On 2026-09-14 we asked every server in the official MCP registry with a public endpoint to
list its tools. 482 of 1,215 answered. These figures are what their manifests declare —
not what the products do.
477 of 477
declare no cap, no expiry and no way to switch a tool off.
MCP has no field in which to declare any of these. A product may provide such controls outside MCP, where a manifest cannot show them.
22%
106 servers declare at least one tool that sends, deletes or moves money.
Read from each tool’s own annotations where present, otherwise from its name. Each server page shows the basis for every tool.
58%
278 servers annotate none of their tools as read-only or destructive.
95 annotate every tool. Annotations are written by the server being described, and MCP clients are told not to rely on them.
14
Servers that declare tools which move money. None declares a spending limit.
Between them, 24 tools. MCP has no field for a spending limit either.
What the tools declare
A tool that can…
Servers
Share
Tools
Send something outward
53
11%
109
Delete or destroy something
76
16%
398
Move money
14
3%
24
Change something (write)
292
61%
1,390
Look something up (read)
399
84%
3,401
5,322 tools across 477 servers. 169 servers declare only lookups. Of the servers with a
delete, 52 marked a tool destructive themselves — MCP’s destructiveHint, which covers any
destructive update, not only removal — and 24 have one named for removal.
Servers that require sign-in. 733 of the 1,215 public endpoints did not answer an
anonymous request, most because they require sign-in, so they are not counted. These figures describe only the servers that
answer without it.
Servers without a public endpoint. Servers distributed as packages you run yourself were not probed.
Controls outside MCP. Token revocation, admin consoles, rate limits and audit logs can exist in a product
without appearing in its manifest.
Change over time. Every figure is a snapshot from 2026-09-14. Each server page is dated.
Answering this question about your own agent? The Agent Permission Audit
applies the same reading to your agent surface and delivers a dated report you can hand to a customer’s security review.
Buying one does not change any listing, score or ranking — see Independence.