Security datasets for the MCP & agent economy
The MCP ecosystem has 21,643 registered servers — and almost nobody publishes measured, per-server security data. We scan it, verify it twice, and sell the result. Every number on this page comes from our own published scans.
The datasets
One-time purchase, instant download. Single-user license: use the data internally, build products and reports on it — just don't resell the raw dataset.
MCP Trust Database
- 94 servers: id, host, score 0-100, grade A-F
- 335 verified findings mapped to 7 flaw classes
- 44 critical findings (44 open handshakes)
- JSON + CSV, methodology & verification notes included
- Grade distribution: A 10 · B 13 · C 35 · D 27 · F 9
MCP Flaw Database
- 7 endpoint rules with measured prevalence (e.g. 91% missing CSP)
- 18 workflow-scanner rules (n8n / agent pipelines)
- OWASP Agentic AI Top 10 mapping per rule
- Why-it-matters + remediation for each rule
- The same engine that powers our public reports
Agent Economy Monitor
- 15,858 indexed x402 resources (catalog total)
- Price distribution: median $0.0045, max $5 in sample
- Scheme mix: exact vs batch-settlement
- MCP market size: 21,643 servers, 72,606 versions (arXiv 2609.14119)
- Monthly refresh cadence — October snapshot included free
Bundle: all three — $39 (save $18)
One download, everything above: mcp-security-dataset.zip (README, trust DB JSON+CSV, flaw DB, economy monitor, free samples for comparison).
Grade distribution & worst offenders (from the Trust DB)
This is the actual data you're buying — the same table our public MCP Security Report is built from.
8 lowest-scoring servers (preview)
| Registry ID | Host | Score | Grade | Findings |
|---|---|---|---|---|
| agency.goji/goji | mcp.goji.agency | 22 | F | 6 critical |
| ai.adoraads/beauty | mcp.adoraads.ai | 22 | F | 6 critical |
| ai.afmr/discovery | afmr.ai | 22 | F | 6 critical |
| ai.agentlookups/counterscript | rx.agentlookups.ai | 22 | F | 6 critical |
| ai.agentlookups/greenlight | solar.agentlookups.ai | 22 | F | 6 critical |
| ai.agentlookups/groundtruth | env.agentlookups.ai | 22 | F | 6 critical |
| ai.agentlookups/overassessed | overassessed.agentlookups.ai | 22 | F | 6 critical |
| ai.agentlookups/plumbline | contractors.agentlookups.ai | 22 | F | 6 critical |
Full 94-row table (JSON + CSV) in the dataset. Free 12-row sample above.
Schema — mcp_trust_db.json
Checkout — instant download
Two rails: pay-per-request for agents (x402, USDC on Base, no account) and a one-time email delivery for humans. Send payment, email the tx hash, download link lands in your inbox within hours.
Humans — USDC on Base
- Send the amount to
0xa1b8be63bde77ddc65d9ffe8a21a2a5f2c9ca6a8 - Fill the form below with the tx hash
- Download link delivered to your inbox (usually minutes, max 24h)
Agents — x402 pay-per-request
Machine-native checkout over the same rail our paid API uses. Your agent hits the endpoint, receives HTTP 402 with payment terms, pays USDC on Base, retries with the receipt — zero human in the loop.
Buying the datasets themselves by agent? Hit the trust endpoint to verify our data quality live, then email [email protected] with the payment receipt — delivery follows the same inbox.
Why trust this data
Every finding was confirmed by a second independent scan pass. Header findings were cross-validated with a second HTTP client on a sample — zero mismatches. No tool calls beyond initialize, no exploitation, findings reported as problem classes. The methodology, per-server table and rule details are public in the MCP Security Report, and our scoring API is live at /trust so you can verify a sample of the claims before paying.
Security-first, privacy-by-design: we store what you pay for and nothing else. No trackers, no third-party scripts on this site.
FAQ
{api_host} sit in the registry today, and we exclude or flag them.Not ready to buy? Verify us first
Read the public MCP Security Report (100 servers, methodology, per-class breakdowns), query our live trust API, or book a fleet scan on our services page. The datasets are the machine-readable layer under all three.