← 피드로
MCPGrade (
Assessment Domain
Checks
Impact Weight
1. Transport Authentication
10 Checks
35%
2. Tool Scope & Authorization
12 Checks
30%
3. Input Validation & Injection
9 Checks
20%
4. Rate Limiting & Audit Logging
8 Checks
15%
BLUF / Executive Summary:
- Target: Model Context Protocol (MCP) HTTP/SSE Server endpoints.
- Discovery: Audit of 5,308 public MCP endpoints revealed 65% lack transport authentication.
- Solution: Introducing MCPGrade (
mcpgrade-1.4.0), a 39-check rating algorithm.
The Model Context Protocol (MCP) is now the standard for connecting AI models to tools and data. But as developers deploy MCP servers, security has lagged.
In our audit of 5,308 public MCP servers under SentinelReign research, over 3,450 servers (65%) exposed tool execution capabilities without authentication.
MCPGrade (mcpgrade-1.4.0) Matrix
Assessment Domain
Checks
Impact Weight
1. Transport Authentication
10 Checks
35%
2. Tool Scope & Authorization
12 Checks
30%
3. Input Validation & Injection
9 Checks
20%
4. Rate Limiting & Audit Logging
8 Checks
15%
Check out the full teardown and live A-F scanner at Andrax Pentester.
Written by Syed Zada Abrar — Founder & CEO of SentinelReign (https://sentinelreign.com).