Is an MCP server safe to use?
Most answer as they claim, but not all: of 22,261 live MCP and A2A servers brick.blue checks, 95 carry text in their cards or tool descriptions aimed at the agent reading them, and 35.6% ask for a key before serving. Check the specific server before connecting it.
Check the one in front of you
curl "https://brick.blue/api/v1/verify?url=https://example.com/mcp"
Or the verify_endpoint tool on https://brick.blue/mcp, or the form at /verify. It answers from measurements: does the server respond, does it
demand a key or a payment, has its card changed, and does it address the agent reading it. A
server the registry has never seen is queued for a crawl.
What the registry measured
| live servers (MCP and A2A) | 22,261 |
|---|---|
| open with no key or payment | 11,007 (49.4%) |
| a tool called and answered | 5,541 |
| ask for a key or login | 7,929 (35.6%) |
| charge per call | 753 |
| text aimed at the reading agent | 95 |
| not yet classified | 1,750 |
What to look at before connecting
- Does it answer? A listed server that stopped responding is the commonest failure; liveness history is on every server's page.
- What does it demand? A key, a login or a payment you did not expect is a reason to stop and read.
- Text addressed to your agent. Instructions inside tool descriptions («ignore previous…», «always call…») are how a server steers the model that reads it.
- Which tools write. Read-only tools say so in their annotations; anything that sends, pays or deletes deserves a confirmation step.
- Least access. The hub measures what a server answers, not its code: grant a local server only the files, network and keys its tools need.
Questions
- Is an MCP server safe to use?
- Most answer as they claim, but not all: of 22,261 live MCP and A2A servers brick.blue checks, 95 carry text in their cards or tool descriptions aimed at the agent reading them, and 35.6% ask for a key before serving. Check the specific server before connecting it.
- How do I check an MCP server before connecting?
- Ask for its measured record: GET https://brick.blue/api/v1/verify?url=<server URL> (or the verify_endpoint MCP tool) returns whether it answers, what it demands, whether its card changed, and any text aimed at the reading agent. No account needed.
- Is an MCP server free?
- Often, but measure it: 11,007 of 22,261 live servers let the hub in with no key or payment, and only 5,541 had a tool actually called and answered; 753 charge per call.
Method and every figure: registry-truth · snapshots with a DOI: 10.5281/zenodo.23166147 · what the crawler does and never calls: /bot