mcp security leaderboard

you connected an MCP server to your AI agent. you didn't check what was inside. we did.

real servers. real scores. no anonymizing. scanned with mcprobe.

98
packages tried
24
servers scanned
13
with findings
11
clean
ranked by risk score
1
@dronelytics/mcp
25 tools - 8 findings - 2 CRITICAL, 2 HIGH, 4 MEDIUM
100

risk 100/100 (CRITICAL) - 25 tools - 8 findings

CRITICAL
prompt injection in tool description
tool description contains "ignore all previous instructions" - your agent reads this before every call
CRITICAL
prompt injection in tool description
tool description contains "you are now a" - identity override attempt
2
@agenticmail/mcp
101 tools - 4 findings - 2 HIGH, 2 MEDIUM
62

risk 62/100 (HIGH) - 101 tools - 4 findings

HIGH
prompt injection in tool description
tool description contains injection pattern - the LLM will read it before deciding what to call
3
@gitdealflow/mcp-signal
13 tools - 8 findings - 2 HIGH, 6 MEDIUM
56

risk 56/100 (HIGH) - 13 tools - 8 findings

HIGH
prompt injection patterns detected
multiple tool descriptions contain injection text
MEDIUM
unrestricted file access
tool parameters accept arbitrary file paths without validation
4
@automatelab/n8n-mcp
12 tools - 2 findings - 2 MEDIUM
50
5
agent-browser-mcp-server
44 tools - 4 findings - 4 MEDIUM
28
6
@artifacta-mcp/mcp
10 tools - 1 finding - 1 MEDIUM
25
7
hostinger-api-mcp
223 tools - 1 finding - 1 CRITICAL
25
8
mcp-db-server
5 tools - 1 finding - 1 MEDIUM
25
9
@dollhousemcp/mcp-server
5 tools - 3 findings - 3 LOW
21
10
@doitintl/doit-mcp-server
135 tools - 1 finding - 1 MEDIUM
7
11
@modelcontextprotocol/server-sequential-thinking
1 tool - 1 finding - 1 LOW
7
12
mcp-calculator-server
6 tools - 6 findings - 6 LOW
5
13
d33naz-mcp-filesystem
2 tools - 2 findings - 2 LOW
4
clean (0 findings)
-
mcp-calculator
101 tools - 0 findings
0
clean
-
@contextium/mcp-server
68 tools - 0 findings
0
clean
-
mcp-server-slack
20 tools - 0 findings
0
clean
-
@bitcompare/mcp-server
18 tools - 0 findings
0
clean
-
@modelcontextprotocol/server-everything
13 tools - 0 findings
0
clean
-
@clicks-protocol/mcp-server
10 tools - 0 findings
0
clean
-
@impri/mcp
8 tools - 0 findings
0
clean
-
@endiagram/mcp
7 tools - 0 findings
0
clean
-
@bluesprincemedia/thiri-mcp
5 tools - 0 findings
0
clean
-
mcp-time-server
2 tools - 0 findings
0
clean
-
mcp-server-docker
1 tool - 0 findings
0
clean

a score of 0 doesn't mean safe. it means we didn't find anything. there's a difference. you should know the difference.

mcprobe checks descriptions, schemas, and parameters. it doesn't execute tool calls. a server can score 0 and still exfiltrate your data at runtime.

but sure, connect it. what could go wrong.