Skip to content

Repository files navigation

🛡️ ToolTrust Directory

This repo hosts tooltrust.dev — the website and pre-scanned report data. If you want to scan your own MCP servers, go to tooltrust-scanner.

A public registry of AI agent tools, continuously scanned for prompt injection, data exfiltration, and privilege escalation by ToolTrust Scanner.

🚨 Supply-Chain Incident Coverage (March 2026) ToolTrust now detects and blocks confirmed supply-chain incidents including the LiteLLM / TeamPCP compromise and the malicious axios npm publish (axios@1.14.1, axios@0.30.4). For npm-backed MCP servers, ToolTrust also scores dependency visibility, transitive lockfile evidence, lifecycle scripts, and IOC indicators such as plain-crypto-js.

ToolTrust Directory UI

Tools Audited Last Scan License: MIT Schema


📊 Security Registry

Top 50 by popularity. View all 1760 tools → Full Directory · data/reports/ · docs/tools/

Tool Version Popularity Grade Key Findings Scanned
typescript-sdk 2.0.0-beta.1 186.6M/mo A AS-014 Aug 5
playwright-mcp 0.0.78 26.4M/mo C AS-014 ×24, 🔑 AS-002 ×11, ⚡ AS-006 ×2, ⚡ AS-011 ×5 Aug 5
ext-apps 1.7.5 10.1M/mo A 🔑 AS-002, AS-014 ×3 Aug 5
chrome-devtools-mcp chrome-dev… 8.2M/mo C AS-014 ×29, 🔑 AS-002 ×13, ⚡ AS-011 ×4, ⚡ AS-006 Aug 5
context7 1.0.30 4.0M/mo A AS-014 ×2, 🔑 AS-002, ⚡ AS-011 Aug 5
upstash-context7-mcp 1.0.30 3.4M/mo A AS-014 ×2, 🔑 AS-002, ⚡ AS-011 Jul 17
mcp-server-filesystem typescript… 2.2M/mo A 🔑 AS-002 ×14, AS-014 ×14, ⚡ AS-011 Aug 5
gemini-cli 0.55.0-nig… 1.9M/mo A AS-014 ×56, 🔑 AS-002 ×23, ⚡ AS-011 ×11 Aug 5
cloudflare-containers 0.3.2 1.6M/mo A 🔑 AS-002 ×5, ⚡ AS-011, AS-014 ×7 Jun 22
inspector 2-alpha-15 880.9k/mo A AS-014 ×2 Aug 5
notion-mcp-server 2.5.0 724.2k/mo A 🔑 AS-002 ×24, ⚡ AS-011 ×24, AS-014 ×24 Aug 5
mcp-server-sequential-thinking typescript… 719.8k/mo A AS-014 Aug 5
n8n-mcp 2.68.0 579.8k/mo A AS-014 ×23, 🔑 AS-002 ×8, ⚡ AS-011 ×4 Aug 5
mcp-server-github typescript… 551.4k/mo A 🔑 AS-002 ×24, AS-014 ×26, ⚡ AS-011 ×18 Aug 5
cameroncooke-xcodebuildmcp 2.3.2 468.8k/mo A AS-014 ×71, 🔑 AS-002 ×31, ⚡ AS-011 ×3 Jun 22
firecrawl-mcp-server 3.2.1 339.2k/mo A 🔑 AS-002 ×30, ⚡ AS-011 ×24, AS-014 ×25 Aug 5
desktopcommandermcp 0.2.47 300.3k/mo B 🔑 AS-002 ×19, AS-014 ×26, ⚡ AS-011 ×8, 📐 AS-003 Aug 5
qwen-code 0.21.6-pre… 300.0k/mo A AS-014 ×54 Aug 5
mcp-framework mcp-framew… 239.4k/mo A AS-014 ×3, 🔑 AS-002 ×2, ⚡ AS-011 Aug 4
mcpb 2.1.2 220.2k/mo C 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×10, ⚡ AS-006 Aug 5
tavily-ai-tavily-mcp 0.2.19 178.6k/mo A 🔑 AS-002 ×7, ⚡ AS-011 ×5, AS-014 ×5 Jun 22
ms-365-mcp-server 0.136.0 142.3k/mo A AS-014 ×188, 🔑 AS-002 ×229, ⚡ AS-011 ×182 Aug 5
mcp-server-cloudflare workers-ob… 138.8k/mo C 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×2, ⚡ AS-006 Aug 4
mcp-server-circleci 0.19.1 134.5k/mo B 🔑 AS-002 ×13, ⚡ AS-011 ×11, AS-014 ×13, 📐 AS-003 ×2 Aug 5
tavily-mcp 0.2.21 127.7k/mo A 🔑 AS-002 ×7, ⚡ AS-011 ×5, AS-014 ×5 Aug 5
circleci-public-mcp-server-circleci 0.15.1 126.3k/mo B 🔑 AS-002 ×15, ⚡ AS-011 ×11, AS-014 ×16, 📐 AS-003 ×2 Jun 22
n8n-nodes-mcp 0.1.37 125.3k/mo A AS-014 ×27, 🔑 AS-002 ×21, ⚡ AS-011 ×9, 🗝️ AS-010 Aug 4
mcp-server-time typescript… 89.2k A AS-014 ×2 Aug 5
ruflo 3.34.0 85.3k/mo A 🔑 AS-002 ×21, ⚡ AS-011 ×18, AS-014 ×27 Aug 4
mcp-playwright 1.0.12 82.2k/mo C 🔑 AS-002 ×6, AS-014 ×6, ⚡ AS-011 ×5, ⚡ AS-006 Aug 4
mobile-mcp 1.0.0 80.8k/mo A AS-014 ×23, 🔑 AS-002 ×5, ⚡ AS-011 Aug 5
mcp-server-kubernetes 4.1.2 79.8k/mo A AS-014 ×22, 🔑 AS-002 ×6, ⚡ AS-011 ×3 Aug 5
exa-mcp-server 3.4.0 79.5k/mo A 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×2 Aug 5
worldmonitor 2.5.23 78.5k A 🔑 AS-002 ×39, AS-014 ×39, ⚡ AS-011 ×5 Aug 4
apify-mcp-server 0.14.1 74.1k/mo C 🔑 AS-002 ×16, ⚡ AS-011 ×7, AS-014 ×16, ⚡ AS-006 ×2 Aug 5
mcp-server-chart 0.9.10 73.3k/mo A AS-014 ×26, 🔑 AS-002, ⚡ AS-011 Aug 5
claude-task-master 0.20.0 70.5k/mo A AS-014 ×14, 🔑 AS-002 ×9, ⚡ AS-011 Aug 4
agent-reach 1.5.0 65.8k A AS-014 ×4, 🔑 AS-002 ×3, ⚡ AS-011 ×2 Aug 4
headroom 0.33.0 64.8k A 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×2 Aug 5
mcp-searxng 1.14.0 64.7k/mo A 🔑 AS-002 ×3, ⚡ AS-011 ×3, AS-014 ×4 Aug 5
mempalace 3.6.0 58.0k A AS-014 ×3, 🔑 AS-002 ×2, ⚡ AS-011 Aug 4
magic-mcp 0.1.1-beta.1 49.1k/mo A 🔑 AS-002 ×4, AS-014 ×4, ⚡ AS-011 ×2 Jul 24
anytype-mcp 1.2.10 48.8k/mo B AS-014 ×18, 🔑 AS-002 ×7, ⚡ AS-011 ×3, 📐 AS-003 Aug 4
mcp-server-mysql 2.0.9 46.8k/mo A 🔑 AS-002 ×4, AS-014 ×4, ⚡ AS-011 Aug 4
ai-engineering-from-scratch 2026.07 44.6k A AS-014 ×3, 🔑 AS-002, ⚡ AS-011 Jul 29
browsermcp 0.1.3 44.1k/mo A 🔑 AS-002, ⚡ AS-011, AS-014 ×12 Aug 5
kong 3.9.3 43.9k A AS-014 Aug 5
codebase-memory-mcp 0.9.1-rc.1 37.3k A AS-014 ×9, 🔑 AS-002 ×6, ⚡ AS-011 ×2 Aug 4
railway-mcp-server 0.1.11 34.9k/mo A 🔑 AS-002 ×31, AS-014 ×36, ⚡ AS-011 ×13, 🗝️ AS-010 Jun 22
kastalien-research-clear-thought-two 1.2.0 33.3k/mo A AS-014 ×3, 🔑 AS-002 ×2, ⚡ AS-011 Jun 22

⚖️ Grading System

Grade Gateway Action Description
S 🌟 ALLOW Reserved for dynamic analysis
A ALLOW Minimal risk. Safe for production agents.
B ALLOW + rate limit Low risk. Minor issues, but generally safe.
C REQUIRE_APPROVAL Moderate risk. Remediation recommended.
D REQUIRE_APPROVAL High risk. Use only in isolated environments.
F BLOCK Critical risk. Do not use in agentic pipelines.

Full methodology: docs/methodology.md


🔍 Check Catalog

ToolTrust Scanner check IDs referenced in all reports:

ID Severity Detects
🛡️ AS‑001 Critical Tool Poisoning — Adversarial prompts hidden in tool descriptions (ignore previous instructions, <INST>)
🔑 AS‑002 High/Low Permission Surfaceexec, network, db, fs beyond stated purpose; over-broad input schema
📐 AS‑003 High Scope Mismatch — Tool name contradicts its permissions (e.g. read_config with exec)
📦 AS‑004 High/Critical Supply Chain CVEs — Known CVEs in bundled dependencies via OSV
🔓 AS‑005 High Privilege Escalationadmin/:write OAuth scopes; sudo/impersonate in descriptions
⚡ AS‑006 Critical Arbitrary Code Executionevaluate_script, _evaluate suffix, execute javascript, page.evaluate() patterns
ℹ️ AS‑007 Info Insufficient Tool Data — Tool lacks a valid description or schema
🚨 AS‑008 Critical Known Compromised Package — Offline embedded blacklist of confirmed supply-chain attacks (LiteLLM 1.82.7/1.82.8, Trivy v0.69.4-v0.69.6, Langflow <1.9.0, Axios 1.14.1/0.30.4). Zero-latency, no network required.
🔤 AS‑009 Medium Typosquatting — Tool name within edit-distance 2 of a well-known MCP tool, suggesting impersonation
🗝️ AS‑010 Medium Secret Handling — Input params accepting API keys/passwords; credentials logged insecurely
⚡ AS‑011 Low DoS Resilience — No rate-limit, timeout, or retry config on network/exec tools
🔄 AS‑012 High Rug-Pull — Tool set changed between scans of the same version without a version bump (directory pipeline only)
👥 AS‑013 High/Medium Tool Shadowing — Duplicate or near-duplicate tool name hijacks calls intended for a trusted tool
ℹ️ AS‑014 Info Dependency Inventory Unavailable — MCP server exposed neither metadata.dependencies nor a repo_url, so supply-chain coverage is limited and must be treated as incomplete
⚠️ AS‑015 Medium/High Suspicious NPM Lifecycle Script — npm dependency publishes preinstall / postinstall / similar install-time scripts; severity rises for remote-fetch or inline-execution patterns
🚨 AS‑016 Critical Suspicious NPM IOC Dependency — published npm metadata or install-time scripts reference a known malicious IOC package, domain, URL, or reviewed script pattern such as plain-crypto-js, even if the top-level package name is new
⚠️ AS‑017 Medium Suspicious Data Exfiltration Description — tool description explicitly suggests sending user data, content, or conversation history to external / remote endpoints, without classifying it as prompt injection
ℹ️ AS‑018 Info Embedded MCP Server Detected — source-level MCP SDK usage was found, but tools could not be enumerated from a manifest or live handshake, so manual review is still required
🔓 AS‑019 High Unauthenticated MCP Route Exposure — embedded MCP HTTP routes expose the same handler without equivalent authentication middleware

Full details → docs/methodology.md


🤖 AI Agent Integration

Let your AI agent scan its own tools. Add ToolTrust as an MCP server in your .mcp.json or claude_desktop_config.json:

{
  "mcpServers": {
    "tooltrust": {
      "command": "npx",
      "args": ["-y", "tooltrust-mcp"]
    }
  }
}

This gives your agent five security tools:

Tool Description
tooltrust_scan_config Scan all MCP servers in your .mcp.json or ~/.claude.json in parallel
tooltrust_scan_server Launch and scan a specific MCP server
tooltrust_scanner_scan Scan a JSON blob of tool definitions
tooltrust_lookup Look up a server's trust grade from this directory
tooltrust_list_rules List all security rules with IDs and descriptions

Claude Code users: ask your agent to run tooltrust_scan_config to audit every MCP server in your project in one shot.


🤝 Contribute

Request a scanopen an issue with the tool's public URL and version.

Dispute a finding — open an issue referencing the finding ID (e.g. AS-002).

Integrate ToolTrust Scanner — see docs/dev.md for the data pipeline and schema spec.


📛 Add to your README

If your MCP server was audited and earned a grade, add our badge to your repo:

Grade A (recommended) — copy this into your README:

[![ToolTrust Grade A](https://raw.githubusercontent.com/AgentSafe-AI/tooltrust-directory/main/docs/badges/grade-a.svg)](https://github.com/AgentSafe-AI/tooltrust-directory)

Other grades — replace grade-a with grade-s, grade-b, grade-c, grade-d, or grade-f:

Grade Badge
S Grade S
A Grade A
B Grade B
C Grade C
D Grade D
F Grade F

Badges link to this directory. Generate SVGs locally: go run ./cmd/badge


⚙️ Automation

The registry table above is kept up to date by a daily GitHub Actions workflow:

.github/workflows/daily-audit.yml   ← cron 00:00 UTC + manual dispatch

Each run:

  1. Discovers popular MCP servers via GitHub Search (50+ stars) plus Smithery-native servers (10+ uses)
  2. Scans new/updated tools with ToolTrust Scanner + OSV supply-chain analysis
  3. Publishes updated reports to data/reports/ and regenerates this README

Licensed MIT. Scanner engine: ToolTrust Scanner.

About

Trust layer for AI Agents. A curated registry of secure tools and MCP servers with A-F risk grading.

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages