state of mcp tool safety

We scanned the tools your agent already trusts.

Every number below comes from a scan anyone can reproduce with a keyless API call. No editorial, no sample selection, no vendor sponsorship — this is the point: a trust layer paid by nobody it scans is the only kind worth having.

6
servers scanned
4
verified (67%)
0
critical + high findings
50%
graded A or better
what we found

0% of scanned servers carry hidden characters or instructions in the text your model reads — the exact attack surface Toolproof was built for. A human reviewing the same screen sees nothing; the model obeys every word.

TP-101 / TP-1020hidden characters or instructions in tool textsmuggled instructions the model reads but a human cannot see
TP-1040exposed credentials in plain texta key sitting in a description is already burned
TP-2023tools touching data with no authenticationpublic by accident, not by design
grade distribution
A+
3 (50%)
C
1 (17%)
—
2 (33%)
cite this

Every figure recomputes on request from live scans, so a citation stays honest. The methodology is the rule catalog — open source, inspectable, and the same code that produced these numbers.