security
Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.
45 CRITICAL
3626 HIGH
531 MEDIUM
1202 LOW
11 NONE
License hygiene: servers missing a license or carrying a strong-copyleft, non-commercial, or unrecognized one — informational, not part of the composite risk score.
- unrecognized borgmcpSEE LICENSE IN LICENSE
- unrecognized @visa/cliSEE LICENSE IN LICENSE
- unrecognized @testsprite/testsprite-mcpBUSL-1.1
- unrecognized @microsoft/github-copilot-app-modernization-mcp-serverSEE LICENSE IN LICENSE.txt
- unrecognized ue-mcpBUSL-1.1
- missing / unlicensed @atlassian-dc-mcp/common— no license declared —
- strong copyleft @kernlang/mcp-serverAGPL-3.0
- unrecognized @ironbee-ai/devtoolsElastic-2.0
- missing / unlicensed @automattic/mcp-wordpress-remote— no license declared —
- unrecognized local-mcpSEE LICENSE IN LICENSE
- missing / unlicensed clavue— no license declared —
- missing / unlicensed @wcag-checkr/mcpUNLICENSED
- unrecognized @askexenow/exe-osSEE LICENSE IN LICENSE
- missing / unlicensed playwright-mcp— no license declared —
- missing / unlicensed agnost— no license declared —
- unrecognized browser-devtools-mcpElastic-2.0
- strong copyleft @aikidosec/mcpAGPL
- unrecognized @microsoft/workiqSEE EULA
- strong copyleft skillfishAGPL-3.0
- unrecognized @ironbee-ai/cliElastic-2.0
- unrecognized context-modeElastic-2.0
- missing / unlicensed @bike4mind/cliUNLICENSED
- non-commercial / non-OSI @taazkareem/clickup-mcp-serverProprietary
- missing / unlicensed @claude-flow/mcp— no license declared —
- unrecognized @sentry/mcp-serverFSL-1.1-ALv2