Scan from the toolbar
Paste any remote MCP server URL into the toolbar popup and get its A–F security grade in seconds — the same reproducible grade the MCPGrade scanner serves, without leaving the page you are on.
Browser Extension
MCPGrade puts a reproducible A–F security grade for any Model Context Protocol server one click away. Scan from the toolbar, catch MCP endpoints as you browse GitHub and docs, and know whether a server is safe to connect — before it ever reaches your agent's context.
The extension is built and in final review — it is not yet published to a web store. This page links to the listing the moment it goes live.
What it does
Every capability ties back to a real, shipping MCP security surface — the extension just brings it into the tab you are working in.
Paste any remote MCP server URL into the toolbar popup and get its A–F security grade in seconds — the same reproducible grade the MCPGrade scanner serves, without leaving the page you are on.
As you browse GitHub, documentation sites and MCP directories, the extension spots Model Context Protocol endpoints on the page and shows their grade inline, so you see risk before you ever wire a server into an agent.
Highlight or hover a server URL, choose “Scan with MCPGrade” from the context menu, and the grade opens instantly. No copy-paste, no switching tabs — assessment where you already are.
Found a server worth tracking? Submit it to the public MCP server directory in a single click, so its grade is scanned, versioned and searchable for everyone else too.
No sign-up, no licence key, no paywall. Install it and it works — the extension is free and open, exactly like the scanner and directory behind it.
Every grade is stamped with the exact methodology version that produced it, so what you see in the toolbar matches the full report on the site and can be recomputed by hand.
How it works
Install it once, then grade servers as you go. The extension is a shortcut to the same engine behind the MCP security scanner.
Add MCPGrade to your browser. It sits quietly in the toolbar until you ask it to scan — nothing runs in the background, and there is no account to create.
Open the popup and paste a server URL, right-click a link, or just browse — the extension auto-detects MCP endpoints on the page and surfaces their grade inline.
See an A–F grade computed against known MCP abuse patterns, with a link straight to the full report and the open methodology behind every point.
Every point in a grade is spelled out in the open MCPGrade methodology, so a toolbar grade and the full report always agree.
Why trust it
A security signal is only worth acting on if you can see how it was produced. The grade behind the extension is free, first-party and reproducible.
Built by an independent security research lab, not a vendor selling you the fix. The grade is not derived from Shodan, Censys or any third-party rating service — the extension runs the same first-party MCP assessment the scanner does.
A grade is a (score, algorithm version) tuple. The extension shows the version alongside the letter, so a grade is never a black box — change the algorithm and the version changes with it.
The extension sends the MCP server URL you ask it to scan, and nothing else. It does not read, collect or transmit your browsing history, page contents or personal data.
Read the full grading methodology and the scanning policy that governs exactly what a scan does and does not do.
FAQ
Yes, completely. There is no account, no licence key and no paid tier. The extension, the scanner and the MCP server directory behind it are all free and open to use.
Only the MCP server URL you choose to scan. When you run a scan the extension sends that single URL to the MCPGrade scanner to grade it. It does not read, store or transmit your browsing history, page contents, cookies or any personal data.
MCPGrade is a Chromium extension, so it targets Chrome and other Chromium-based browsers such as Edge, Brave and Arc. It is built but not yet published to a web store — this page will link to the listing the moment it goes live.
The extension shows the same grade as the MCPGrade scanner: an A–F score computed against known MCP abuse patterns — tool poisoning, prompt injection, data exfiltration and excessive permissions. Every check, its OWASP MCP Top-10 mapping and its point value are published in the open methodology, and each grade is stamped with the methodology version that produced it.
No. The grade comes from the read-only MCPGrade scanner, which enumerates and statically analyses a server’s advertised tools, resources and prompts. It never calls a tool, never authenticates, and honours 401, robots.txt and rate limits. The extension itself only requests the grade.
Yes. Use the one-click submit action to add your server to the public directory. It is then scanned, graded and listed alongside every other server, and you can embed its live grade badge in your README.
Get the grade
Grade a server in your browser now, or explore the same engine on the web: run the MCP security scanner and browse the graded server directory.
Free · No account · Only scans the URLs you choose