53 MCP servers scanned: 36% graded D/F, mostly for over-permissioned scope

BrilliantSecret143 · reddit · 2026-09-16

The author ran OpenTrustBench across 53 public MCP servers and SDKs, producing graded results:

The pattern is clear: A-grade servers have minimal scope and zero findings; D/F grades are almost all excessive scope (shell, broad network, file deletion) — not necessarily vulnerabilities, just over-permissioned.

Every grade has a public report page with file:line evidence, and badges link back for verification. The scanner is free, local-only, Apache-2.0: npx @opentrustbench/cli scan <github-url>.

Original post →

More from coding & agent

coding & agent channel →