Canopii Trust Index — Security-scored MCP servers

2 min read Original article ↗

Security scores for every MCP server.

Continuously scanned for tool poisoning, prompt injection, supply-chain, and credential risk. One score per version — before your agents connect.

Browse all 18,616 servers →

The MCP ecosystem, scored

Every server independently scanned and scored for security — here's how the ecosystem looks so far.

40%

Rated A · strong posture

4,968

Live-verified endpoints

Grade distribution

14,270 scored servers

A5,697 · 40%

B6,423 · 45%

C393 · 3%

D629 · 4%

F1,128 · 8%

4,295 unverifiable

Scan from your terminal

canopii is the open-source CLI behind the Trust Index — the same scoring engine, run locally against any GitHub repo, npm/PyPI package, or live MCP endpoint. Free, no account.

$npx canopii scan --github <repo>

Star on GitHub

Need API access?

Check any MCP server's security score from your own tools — CI gates, procurement review, agent allow-lists. Key-authenticated, rate-limited.

Top scored

Needs review

m3-memoryio.github.skynetcmdv2026.7.25.0

Local-first agentic memory — 100+ tools, 92% LongMemEval-S, hybrid search, GDPR, zero cloud.

openlibrary-mcp-serverio.github.cyanheadsv0.1.19

Search books and authors, fetch editions, browse subjects, and resolve cover images.

groupdocs-parser-mcpio.github.groupdocs-parserv26.7.3

MCP server for GroupDocs.Parser — extract text, images, metadata, tables, barcodes via AI.

groupdocs-total-mcpio.github.groupdocs-totalv26.7.3

MCP server for GroupDocs.Total — annotate, sign, convert, watermark, parse, redact documents via AI.

anodizerio.github.tj-smith47v0.23.0

Rust release tooling — drop-in GoReleaser parity + Rust extras.

inspeximusio.github.DanceNitrav1.63.0

Self-correcting agent memory + MCP server: recall, supersede/revert/review corrections, erasure.