Every server in the directory carries a trust score from 0 to 100 and an A–D grade. The score is built from public signals only. It is not a penetration test and not a code audit — it tells you where a server sits before you invest time in your own review.
The four signals
| Signal | Weight | What earns full marks |
|---|---|---|
| Authentication | 30 | Server supports scoped, revocable auth (OAuth 2.1 or equivalent); auth is the default, not an opt-in flag. |
| Maintenance | 25 | Commits and releases within the last ~60 days; more than one active maintainer. |
| Known CVEs | 25 | No open, unpatched advisories; any past CVE was fixed promptly. |
| Transport safety | 20 | Defaults to a transport appropriate to its exposure; HTTP options carry TLS; no shelling out to helper binaries on untrusted input. |
Score bands: A 85–100, B 70–84, C 50–69, D below 50.
What the grade does not tell you
- Whether the server is safe for your specific data — that depends on the credential you give it and what your agent is allowed to do with the results.
- Whether the current release has a bug that has not been disclosed yet.
- Anything about the hosted infrastructure of a remote server beyond what the vendor documents.
Re-scoring
Listings are re-checked when a server ships a major release, when a CVE is
disclosed against it, or on a rolling quarterly pass — whichever comes first. The
last_updated field on each listing shows the maintenance date we last verified,
not the date we scored it.
Disagree with a score?
Open an issue on the GitHub mirror with the signal you think is wrong and a public source. Scores move on evidence.
Need this built and hardened for you?
We build custom, security-reviewed MCP servers. Tell us what you need an agent to reach.
Start a conversation