A grade is a (score, algorithm) tuple
Every grade is stamped with the exact methodology version that produced it, so a badge stays reproducible and nothing is a black box. Change the algorithm and the version changes with it.
Platform
Security tooling built for modern researchers and professionals. Join the waitlist to hear when early access opens — honest status only, no fake product demos. What is already live is live; what is planned is labelled as planned.
Live today
The platform vision is honest about what is still in development — but the security work behind it is already in production. As an independent security research lab and the authority on Model Context Protocol (MCP) security, Andrax Pentester runs a live scanner that grades any MCP server against known abuse patterns, a vetted server directory, and a published methodology for vetting a server before an agent connects to it.
Explore the MCP security scanner and hub
Connect to any remote MCP server by URL, run the real initialize handshake, enumerate every tool, resource and prompt, and grade it A–F for tool poisoning, prompt injection, data exfiltration and excessive permissions.
LiveA live, searchable directory of graded Model Context Protocol servers — filter by grade, transport, authorization and category, and open a full report for any of them.
LiveEvery check the grade runs is published: its OWASP MCP Top-10 mapping, spec reference, point modifier and grade cap. Anyone can recompute a grade by hand.
LiveA public, read-only REST API over the MCPGrade dataset: grade lookups, the server directory and facet counts. No key required, open CORS, 60 requests per minute free.
LiveA shields-style SVG security badge for any server that re-renders as its grade changes — drop it into a README, docs or landing page with a single <img> tag.
LiveAn ecosystem-wide data report built from every scan: how much of the landscape is graded, the A–F spread, and how many servers accept an agent with no authorization at all.
LiveThe product is only as good as the trust behind its numbers. Every grade the platform serves is designed to be reproducible, versioned and auditable — the opposite of a black-box score.
Every grade is stamped with the exact methodology version that produced it, so a badge stays reproducible and nothing is a black box. Change the algorithm and the version changes with it.
Scans are never overwritten. Each result is added to a permanent record, so a server’s grade over time is itself a dataset — the moat that a one-off scan can never build.
The scanner enumerates and statically analyses metadata. It never calls a tool, never authenticates, refuses private and metadata addresses, and honours 401 / robots.txt / 429. The full policy is public.
Read the full MCPGrade methodology and the scanning policy.
Anyone wiring an MCP server into Claude, Cursor, VS Code or a custom agent, who needs to answer "is this safe to connect?" before it ever reaches the model’s context.
Publishers who want a transparent, reproducible grade for their own server, a README badge that proves it, and a clear methodology showing exactly how to improve the score.
Practitioners assessing the AI-agent supply chain, who need structured, queryable data and a methodology they can audit rather than a marketing score.
Beyond MCP, the broader Andrax Security Platform is in development. These are the workflows being built next — labelled honestly with their current status, not presented as shipped.
Automated asset and service discovery
COMING_SOONWeb application security analysis workflows
COMING_SOONAPI spec parsing and security checks
COMING_SOONProfessional security report generation
COMING_SOONScheduled and event-driven security workflows
COMING_SOONMulti-user workspaces and role-based access
COMING_SOONComing soon
Get notified when the platform enters beta and early access becomes available. In the meantime, everything under MCP security and the developer API is already free to use.
We respect your privacy. No spam.