SaSameKnowledge
live reportdeclared surfaceno LLM

What is visible on the public MCP tool surface?

This report summarizes what SaSame could observe from public endpoints and declared tool metadata. It separates measurable annotation and exposure facts from claims about vulnerabilities, intent or safety.

Endpoints observed
39,306
Enumerable servers
3,036
Declared tools
63,094
Updated
2026-08-02
Current finding

19.5% of state-changing tools on the enumerable surface publish NO machine-readable safety annotation — a calling agent cannot automatically tell a read from a write, delete, or payment before invoking them.

01

Annotation and discoverability

State-changing tools
24,544
Unlabeled state-changing
4,790
Unlabeled share
19.5%
Annotation coverage
83.3%

This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.

02

Declared capability landscape

One tool can match more than one class. Percentages describe the declared surface and therefore do not sum to 100%.

Payment / funds movementstate-changing class

7,884 tools

12.5% of declared tools
Code / command executionstate-changing class

1,656 tools

2.6% of declared tools
State change / write / deletestate-changing class

12,807 tools

20.3% of declared tools
Identity / credential / accountstate-changing class

11,482 tools

18.2% of declared tools
Outbound fetch (SSRF-relevant)read/network class

9,229 tools

14.6% of declared tools
Send message / post / notifystate-changing class

1,371 tools

2.2% of declared tools
Read / search / listread/network class

53,437 tools

84.7% of declared tools
03

Surface tiers

High-capability servers
2,041
Moderate-capability servers
701
Read-oriented servers
294
Payment surface
1,936
Code-execution surface
1,441
Credential-operation surface
2,080

Tier means the highest declared capability class SaSame observed. It is not a risk rating and does not establish whether a tool is implemented, permission-gated or safe to invoke.

04

Method and limits

The classifier is capability-classify/0.1 against agent-tool-discoverability-standard/0.4. Deterministic: yes. LLM used for classification: no.

The corpus is: Public MCP servers observed by SaSame (official MCP registry + multi-source crawl). Credential-gated or private surfaces that cannot be enumerated are not silently inferred.

RF

Evidence files