The 20 most popular MCP servers, scanned: what's actually in their tool descriptions
Pennyforge · dated evidence report, 2026-10-07 · follow-up to our dated MCP security timeline The Model Context Protocol has been around since November 2024, and it moved fast: the official TypeScript/Python SDK alone p
Pennyforge · dated evidence report, 2026-10-07 · follow-up to our dated MCP security timeline
The Model Context Protocol has been around since November 2024, and it moved fast: the official TypeScript/Python SDK alone pulled 242 million npm downloads last month (npm registry, checked 2026-10-07), and GitHub now lists 33,674 repositories tagged mcp-server. In May 2026 the U.S. NSA published "Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation" and said the protocol's "rapid proliferation has outpaced the development of its security model." We think that's fair. Here is a dated, method-transparent look at what the most popular MCP servers actually say and ship.
What we did
On 2026-10-07 we shallow-cloned 20 MCP server repositories: the official/reference servers (modelcontextprotocol/servers, 91.1k★; github/github-mcp-server, 33.4k★; ChromeDevTools/chrome-devtools-mcp, 53.1k★; microsoft/playwright-mcp, 37.9k★; upstash/context7, 62.8k★) plus the highest-starred third-party servers on the GitHub mcp-server topic (serena, context-mode, n8n-mcp, xiaohongshu-mcp, docker-android, Skill_Seekers, rea, ida-pro-mcp, hexstrike-ai, fastapi_mcp, mcp-use, Douyin_TikTok_Download_API, codebase-memory-mcp, and two smaller browser-automation servers).
We then ran a local static analyzer over every source file with five heuristic signals:
- F1 — instructions in tool descriptions. Patterns like "you must", "always", "prefer", "call this before…" — the "tool poisoning" family: behavior-steering text that agents read but humans usually don't.
- F2 — permission claims. Descriptions that mention your database, credentials, environment variables, tokens, files, or arbitrary commands.
- F3 — URL inventory. Every external domain referenced in source (docs, tests and code — not proof of live egress).
-
F4 — spec state. Markers of the pre-2026-07-28 protocol (
initializehandshake,Mcp-Session-Id) vs. the breaking 2026-07-28 revision (stateless_metaversion/capability exchange,server/discover). - F5 — maintenance. Last-push date from GitHub.
Upfront limitations: these are pattern matches on source, not runtime tests; a match can be a false positive (a legitimate "always" in a math description); stars measure attention, not adoption. We kept the analyzer and all match text for inspection.
Findings
1. Steering language is normal, including at the biggest official servers. 41 instruction-pattern matches across 8 of 20 repos. Verbatim examples (truncated):
-
ChromeDevTools/chrome-devtools-mcp(53.1k★): "…ALWAYS prefer this tool over multiple individual…" -
upstash/context7(62.8k★): "You MUST call this function before…" -
mcp-use/mcp-use(10.7k★): "Call this BEFORE using create_view for the first time." -
czlonkowski/n8n-mcp(23.0k★): "Always available — node info, search, validation, etc."
None of these are obviously malicious — steering hints are often useful. The point of the report-card format is to make the pattern visible before you connect, because the agent reads it either way.
2. Permission claims show up in descriptions, too. The reference repo's environment tool: "Returns all environment variables, helpful for debugging" — accurate, and worth knowing. n8n-mcp's diagnostic tool: "Include detailed debug information including full environment variables and API response details" — meaning a single diagnostic call can return your env to the model. That's a design choice; we flag it, not judge it.
3. Ten weeks after the breaking spec revision, almost nobody has migrated. The 2026-07-28 MCP revision removed the initialize handshake and Mcp-Session-Id sessions entirely — every request now carries protocol version and capabilities in _meta, and server/discover is the new front door. Ten weeks on: 0 of 20 repos show a clean new-spec signal, 11 show only old-spec markers, 4 show a mix, 5 are indeterminate (our extractor couldn't find direct RPC code — SDK-only usage). The 91k-star official reference repo is still old-spec. That's not a criticism; it's a migration status, dated today.
4. The ecosystem chur ns faster than its directories. Two of our original "top 20" slots were already 404s on 2026-10-07: the flagship punkpeye/fetch-mcp and puppeteer-mcp/puppeteer-mcp had been renamed or moved, so we substituted the top-ranked alternates (jae-jae/fetcher-mcp, 1.1k★; merajmehrabi/puppeteer-mcp-server, 486★ — last pushed 2025-03-14). Meanwhile tadata-org/fastapi_mcp (12k★) hasn't been pushed since 2025-11-24 — 14 months — and the first MCP scanner, Invariant Labs' mcp-scan (April 2025, the tool behind the "tool poisoning" term), is now snyk/agent-scan after acquisition. Security tooling is consolidating while the server ecosystem churns.
The full card (2026-10-07)
| repository | stars | last push | tool descs found | instruction matches | permission matches | spec state |
|---|---|---|---|---|---|---|
| modelcontextprotocol/servers | 91,066 | 2026-10-07 | 50 | 0 | 1 | old-spec |
| upstash/context7 | 62,771 | 2026-10-07 | 17 | 2 | 0 | mixed |
| ChromeDevTools/chrome-devtools-mcp | 53,083 | 2026-10-07 | 205 | 10 | 0 | old-spec |
| DeusData/codebase-memory-mcp | 45,993 | 2026-10-07 | 1 | 0 | 0 | old-spec |
| microsoft/playwright-mcp | 37,901 | 2026-10-07 | 1 | 0 | 0 | unknown |
| github/github-mcp-server | 33,432 | 2026-10-07 | 84 | 0 | 0 | mixed |
| oraios/serena | 30,084 | 2026-10-06 | 10 | 0 | 0 | old-spec |
| mksglu/context-mode | 25,615 | 2026-10-07 | 49 | 3 | 0 | old-spec |
| czlonkowski/n8n-mcp | 23,048 | 2026-10-06 | 215 | 7 | 3 | mixed |
| Evil0ctal/Douyin_TikTok_Download_API | 20,501 | 2026-10-02 | 1 | 0 | 0 | old-spec |
| xpzouying/xiaohongshu-mcp | 16,135 | 2026-10-05 | 7 | 0 | 0 | unknown |
| budtmo/docker-android | 15,946 | 2026-10-07 | 0 | 0 | 0 | unknown |
| yusufkaraaslan/Skill_Seekers | 15,114 | 2026-09-30 | 64 | 4 | 0 | old-spec |
| morluto/rea | 14,302 | 2026-10-07 | 60 | 11 | 0 | old-spec |
| mrexodia/ida-pro-mcp | 12,511 | 2026-09-26 | 2 | 0 | 0 | old-spec |
| 0x4m4/hexstrike-ai | 12,510 | 2026-08-03 | 0 | 0 | 0 | unknown |
| tadata-org/fastapi_mcp | 12,018 | 2025-11-24 | 1 | 0 | 0 | old-spec |
| mcp-use/mcp-use | 10,729 | 2026-10-07 | 182 | 4 | 0 | mixed |
| jae-jae/fetcher-mcp | 1,088 | 2026-01-14 | 6 | 0 | 0 | old-spec |
| merajmehrabi/puppeteer-mcp-server | 486 | 2025-03-14 | 6 | 0 | 0 | unknown |
What this is and isn't
It's one dated snapshot of 20 out of 33,674 tagged repos — a report card, not a ranking. Nothing here is a security verdict: a server with zero instruction matches can still be doing anything at runtime, and two of the critical CVEs in this space (mcp-remote, CVSS 9.6; MCP Inspector <0.14.1, CVSS 9.4) live in glue packages, not in the server repos we scanned. If you connect an agent to an MCP server for the first time, read its tool descriptions the way you'd read a nutrition label — that's the whole habit the report card is trying to build.
Status note as of 2026-10-07: heuristic static analysis on shallow clones; matches shown verbatim are truncations. Studio voice, not legal advice. Method: GitHub stars/push dates from the GitHub API, npm download counts from the npm registry, spec claims from the 2026-07-28 MCP specification changelog, CVE data from the NVD, NSA report citation from its media.defense.gov PDF.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.