MCP security, explained

Blog — page 3

Guides and deep-dives on MCP security — tool poisoning, toxic flows, supply-chain risk and how to scan a Model Context Protocol server before you connect it to your data.

July 23, 2026

Top 10 MCP Servers for API Development in 2026

A ranked, honest guide to the top MCP servers for API development in 2026 — from OpenAPI generators and REST testers to official vendor servers like Postman and Stripe — every one security-scanned with a published MCP Trust Score you can verify.

Read more →
July 23, 2026

Top 6 MCP Servers for Analytics & Monitoring in 2026

A ranked, security-first guide to the top MCP servers for observability in 2026. Every server has been scanned by MCP Trust Checker, so you see its deterministic A–F Trust Score and any high-severity findings alongside what it actually does.

Read more →
July 23, 2026

Top 10 MCP Servers for AI, Memory & Reasoning in 2026

A ranked, honestly-graded guide to the 10 best MCP servers for giving AI agents long-term memory, knowledge graphs and structured reasoning in 2026 — every one carrying a deterministic MCP Trust Score from our security scanner.

Read more →
July 23, 2026

Top 12 MCP Servers for AI & Agents in 2026

A ranked, honestly-graded guide to the best MCP servers for building AI agents in 2026 — covering search, long-term memory, documentation grounding, web ingestion, and orchestration. Every server carries a deterministic MCP Trust Score from our security scan.

Read more →
July 21, 2026

Introducing the MCP Trust Registry: a Security-Scanned Directory of MCP Servers

Every MCP directory tells you what a server does. The new MCP Trust Registry also tells you what it could do to you: every listed server is scanned by the same deterministic engine as the CLI and the free API — A–F Trust Score, capability blast radius, findings with evidence, and an embeddable badge.

Read more →
July 21, 2026

Introducing the MCP Trust Checker API: Scan Any MCP Server Over HTTP

A beginner-friendly guide to the new free MCP Trust Checker API: what it does, how to get a key, and how to scan any MCP server over a single HTTPS request — with copy-paste examples you can run in two minutes.

Read more →
July 20, 2026

MCP Security: The Complete 2026 Guide

A complete 2026 guide to MCP security: why tool descriptions are a new attack surface, the six main risk categories, and how to actually check a server before you trust it.

Read more →
July 17, 2026

How to Scan an MCP Server: Free Step-by-Step Guide

A step-by-step guide to scanning any MCP server for prompt injection, tool poisoning, and supply-chain risk with one free npx command — no signup required.

Read more →
July 14, 2026

MCP Tool Poisoning: Hidden Instructions That Hijack Agents

How hidden instructions in MCP tool descriptions hijack AI agents — the five attack shapes defenders should recognize, why "looks clean" is not clean, and how to detect poisoning deterministically.

Read more →
July 11, 2026

The Lethal Trifecta: How MCP Toxic Flows Exfiltrate Data

How the lethal trifecta assembles itself from benign MCP tools, why single-tool scanners miss cross-tool composition, and how a static toxic-flow graph proves the exfiltration primitive before an attacker uses it.

Read more →
July 8, 2026

MCP Rug Pulls: Supply-Chain Security for MCP Servers

How to vet npm and PyPI MCP servers before you install them — and how hash-pinning the tool surface and the artifact bytes catches a rug pull, even a same-version republish.

Read more →
June 10, 2026

MCP Servers Explained: Tools, Resources, and Prompts

An MCP server exposes exactly three primitives — tools, resources, and prompts. Here is what each one does, how the client and model use them, how capability negotiation works at connect time, and why tool descriptions are a security concern.

Read more →