53 MCP servers scanned: 36% graded D/F, mostly for over-permissioned scope
BrilliantSecret143 · reddit · 2026-09-16
The author ran OpenTrustBench across 53 public MCP servers and SDKs, producing graded results:
- Grade A (16): wong2/mcp-cli, pinecone, tavily, java/csharp/go/kotlin SDKs, terraform, elastic, qdrant, motherduck, e2b, mcp-fetch, mcp-sequentialthinking, mcp-time, etc.
- Grade B (13): github-mcp-server, playwright-mcp, registry, exa, sentry, prefect, grafana, slack, gmail, flux, clickhouse, mcp-git, mcp-everything, mcp-proxy
- Grade C (5) and Grade D/F (19): fastmcp, mcp-use, mongodb, stripe, blender, etc.
The pattern is clear: A-grade servers have minimal scope and zero findings; D/F grades are almost all excessive scope (shell, broad network, file deletion) — not necessarily vulnerabilities, just over-permissioned.
Every grade has a public report page with file:line evidence, and badges link back for verification. The scanner is free, local-only, Apache-2.0: npx @opentrustbench/cli scan <github-url>.
More from coding & agent
- How to shrink a multi-thousand-token extraction prompt without losing accuracy or speed — Slow-Business8503 · 2026-09-16
- Podcaster runs 50k-subscriber media business with AI agents as producers and marketers — hugobowne · 2026-09-16
- Dev runs a daily AI assistant inside his note vault, guarded by instruction files, skills and hooks — dSebastien · 2026-09-16
- Stop hunting for one smartest model: right model per job plus a learning loop compounds — PrajwalTomar_ · 2026-09-16
- TokenRhythm's loop: test for weak spots, weight next training batch toward them — PrajwalTomar_ · 2026-09-16
- Plane Launches Agents With BYOK Support; VC Claims 15 Militaries Run on It — JosephJacks_ · 2026-09-16