MCP Safety Index
An independent ranking of official MCP servers — hosted and local — scored on security, compliance, and protocol fidelity, so you know what you're really plugging your agents into before you connect it.
Two transports, one question: how much do you expose by connecting it. Hosted and local servers are scored on the same scale — each measured for what it can actually do wrong.
Security
Token/credential handling, authz enforcement, data over-sharing, and supply-chain integrity — how much damage a single tool call, or a single install, can do.
✓ OWASP MCP Top 10 · 5 measured live + 5 LLM-assessed, cited · Hosted: scope creep & over-sharing · Local: package integrity & process blast radius
Access & credentials
How access is granted and the credential is protected — and what it can reach if it leaks.
✓ Hosted: OAuth 2.1 + RFC 8707/9728/7591/7636/9207, walked live · Local: secret storage (keychain vs plaintext env) & blast radius under your user
Protocol fidelity
How faithfully the server implements the spec — capabilities, tool schemas, errors, transport — judged for today and for the July release.
✓ MCP 2025-06-18 & the 2026-07-28 RC · official conformance suite, run as an authorized client (HTTP or stdio)
Get an MCP scored
Drop the server URL and your email — we'll run it through the rubric and send you the results.
Ranking
| Server | Security | Auth | Protocol · 2025-06-18 | Overall |
|---|---|---|---|---|
1 Productboard https://mcp.productboard.com/mcp Hosted MCP ServerOAuth | 82 | 88 | 91 | 87B |
2 ElevenLabs local:elevenlabs-mcp Local · stdioAPI key | 76 | 81 | 91 | 83B |
3 Honeycomb https://mcp.honeycomb.io/mcp Hosted MCP ServerOAuth | 75 | 79 | 94 | 83B |
4 Airtable https://mcp.airtable.com/mcp Hosted MCP ServerOAuth | 76 | 81 | 88 | 82B |
5 Apify https://mcp.apify.com Hosted MCP ServerOAuth | 72 | 75 | 97 | 81B |
6 Make https://mcp.make.com Hosted MCP ServerOAuth | 72 | 81 | 91 | 81B |
7 Mixpanel https://mcp.mixpanel.com/mcp Hosted MCP ServerOAuth | 75 | 78 | 91 | 81B |
8 Stripe https://mcp.stripe.com Hosted MCP ServerOAuth | 75 | 75 | 94 | 81B |
9 Attio https://mcp.attio.com/mcp Hosted MCP ServerOAuth | 81 | 82 | 77 | 80B |
10 Calendly https://mcp.calendly.com Hosted MCP ServerOAuth | 76 | 76 | 88 | 80B |