Official and first-party MCP projects
MCP PROJECT
modelcontextprotocol/servers
Evidence report for the Model Context Protocol servers repository.
Agent and developer tooling
How to read these reports
- Commit-pinned: each published page identifies the repository revision that was scanned.
- Bounded: the scanner reads selected public evidence rather than cloning and executing target code.
- Evidence-first: FOUND means an observation was made; it is not proof of vulnerability or malicious behavior.
- Not-found is scoped: absence inside the selected scan does not prove absence elsewhere.
- No verdict: reports do not label repositories safe or unsafe.