MCP servers that publish no source
9,915 servers in the official MCP registry are only an address: no package to install and no repository to read. This site cannot verify any of them, because verifying starts with reading. They are listed here anyway, free, with the one thing that can be measured from outside: whether they answer.
- Listed
- 9,915
- Answered their last test
- 2,704
- Declare a key
- 1,901
- Not tested yet
- 4,872
What a test sends. The MCP handshake, then a request for the tool list. No key, no data of yours, and never a call to a tool.
What it cannot tell you. What a tool does when called, where your data goes, or who runs the server. An answer means the door opened, not that it is safe to go in.
Servers that want a key can only be tested as far as the door. That is recorded as asking for a key, which is not a failure.
2,404 servers match · page 12 of 61 · ordered by observable signals, from the table as read at 7 Oct, 20:15 UTC (how)
Moved toward the catalogue
A server that declares its source or a package leaves this list, because the catalogue can read it. Its page stays, dated, and says what happened.
- Agent Utility Suite (x402)Now publishes source, not yet read · since 7 October 2026
- AskOneNow publishes a package, not yet read · since 7 October 2026
- Collar Guardrail — Pre-Trade Risk LayerNow publishes source, not yet read · since 7 October 2026
- SoundingNow publishes source, not yet read · since 7 October 2026
- ContinuityNow publishes source, not yet read · since 7 October 2026
- AalyNow publishes source, not yet read · since 7 October 2026
What is listed, and what is not
- Every server in the official MCP registry, at its latest version, that offers a remote endpoint and no package.
- That declares no source repository. One that does can be read, and belongs in the catalogue, on its terms.
- That the registry marks active, with at least one https address on a host name.
- Nothing is left out for being unpopular, new, or failing a test. The default order counts the latest test as one input among four, set out below; it is not a verdict on the server.
Registry servers with an endpoint, not listed here
- Publishes a package
- 2,003
- Declares a source repository
- 13,258
- No https endpoint on a host name
- 65
- A deprecated or deleted registry entry
- 108
Last full pass of the registry completed 19 hours ago. Source: the official MCP registry, registry.modelcontextprotocol.io.
How the order is decided
The default order weighs what can be seen from outside a server that publishes no source. Each input below is worth the points shown, out of 100. Three of them are held at zero for every entry here, because what they need does not exist for these servers, so the most any entry can reach is 60. Ties go to the entry updated most recently in the registry, then to the name. Only active registry entries are listed at all.
| Input | Points | How it is read here |
|---|---|---|
| Source published | 20, held at 0 | No entry here publishes source: that is what puts it in this directory. |
| Licence stated | 10, held at 0 | With no files, there is nothing for a licence to be stated in or held against. |
| Advisory state | 10, held at 0 | Advisory databases index packages, and these entries publish none, so there is nothing to look up. |
| Auth declared | 15 | The registry entry names a required or secret header: a key or a token. |
| Latest connection test reached it | 20 | The latest test had its handshake answered, or was told that a key is needed. |
| Changed in the registry recently | 15 |
Why an address alone is not enough to go on
What audits of AI-built software have found when somebody did read it. Each figure is as its publisher states it, with the sample it was drawn from.
More than 2,000 high-impact vulnerabilities, 400 or more exposed secrets and 175 instances of exposed personal data, across publicly reachable apps built on vibe-coding platforms.
- Sample:
- 5,600+ deployed apps, from Lovable, Base44, Create.xyz, Vibe Studio and Bolt.new
- Source:
- Escape, Methodology: how we discovered over 2k high-impact vulnerabilities in apps built with vibe coding platforms , 29 October 2025
Escape's report page counts 2,038 of these vulnerabilities, found across about 1,400 of the apps scanned.
None of the 15 apps had working CSRF protection (0 of 15). In the one app built around fetching a user-supplied link, every agent's build had SSRF (5 of 5). 69 vulnerabilities in all.
- Sample:
- 15 apps: five coding agents (Cursor, Claude Code, OpenAI Codex, Replit, Devin) each building the same three apps
- Source:
- Tenzai, Bad Vibes: comparing the secure coding capabilities of popular coding agents , 13 January 2026