tirekicker
First report in progress

We kick the tires on MCP servers so you don't have to.

The official registry lists more than 38,000 MCP servers and doesn't test whether any of them run. We start each one in a clean sandbox and record what happens: does it run, does it answer, and, as we re-test, has it changed.

Get the first report

Free. One email when it's published.

37.5%

of sampled registry servers never started.
Source: independent academic study, Sept 2026.

The problem

A listing tells you a server exists. It doesn't tell you it works.

Researchers drew 400 servers at random from an MCP registry and tried to start each one. 150 never started. Another 53 stopped to ask for credentials. Fewer than half completed a basic handshake. Read the study.

That figure is theirs, from a single snapshot, and we found nobody re-running it. Security scanners tell you whether a server looks malicious, which is a different question from whether it still runs this week. That is the gap we are working on, and our own numbers will replace this one when the first report is out.

Method

What we do to every server

The same procedure for every server, run by software, with the raw output kept. No judgement calls and no favourites.

  1. Install it cleanA throwaway container with no credentials, capped memory and a hard time limit. Nothing carries over between servers.
  2. Start itWe record whether it starts, how long it takes, and what it prints if it doesn't.
  3. Ask what it offersWe complete the protocol handshake and request its tool list, then fingerprint that list.
  4. Do it againOne run is a snapshot. Re-running on a schedule is what shows what broke, what recovered, and whose tools quietly changed.
What this does not tell you
  • We do not call any tool yet, so a server that starts may still have tools that fail.
  • A server that needs an API key is reported as "needs key", not as broken. We test without credentials.
  • This is not a security audit. Use a scanner for that, alongside this.
Independence

Nobody pays for a result

No paid rankingsA server's result is whatever the test recorded. It cannot be bought, sponsored or improved by asking.
Open method, raw outputThe procedure and the recorded output are published with every result, so you can check the work instead of trusting us.
Corrections in publicIf a result is wrong, we re-test and say so. Authors can request a re-test; the new result is published whatever it shows.