be enumerated from a manifest or live handshake, so manual review is still required |
| πΒ ASβ019 |
High |
Unauthenticated MCP Route Exposure β embedded MCP HTTP routes expose the same handler without equivalent authentication middleware |
Full details β docs/methodology.md
π€ AI Agent Integration
Let your AI agent scan its own tools. Add ToolTrust as an MCP server in your .mcp.json or claude_desktop_config.json:
{
"mcpServers": {
"tooltrust": {
"command": "npx",
"args": ["-y", "tooltrust-mcp"]
}
}
}
This gives your agent five security tools:
| Tool |
Description |
tooltrust_scan_config |
Scan all MCP servers in your .mcp.json or ~/.claude.json in parallel |
tooltrust_scan_server |
Launch and scan a specific MCP server |
tooltrust_scanner_scan |
Scan a JSON blob of tool definitions |
tooltrust_lookup |
Look up a server's trust grade from this directory |
tooltrust_list_rules |
List all security rules with IDs and descriptions |
Claude Code users: ask your agent to run tooltrust_scan_config to audit every MCP server in your project in one shot.
π€ Contribute
Request a scan β open an issue with the tool's public URL and version.
Dispute a finding β open an issue referencing the finding ID (e.g. AS-002).
Integrate ToolTrust Scanner β see docs/dev.md for the data pipeline and schema spec.
π Add to your README
If your MCP server was audited and earned a grade, add our badge to your repo:
Grade A (recommended) β copy this into your README:
[](https://github.com/AgentSafe-AI/tooltrust-directory)
Other grades β replace grade-a with grade-s, grade-b, grade-c, grade-d, or grade-f:
Badges link to this directory. Generate SVGs locally: go run ./cmd/badge
βοΈ Automation
The registry table above is kept up to date by a daily GitHub Actions workflow:
.github/workflows/daily-audit.yml β cron 00:00 UTC + manual dispatch
Each run:
- Discovers popular MCP servers via GitHub Search (50+ stars) plus Smithery-native servers (10+ uses)
- Scans new/updated tools with ToolTrust Scanner + OSV supply-chain analysis
- Publishes updated reports to
data/reports/ and regenerates this README
Licensed MIT. Scanner engine: ToolTrust Scanner.