Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts. New here? The Risk tab gives an at-a-glance composite grade per server; the Code Analysis tab shows what the static scanner found in published source.
Trends: ecosystem security posture over the last 90 days — new advisories and capability drift bucketed by day (historical), plus the current risk-grade mix (a point-in-time snapshot, not a trend).
New CVE advisories per day, by publication date (OSV.dev). Historical — each bar is the day the advisory was first published.
advisories / day
Capability-drift advisory events per day — permission escalations, tool changes, and lost verification detected by the capture path. Historical, by event date.
drift events / day
Current risk-grade mix across all graded servers (A safest → E highest exposure). This is a point-in-time snapshot, not a trend — historical grade migration isn't stored.
- grade A 14951
- grade B 8502
- grade C 2698
- grade D 379
- grade E 17