Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

All researchBrowse the catalogue
All research
ooruby IndexOriginal research, free to cite· Data as of 25 September 2026

ooruby Index #1: what 823 public MCP servers actually ship

Read file by file, what do the MCP servers people install from npm and PyPI actually ship?

What we found

50.9% of the 823 public MCP servers we read raised at least one finding. 24.8% start a process or evaluate code, and that is a floor rather than a rate: for 34.8% of them the scanner saw three files or fewer. 20.2% ship no licence file, and 159 of those 166 declare a licence in their registry metadata all the same.

MCP servers read
823
of 825 listed
Files read
62,875
median 5 a server
At least one finding
50.9%
419 servers
Checks run
6 of 11
that apply to an MCP server
Figure

Share of servers read with a finding, by check

No licence file20.2%No data statement17.1%Execution calls24.8%Credential strings3.2%

Computed when this page was built, from the same records every other page on this site shows, as of 25 September 2026. Nothing here is typed by hand.

CheckWhat counts as a findingServersShare of servers read
No licence fileNo LICENSE, LICENCE or COPYING file anywhere in the published package.16620.2%
No data statementNothing in the readme or manifest saying what it reads, writes or sends.14117.1%
Execution callsA child process, a shell call, eval or the Function constructor in the files read.20424.8%
Credential stringsA string shaped like an API key, token or private key in the files read.263.2%

Computed from the published records, as of 25 September 2026.

By registry

The same four checks, split by where the package is published. A Python wheel usually ships its source and an npm package often ships only compiled code, so read this as a difference in what each publishes as much as in how it is written.

RegistryServers readNo licence fileNo data statementExecution callsNone of the four
npm69120.5%16.4%22.9%51.8%
PyPI13218.2%21.2%34.8%34.8%

What the execution matches were

Servers with at least one match of each kind. Both rows are floors: each listing's report keeps its first four matches per check, so a later match of the other kind can go uncounted.

MatchServersShare of servers read
A child process or shell call19423.6%
eval or the Function constructor242.9%

How much of each package was read

Files read per server. The scanner does not enter folders named dist and build, which is where most npm packages put their compiled code, so a server in the first row was usually read for its manifest, readme and licence and little else.

Files readServersShare
1 to 328634.8%
4 to 1023628.7%
11 to 10024129.3%
More than 100607.3%

The rubric, and what this edition ran

Every check in rubric 1.0 that applies to an MCP server. A server with no finding has passed nothing in the rows marked not run.

CheckThis edition
No shipped credentialsRun, reported as a count only
Dependency advisoriesRun, recorded as an inventory
Behaviour matches the manifestNot run
Declared egressRun, recorded as an inventory
Data handling disclosedRun
Licence and provenanceRun
Transparency self-certificationNot run
URL handlingNot run
Tool description integrityNot in these figures; a separate nightly scan reads tool descriptions
Command execution is boundedRun
Authentication enforcedNot run
The data

Download the per-server data (CSV)

One row per server read: its package and pinned version, when it was read, how many files were read, the licence its registry metadata declares, and what three of the four checks found. The credential check is left out and reported only as a total.

Download CSV
How we computed it
  • Population: every MCP server the catalogue lists, 825 in all, 692 published to npm and 133 to PyPI. This is a census of the catalogue, not a sample of it; 823 were read and 2 were not (see the limitations).
  • Each package was downloaded from its registry at the exact version its listing pins, and unpacked without running anything. PyPI files were checked against the sha256 digest the registry publishes before a byte was read. Nothing in any package was executed.
  • Each package was read by the ooruby scanner in its offline mode, which runs 6 of the 11 rubric checks that apply to an MCP server. 4 of those can raise a finding; the other 2, declared egress and dependency manifests, are recorded as an inventory and never counted as one.
  • Comments are blanked before the execution and credential checks match, so code a maintainer has commented out does not count against a server.
  • A server counts once per check, however many matches it has. Every share is of the 823 servers read, to one decimal place.
  • Rubric version 1.0. Every figure on this page and every row in the file is computed when the site is built, from the same scan records each listing page shows. None is typed by hand.
What this CANNOT tell you
  • This edition ran 6 of the 11 checks that apply to an MCP server. The other 5 are not in these figures: Behaviour matches the manifest, Transparency self-certification, URL handling, Tool description integrity and Authentication enforced. A server with no finding here has passed nothing it was not checked for. Tool descriptions are read by a separate nightly scan whose results appear on each listing page; URL handling and authentication need a run, not a read of the files.
  • The scanner does not enter folders named dist and build, which is where most npm packages ship their compiled code. For 286 servers (34.8%) it read three files or fewer, usually the manifest, the readme and the licence. On those servers the execution and credential checks saw little or none of what actually runs, so their figures are floors, and a clean result means only that nothing was found in what was read.
  • An execution call is not a defect. Plenty of servers exist to run commands, and the rubric's real question, whether execution is bounded to a fixed set of named commands, needs a reading of each call that this edition does not make. Read that row as a map of where to look.
  • A missing licence file is a fact about the package as published, not about the project: a repository can carry a licence its package leaves out. 159 of the 166 servers with no licence file declare one in their registry metadata.
  • The data-handling check asks whether the readme or manifest says anything about data, privacy, permissions, network access or telemetry. It measures whether a statement exists, not whether it is true or complete, and a readme that mentions its network access in passing counts as a statement.
  • Credential-shaped strings are counted, never located. This study reports them as a total and leaves them out of the file; each affected listing says a match was found and no page says where. A shape match is not a confirmed live credential: test fixtures and example keys match too.
  • It is not a random sample of all MCP servers. The catalogue keeps places topic by topic, so it leans toward servers for things people search for, and it holds only servers that publish a package to npm or PyPI. Servers that publish no package are not in it.
  • It is one point in time. Each server was read at the version its listing pins, between 22 August 2026 and 25 September 2026, and its maker may have shipped since.
  • 2 listed servers are not in these figures: 1 because the package is larger than the scanner reads, where a clean read of the few source files beside the binaries would mislead, and 1 because the scan did not complete.
Citation

Cite as: ooruby, ooruby Index #1: what 823 public MCP servers actually ship, https://ooruby.com/research/ooruby-index-1, data as of 25 September 2026.

Free to quote, chart or republish with attribution. Every study links the row-by-row file its figures were computed from, so any number here can be checked without asking us.

Read next

What we do not checkHow to read a findings report without panickingTool poisoningSupply chain attack

Findings describe each package or repository as published, at the version or commit and on the date shown, read without running it. A finding is a reason to look closer, not an allegation against any maker. No figure here says that a server or an app with a finding is unsafe, or that one without a finding is safe.