nowfound

AI · February 5, 2026

RA

Risk Analysis Database of Every MCP Server

Hi HN, We’re building security tooling around agentic AI systems. Today, we're releasing our public MCP catalog with detailed risk analysis for every MCP server we've found on the internet: https://mcp.armor1.ai/mcp-directory We all love agents and the power that MCPs unlock: suddenly your AI assistant can query databases, manage files, call APIs, and interact with the real world. But when we started adopting MCPs ourselves, we kept running into the same nagging questions: Is this MCP safe? Where is my data actually going? Could it execute destructive actions? Is it…

Visit mcp.armor1.aiAlternativestop 13% of February 2026

In plain words

Risk Analysis Database of Every MCP Server is a public catalog that provides detailed security assessments for MCP (Model Context Protocol) servers found across the internet. It helps users evaluate whether specific MCP servers are safe to use by analyzing potential risks including data exposure, destructive actions, prompt injection vulnerabilities, and data exfiltration between servers. The tool is designed for organizations and developers adopting agentic AI systems who need to understand the security implications of connecting AI assistants to external tools and APIs.

written from the facts on this page · September 2026

From the sources

In the maker’s words, at launch

Hi HN, We’re building security tooling around agentic AI systems. Today, we're releasing our public MCP catalog with detailed risk analysis for every MCP server we've found on the internet: https://mcp.armor1.ai/mcp-directory We all love agents and the power that MCPs unlock: suddenly your AI assistant can query databases, manage files, call APIs, and interact with the real world. But when we started adopting MCPs ourselves, we kept running into the same nagging questions: Is this MCP safe? Where is my data actually going? Could it execute destructive actions? Is it susceptible to prompt injection? Can the LLM be tricked into calling something it shouldn't? And perhaps most concerning, can one MCP server influence the model and exfiltrate data meant for another? We looked for answers and found... not much. No comprehensive catalog or standardized risk assessment. Nothing that gave us confidence before connecting an MCP to our agents. So we built an MCP threat catalog and what we found was eye-opening. We built what we believe is the deepest risk analysis pipeline for MCP servers: • Provenance tracking: from an official source or community-contributed • MCP spec conformance: does it follow the protocol correctly, or are there deviations that could cause unexpected behavior • OWASP Top 10 for Agentic Apps: evaluate tool descriptions against the emerging threat categories specific to AI agents • Static source analysis: analyze source code for AI-specific vulnerabilities, not just traditional ones • CVE correlation: check dependencies against known vulnerabilities. • Behavioral risk patterns: tool definitions that could enable prompt injection, privilege escalation, or cross-server data theft What we found: • Hundreds of credential leaks: API keys, tokens, and secrets exposed in server configurations and code. • Dozens of MCP servers using known malicious packages: Not just vulnerable dependencies, but actually malicious ones. • Tools attempting context poisoning: MCP servers designed to subvert the LLM and steal information via memory manipulation, potentially exfiltrating data meant for other connected servers. We want everyone to realize the benefits of agentic AI, but not at the cost of security being an afterthought. So we're making this catalog free with no login, and we're committed to keeping it that way. This is still a WIP. Looking forward to your feedback on what we need to improve, what we got right, and what we should prioritize next.

More ai this month

the category →
  • I trained a 125M-parameter transformer to autocomplete piano performances in real time (~108 notes/sec on an iPhone 15). The idea is basically GitHub Copilot or Tabnine, except instead of prompting it with code, you prompt it by playing a few notes on a MIDI piano. The model then continues what you played, entirely on-device. The app is free if anyone wants to try it. Happy to answer questions about the model, training, Core ML, or the many things that didn't work.

    AI · 17d ago · simedw.com

  • Astute585

    Automate your B2B brand going viral, with new media creators

    AI · 18d ago · company-app.joinastute.com

  • Grok Bot547

    AI teammates that you can give real work to

    AI · 25d ago · x.ai

  • Hey HN, Henry from Cactus here! We previously released Cactus Needle, a 14MB agentic LLM for tool call, device use, and structured extraction for phones, wearables, smart homes, small robots and microcontrollers. We got really great feedback here, and have now incorporated the suggestions to release Needle 2. The whole model is a single 14MB binary that runs a full session in 28MB of RAM; 45m parameters at 2bit compression. Needle hits 500 tokens/sec decode speed on a Raspberry Pi 5, sits between 400-1,500 tokens/sec on VR devices like Meta Quest 3S and Apple Vision Pro, and ranges…

    AI · 26d ago · cactuscompute.com

  • Make your software self-driving

    AI · 30d ago · coldtea.ai

  • Soloop472

    Approval-first Agent OS for solo founders

    AI · 30d ago · soloop.io

Launched alongside, February 2026

the whole month →
  • Rork Max1,430

    Best AI for iOS apps. Website that replaces Xcode

    Life & fun · Feb 2026 · rork.com

  • happycapy1,367

    The agent-native computer, for the rest of us

    AI · Feb 2026 · happycapy.ai

  • SuperX902

    All-in-one growth OS for serious 𝕏 creators

    AI · Feb 2026 · superx.so

  • KiloClaw871

    Hosted OpenClaw. No Mac mini required.

    Dev tools · Feb 2026 · kilo.ai

  • Talk it out and feel better

    AI · Feb 2026 · lovon.app

  • Claude’s most advanced model for agentic tasks

    AI · Feb 2026 · anthropic.com