Independent audit · Model Context Protocol servers
Which MCP connectors put instructions for the model into text the model was told was data.
Every entry links to the raw payload it came from and a command that reproduces it without credentials. Nothing is published until a person has reproduced it from a committed snapshot — and that applies to a clean result exactly as it does to a bad one.
9 servers scanned so far. Servers under review are not named: a scan result is not a finding until a person has reproduced it and decided to publish.
Published entries
How to read a grade
The number is a penalty
It counts problems found, so 0 is the best possible result and there is no upper bound — a server can score 300. Points accrue by severity: concealment 40, model-directed 20, promotional 8. Findings in tool results count 1.5×, and the nth hit of one rule counts half the last, so a verbose server does not outrank a deceptive one.
The letter is a band
A is 0, B under 10, C under 25, D under 50, F at 50 or above. It is not a second opinion, and grade A never means a server is clean — only that nothing matched in what could be seen.
Covert vs. disclosed
Disclosed is a product fact the model can present as data (“advanced search requires the Business plan”). Covert is that text arriving next to an instruction telling the model to relay it. Only the second is injection, and they are never graded alike.