MCP Servers

Model Context Protocol servers

MCP (Model Context Protocol) servers are the newest surface we track — roughly 19,000 registries and repositories — and the highest-consequence one: an MCP server is a set of tools you deliberately hand to an AI agent that can read your files, call your APIs, and spend your tokens. The Shai-Hulud npm worm explicitly targeted Claude Code and MCP configuration files, which is the pattern to worry about here. We score MCP servers on tool permissions, transport security, credential handling, and the packages they pull in at runtime.

Tracked campaigns: Shai-Hulud
  • Tool descriptions that instruct the agent to read ~/.ssh, .env, or browser credential stores
  • Servers that install or execute packages at runtime
  • Credential harvesting aimed at agent configuration files, as in Shai-Hulud

Security intelligence powered by Risky Plugins

19.8K
Extensions
19.8K
Analyzed

Risk Distribution

CRITICAL
130
HIGH
532
MEDIUM
4.5K
LOW
2.9K
MINIMAL
11.7K

Highest Risk Extensions

Recently Analyzed

Other Marketplaces