ooruby Index #1: what 823 public MCP servers actually ship
Read file by file, what do the MCP servers people install from npm and PyPI actually ship?
50.9% of the 823 public MCP servers we read raised at least one finding. 24.8% start a process or evaluate code, and that is a floor rather than a rate: for 34.8% of them the scanner saw three files or fewer. 20.2% ship no licence file, and 159 of those 166 declare a licence in their registry metadata all the same.
- MCP servers read
- 823
- of 825 listed
- Files read
- 62,875
- median 5 a server
- At least one finding
- 50.9%
- 419 servers
- Checks run
- 6 of 11
- that apply to an MCP server
Share of servers read with a finding, by check
Computed when this page was built, from the same records every other page on this site shows, as of 25 September 2026. Nothing here is typed by hand.
| Check | What counts as a finding | Servers | Share of servers read |
|---|---|---|---|
| No licence file | No LICENSE, LICENCE or COPYING file anywhere in the published package. | 166 | 20.2% |
| No data statement | Nothing in the readme or manifest saying what it reads, writes or sends. | 141 | 17.1% |
| Execution calls | A child process, a shell call, eval or the Function constructor in the files read. | 204 | 24.8% |
| Credential strings | A string shaped like an API key, token or private key in the files read. | 26 | 3.2% |
Computed from the published records, as of 25 September 2026.
By registry
The same four checks, split by where the package is published. A Python wheel usually ships its source and an npm package often ships only compiled code, so read this as a difference in what each publishes as much as in how it is written.
| Registry | Servers read | No licence file | No data statement | Execution calls | None of the four |
|---|---|---|---|---|---|
| npm | 691 | 20.5% | 16.4% | 22.9% | 51.8% |
| PyPI | 132 | 18.2% | 21.2% | 34.8% | 34.8% |
What the execution matches were
Servers with at least one match of each kind. Both rows are floors: each listing's report keeps its first four matches per check, so a later match of the other kind can go uncounted.
| Match | Servers | Share of servers read |
|---|---|---|
| A child process or shell call | 194 | 23.6% |
| eval or the Function constructor | 24 | 2.9% |
How much of each package was read
Files read per server. The scanner does not enter folders named dist and build, which is where most npm packages put their compiled code, so a server in the first row was usually read for its manifest, readme and licence and little else.
| Files read | Servers | Share |
|---|---|---|
| 1 to 3 | 286 | 34.8% |
| 4 to 10 | 236 | 28.7% |
| 11 to 100 | 241 | 29.3% |
| More than 100 | 60 | 7.3% |
The rubric, and what this edition ran
Every check in rubric 1.0 that applies to an MCP server. A server with no finding has passed nothing in the rows marked not run.
| Check | This edition |
|---|---|
| No shipped credentials | Run, reported as a count only |
| Dependency advisories | Run, recorded as an inventory |
| Behaviour matches the manifest | Not run |
| Declared egress | Run, recorded as an inventory |
| Data handling disclosed | Run |
| Licence and provenance | Run |
| Transparency self-certification | Not run |
| URL handling | Not run |
| Tool description integrity | Not in these figures; a separate nightly scan reads tool descriptions |
| Command execution is bounded | Run |
| Authentication enforced | Not run |
Download the per-server data (CSV)
One row per server read: its package and pinned version, when it was read, how many files were read, the licence its registry metadata declares, and what three of the four checks found. The credential check is left out and reported only as a total.
- Population: every MCP server the catalogue lists, 825 in all, 692 published to npm and 133 to PyPI. This is a census of the catalogue, not a sample of it; 823 were read and 2 were not (see the limitations).
- Each package was downloaded from its registry at the exact version its listing pins, and unpacked without running anything. PyPI files were checked against the sha256 digest the registry publishes before a byte was read. Nothing in any package was executed.
- Each package was read by the ooruby scanner in its offline mode, which runs 6 of the 11 rubric checks that apply to an MCP server. 4 of those can raise a finding; the other 2, declared egress and dependency manifests, are recorded as an inventory and never counted as one.
- Comments are blanked before the execution and credential checks match, so code a maintainer has commented out does not count against a server.
- A server counts once per check, however many matches it has. Every share is of the 823 servers read, to one decimal place.
- Rubric version 1.0. Every figure on this page and every row in the file is computed when the site is built, from the same scan records each listing page shows. None is typed by hand.
- This edition ran 6 of the 11 checks that apply to an MCP server. The other 5 are not in these figures: Behaviour matches the manifest, Transparency self-certification, URL handling, Tool description integrity and Authentication enforced. A server with no finding here has passed nothing it was not checked for. Tool descriptions are read by a separate nightly scan whose results appear on each listing page; URL handling and authentication need a run, not a read of the files.
- The scanner does not enter folders named dist and build, which is where most npm packages ship their compiled code. For 286 servers (34.8%) it read three files or fewer, usually the manifest, the readme and the licence. On those servers the execution and credential checks saw little or none of what actually runs, so their figures are floors, and a clean result means only that nothing was found in what was read.
- An execution call is not a defect. Plenty of servers exist to run commands, and the rubric's real question, whether execution is bounded to a fixed set of named commands, needs a reading of each call that this edition does not make. Read that row as a map of where to look.
- A missing licence file is a fact about the package as published, not about the project: a repository can carry a licence its package leaves out. 159 of the 166 servers with no licence file declare one in their registry metadata.
- The data-handling check asks whether the readme or manifest says anything about data, privacy, permissions, network access or telemetry. It measures whether a statement exists, not whether it is true or complete, and a readme that mentions its network access in passing counts as a statement.
- Credential-shaped strings are counted, never located. This study reports them as a total and leaves them out of the file; each affected listing says a match was found and no page says where. A shape match is not a confirmed live credential: test fixtures and example keys match too.
- It is not a random sample of all MCP servers. The catalogue keeps places topic by topic, so it leans toward servers for things people search for, and it holds only servers that publish a package to npm or PyPI. Servers that publish no package are not in it.
- It is one point in time. Each server was read at the version its listing pins, between 22 August 2026 and 25 September 2026, and its maker may have shipped since.
- 2 listed servers are not in these figures: 1 because the package is larger than the scanner reads, where a clean read of the few source files beside the binaries would mislead, and 1 because the scan did not complete.
Cite as: ooruby, ooruby Index #1: what 823 public MCP servers actually ship, https://ooruby.com/research/ooruby-index-1, data as of 25 September 2026.
Free to quote, chart or republish with attribution. Every study links the row-by-row file its figures were computed from, so any number here can be checked without asking us.
Read next
Findings describe each package or repository as published, at the version or commit and on the date shown, read without running it. A finding is a reason to look closer, not an allegation against any maker. No figure here says that a server or an app with a finding is unsafe, or that one without a finding is safe.