This repo hosts tooltrust.dev — the website and pre-scanned report data. If you want to scan your own MCP servers, go to tooltrust-scanner.
A public registry of AI agent tools, continuously scanned for prompt injection, data exfiltration, and privilege escalation by ToolTrust Scanner.
🚨 Supply-Chain Incident Coverage (March 2026) ToolTrust now detects and blocks confirmed supply-chain incidents including the LiteLLM / TeamPCP compromise and the malicious axios npm publish (
axios@1.14.1,axios@0.30.4). For npm-backed MCP servers, ToolTrust also scores dependency visibility, transitive lockfile evidence, lifecycle scripts, and IOC indicators such asplain-crypto-js.
Top 50 by popularity. View all 1760 tools → Full Directory · data/reports/ · docs/tools/
| Tool | Version | Popularity | Grade | Key Findings | Scanned |
|---|---|---|---|---|---|
| typescript-sdk | 2.0.0-beta.1 |
186.6M/mo | A | AS-014 |
Aug 5 |
| playwright-mcp | 0.0.78 |
26.4M/mo | C | AS-014 ×24, 🔑 AS-002 ×11, ⚡ AS-006 ×2, ⚡ AS-011 ×5 |
Aug 5 |
| ext-apps | 1.7.5 |
10.1M/mo | A | 🔑 AS-002, AS-014 ×3 |
Aug 5 |
| chrome-devtools-mcp | chrome-dev… |
8.2M/mo | C | AS-014 ×29, 🔑 AS-002 ×13, ⚡ AS-011 ×4, ⚡ AS-006 |
Aug 5 |
| context7 | 1.0.30 |
4.0M/mo | A | AS-014 ×2, 🔑 AS-002, ⚡ AS-011 |
Aug 5 |
| upstash-context7-mcp | 1.0.30 |
3.4M/mo | A | AS-014 ×2, 🔑 AS-002, ⚡ AS-011 |
Jul 17 |
| mcp-server-filesystem | typescript… |
2.2M/mo | A | 🔑 AS-002 ×14, AS-014 ×14, ⚡ AS-011 |
Aug 5 |
| gemini-cli | 0.55.0-nig… |
1.9M/mo | A | AS-014 ×56, 🔑 AS-002 ×23, ⚡ AS-011 ×11 |
Aug 5 |
| cloudflare-containers | 0.3.2 |
1.6M/mo | A | 🔑 AS-002 ×5, ⚡ AS-011, AS-014 ×7 |
Jun 22 |
| inspector | 2-alpha-15 |
880.9k/mo | A | AS-014 ×2 |
Aug 5 |
| notion-mcp-server | 2.5.0 |
724.2k/mo | A | 🔑 AS-002 ×24, ⚡ AS-011 ×24, AS-014 ×24 |
Aug 5 |
| mcp-server-sequential-thinking | typescript… |
719.8k/mo | A | AS-014 |
Aug 5 |
| n8n-mcp | 2.68.0 |
579.8k/mo | A | AS-014 ×23, 🔑 AS-002 ×8, ⚡ AS-011 ×4 |
Aug 5 |
| mcp-server-github | typescript… |
551.4k/mo | A | 🔑 AS-002 ×24, AS-014 ×26, ⚡ AS-011 ×18 |
Aug 5 |
| cameroncooke-xcodebuildmcp | 2.3.2 |
468.8k/mo | A | AS-014 ×71, 🔑 AS-002 ×31, ⚡ AS-011 ×3 |
Jun 22 |
| firecrawl-mcp-server | 3.2.1 |
339.2k/mo | A | 🔑 AS-002 ×30, ⚡ AS-011 ×24, AS-014 ×25 |
Aug 5 |
| desktopcommandermcp | 0.2.47 |
300.3k/mo | B | 🔑 AS-002 ×19, AS-014 ×26, ⚡ AS-011 ×8, 📐 AS-003 |
Aug 5 |
| qwen-code | 0.21.6-pre… |
300.0k/mo | A | AS-014 ×54 |
Aug 5 |
| mcp-framework | mcp-framew… |
239.4k/mo | A | AS-014 ×3, 🔑 AS-002 ×2, ⚡ AS-011 |
Aug 4 |
| mcpb | 2.1.2 |
220.2k/mo | C | 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×10, ⚡ AS-006 |
Aug 5 |
| tavily-ai-tavily-mcp | 0.2.19 |
178.6k/mo | A | 🔑 AS-002 ×7, ⚡ AS-011 ×5, AS-014 ×5 |
Jun 22 |
| ms-365-mcp-server | 0.136.0 |
142.3k/mo | A | AS-014 ×188, 🔑 AS-002 ×229, ⚡ AS-011 ×182 |
Aug 5 |
| mcp-server-cloudflare | workers-ob… |
138.8k/mo | C | 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×2, ⚡ AS-006 |
Aug 4 |
| mcp-server-circleci | 0.19.1 |
134.5k/mo | B | 🔑 AS-002 ×13, ⚡ AS-011 ×11, AS-014 ×13, 📐 AS-003 ×2 |
Aug 5 |
| tavily-mcp | 0.2.21 |
127.7k/mo | A | 🔑 AS-002 ×7, ⚡ AS-011 ×5, AS-014 ×5 |
Aug 5 |
| circleci-public-mcp-server-circleci | 0.15.1 |
126.3k/mo | B | 🔑 AS-002 ×15, ⚡ AS-011 ×11, AS-014 ×16, 📐 AS-003 ×2 |
Jun 22 |
| n8n-nodes-mcp | 0.1.37 |
125.3k/mo | A | AS-014 ×27, 🔑 AS-002 ×21, ⚡ AS-011 ×9, 🗝️ AS-010 |
Aug 4 |
| mcp-server-time | typescript… |
89.2k | A | AS-014 ×2 |
Aug 5 |
| ruflo | 3.34.0 |
85.3k/mo | A | 🔑 AS-002 ×21, ⚡ AS-011 ×18, AS-014 ×27 |
Aug 4 |
| mcp-playwright | 1.0.12 |
82.2k/mo | C | 🔑 AS-002 ×6, AS-014 ×6, ⚡ AS-011 ×5, ⚡ AS-006 |
Aug 4 |
| mobile-mcp | 1.0.0 |
80.8k/mo | A | AS-014 ×23, 🔑 AS-002 ×5, ⚡ AS-011 |
Aug 5 |
| mcp-server-kubernetes | 4.1.2 |
79.8k/mo | A | AS-014 ×22, 🔑 AS-002 ×6, ⚡ AS-011 ×3 |
Aug 5 |
| exa-mcp-server | 3.4.0 |
79.5k/mo | A | 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×2 |
Aug 5 |
| worldmonitor | 2.5.23 |
78.5k | A | 🔑 AS-002 ×39, AS-014 ×39, ⚡ AS-011 ×5 |
Aug 4 |
| apify-mcp-server | 0.14.1 |
74.1k/mo | C | 🔑 AS-002 ×16, ⚡ AS-011 ×7, AS-014 ×16, ⚡ AS-006 ×2 |
Aug 5 |
| mcp-server-chart | 0.9.10 |
73.3k/mo | A | AS-014 ×26, 🔑 AS-002, ⚡ AS-011 |
Aug 5 |
| claude-task-master | 0.20.0 |
70.5k/mo | A | AS-014 ×14, 🔑 AS-002 ×9, ⚡ AS-011 |
Aug 4 |
| agent-reach | 1.5.0 |
65.8k | A | AS-014 ×4, 🔑 AS-002 ×3, ⚡ AS-011 ×2 |
Aug 4 |
| headroom | 0.33.0 |
64.8k | A | 🔑 AS-002 ×2, ⚡ AS-011 ×2, AS-014 ×2 |
Aug 5 |
| mcp-searxng | 1.14.0 |
64.7k/mo | A | 🔑 AS-002 ×3, ⚡ AS-011 ×3, AS-014 ×4 |
Aug 5 |
| mempalace | 3.6.0 |
58.0k | A | AS-014 ×3, 🔑 AS-002 ×2, ⚡ AS-011 |
Aug 4 |
| magic-mcp | 0.1.1-beta.1 |
49.1k/mo | A | 🔑 AS-002 ×4, AS-014 ×4, ⚡ AS-011 ×2 |
Jul 24 |
| anytype-mcp | 1.2.10 |
48.8k/mo | B | AS-014 ×18, 🔑 AS-002 ×7, ⚡ AS-011 ×3, 📐 AS-003 |
Aug 4 |
| mcp-server-mysql | 2.0.9 |
46.8k/mo | A | 🔑 AS-002 ×4, AS-014 ×4, ⚡ AS-011 |
Aug 4 |
| ai-engineering-from-scratch | 2026.07 |
44.6k | A | AS-014 ×3, 🔑 AS-002, ⚡ AS-011 |
Jul 29 |
| browsermcp | 0.1.3 |
44.1k/mo | A | 🔑 AS-002, ⚡ AS-011, AS-014 ×12 |
Aug 5 |
| kong | 3.9.3 |
43.9k | A | AS-014 |
Aug 5 |
| codebase-memory-mcp | 0.9.1-rc.1 |
37.3k | A | AS-014 ×9, 🔑 AS-002 ×6, ⚡ AS-011 ×2 |
Aug 4 |
| railway-mcp-server | 0.1.11 |
34.9k/mo | A | 🔑 AS-002 ×31, AS-014 ×36, ⚡ AS-011 ×13, 🗝️ AS-010 |
Jun 22 |
| kastalien-research-clear-thought-two | 1.2.0 |
33.3k/mo | A | AS-014 ×3, 🔑 AS-002 ×2, ⚡ AS-011 |
Jun 22 |
| Grade | Gateway Action | Description |
|---|---|---|
| S 🌟 | ALLOW |
Reserved for dynamic analysis |
| A | ALLOW |
Minimal risk. Safe for production agents. |
| B | ALLOW + rate limit |
Low risk. Minor issues, but generally safe. |
| C | REQUIRE_APPROVAL |
Moderate risk. Remediation recommended. |
| D | REQUIRE_APPROVAL |
High risk. Use only in isolated environments. |
| F | BLOCK |
Critical risk. Do not use in agentic pipelines. |
Full methodology: docs/methodology.md
ToolTrust Scanner check IDs referenced in all reports:
| ID | Severity | Detects |
|---|---|---|
| 🛡️ AS‑001 | Critical |
Tool Poisoning — Adversarial prompts hidden in tool descriptions (ignore previous instructions, <INST>) |
| 🔑 AS‑002 | High/Low |
Permission Surface — exec, network, db, fs beyond stated purpose; over-broad input schema |
| 📐 AS‑003 | High |
Scope Mismatch — Tool name contradicts its permissions (e.g. read_config with exec) |
| 📦 AS‑004 | High/Critical |
Supply Chain CVEs — Known CVEs in bundled dependencies via OSV |
| 🔓 AS‑005 | High |
Privilege Escalation — admin/:write OAuth scopes; sudo/impersonate in descriptions |
| ⚡ AS‑006 | Critical |
Arbitrary Code Execution — evaluate_script, _evaluate suffix, execute javascript, page.evaluate() patterns |
| ℹ️ AS‑007 | Info |
Insufficient Tool Data — Tool lacks a valid description or schema |
| 🚨 AS‑008 | Critical |
Known Compromised Package — Offline embedded blacklist of confirmed supply-chain attacks (LiteLLM 1.82.7/1.82.8, Trivy v0.69.4-v0.69.6, Langflow <1.9.0, Axios 1.14.1/0.30.4). Zero-latency, no network required. |
| 🔤 AS‑009 | Medium |
Typosquatting — Tool name within edit-distance 2 of a well-known MCP tool, suggesting impersonation |
| 🗝️ AS‑010 | Medium |
Secret Handling — Input params accepting API keys/passwords; credentials logged insecurely |
| ⚡ AS‑011 | Low |
DoS Resilience — No rate-limit, timeout, or retry config on network/exec tools |
| 🔄 AS‑012 | High |
Rug-Pull — Tool set changed between scans of the same version without a version bump (directory pipeline only) |
| 👥 AS‑013 | High/Medium |
Tool Shadowing — Duplicate or near-duplicate tool name hijacks calls intended for a trusted tool |
| ℹ️ AS‑014 | Info |
Dependency Inventory Unavailable — MCP server exposed neither metadata.dependencies nor a repo_url, so supply-chain coverage is limited and must be treated as incomplete |
Medium/High |
Suspicious NPM Lifecycle Script — npm dependency publishes preinstall / postinstall / similar install-time scripts; severity rises for remote-fetch or inline-execution patterns |
|
| 🚨 AS‑016 | Critical |
Suspicious NPM IOC Dependency — published npm metadata or install-time scripts reference a known malicious IOC package, domain, URL, or reviewed script pattern such as plain-crypto-js, even if the top-level package name is new |
Medium |
Suspicious Data Exfiltration Description — tool description explicitly suggests sending user data, content, or conversation history to external / remote endpoints, without classifying it as prompt injection | |
| ℹ️ AS‑018 | Info |
Embedded MCP Server Detected — source-level MCP SDK usage was found, but tools could not be enumerated from a manifest or live handshake, so manual review is still required |
| 🔓 AS‑019 | High |
Unauthenticated MCP Route Exposure — embedded MCP HTTP routes expose the same handler without equivalent authentication middleware |
Full details → docs/methodology.md
Let your AI agent scan its own tools. Add ToolTrust as an MCP server in your .mcp.json or claude_desktop_config.json:
{
"mcpServers": {
"tooltrust": {
"command": "npx",
"args": ["-y", "tooltrust-mcp"]
}
}
}This gives your agent five security tools:
| Tool | Description |
|---|---|
tooltrust_scan_config |
Scan all MCP servers in your .mcp.json or ~/.claude.json in parallel |
tooltrust_scan_server |
Launch and scan a specific MCP server |
tooltrust_scanner_scan |
Scan a JSON blob of tool definitions |
tooltrust_lookup |
Look up a server's trust grade from this directory |
tooltrust_list_rules |
List all security rules with IDs and descriptions |
Claude Code users: ask your agent to run tooltrust_scan_config to audit every MCP server in your project in one shot.
Request a scan — open an issue with the tool's public URL and version.
Dispute a finding — open an issue referencing the finding ID (e.g. AS-002).
Integrate ToolTrust Scanner — see docs/dev.md for the data pipeline and schema spec.
If your MCP server was audited and earned a grade, add our badge to your repo:
Grade A (recommended) — copy this into your README:
[](https://github.com/AgentSafe-AI/tooltrust-directory)Other grades — replace grade-a with grade-s, grade-b, grade-c, grade-d, or grade-f:
| Grade | Badge |
|---|---|
| S | |
| A | |
| B | |
| C | |
| D | |
| F |
Badges link to this directory. Generate SVGs locally: go run ./cmd/badge
The registry table above is kept up to date by a daily GitHub Actions workflow:
.github/workflows/daily-audit.yml ← cron 00:00 UTC + manual dispatch
Each run:
- Discovers popular MCP servers via GitHub Search (50+ stars) plus Smithery-native servers (10+ uses)
- Scans new/updated tools with ToolTrust Scanner + OSV supply-chain analysis
- Publishes updated reports to
data/reports/and regenerates this README
Licensed MIT. Scanner engine: ToolTrust Scanner.
