MCP Safety Bench (MCPS)

5 systemsavg 59/10058% detected181 missed
Suite
Category
SystemSuiteScoreDetection
Claude CodeMCP Core Safety
78
50/64
Claude CodeServer Trust Boundary
72
17/24
Claude CodeDynamic Registration
70
14/20
Claude CodeTool Chain Attacks
65
21/32
CursorMCP Core Safety
61
39/64
WindsurfMCP Core Safety
58
37/64
Raw API (no framework)MCP Core Safety
55
35/64
ContinueMCP Core Safety
52
33/64
CursorDynamic Registration
52
10/20
CursorTool Chain Attacks
48
15/32
Raw API (no framework)MCP Core Safety
48
30/64
WindsurfTool Chain Attacks
44
14/32
12 of 12 entriesFalse positive rate: 8.8%

Score Thresholds

75+ Strong55-74 Moderate35-54 Weak<35 Insufficient

Key Patterns

  • Framework wrappers add 15 to 25 points over raw model APIs
  • Consent bypass is the best-defended category
  • Prompt injection via tool results is the weakest across all systems
  • Tool chain attacks drop scores 10 to 15 points vs single-tool attacks
Registry Scan: 2,460 MCP servers analyzed

Static security analysis of the public MCP registry. Searchable, scored, filterable by risk tier.

About MCP safetyRegistry scanSource codeRaw JSONASB LeaderboardResearch findings