What is visible on the public MCP tool surface?
This report summarizes what SaSame could observe from public endpoints and declared tool metadata. It separates measurable annotation and exposure facts from claims about vulnerabilities, intent or safety.
- Endpoints observed
- 57,114
- Enumerable servers
- 7,508
- Declared tools
- 129,957
- Updated
- 2026-09-16
52.7% of state-changing tools on the enumerable surface publish NO machine-readable safety annotation — a calling agent cannot automatically tell a read from a write, delete, or payment before invoking them.
Evidence capsule
52.7% of state-changing tools on the enumerable surface publish NO machine-readable safety annotation — a calling agent cannot automatically tell a read from a write, delete, or payment before invoking them.
- Observed at
- 2026-09-16T20:19:40.186Z
- Generated at
- 2026-09-16T20:19:40.186Z
- Classifier
- capability-classify/0.1
Quotable text: SaSame observed 129,957 declared tools across 57,114 public MCP endpoint(s); this is an outside-in measurement, not a safety verdict.
Methodology: Protocol methodology mcp-census-methodology/0.4; probe profile mcp-era-census/1.0; historical rows rewritten: no. Attack-surface classifier: capability-classify/0.1.
Caveat: This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.
Source freshness: Each raw Observatory source carries its own generated_at/observed_at semantics; page generation never fabricates freshness. Source snapshot as of 2026-09-16T20:19:40.186Z. 1_source(s)_older_than_their_own_configured_freshness_window
Suggested citation: State of MCP public tool surface. SaSame Protocol Observatory. https://srl-sasame.com/observatory/state-of-mcp. Raw evidence: https://live-vps.sasame.online/observatory/attack-surface.json. Generated 2026-09-16T20:19:40.186Z.
Annotation and discoverability
- State-changing tools
- 37,295
- Unlabeled state-changing
- 19,636
- Unlabeled share
- 52.7%
- Annotation coverage
- 32.2%
This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.
Declared capability landscape
One tool can match more than one class. Percentages describe the declared surface and therefore do not sum to 100%.
12,540 tools
9.6% of declared tools3,086 tools
2.4% of declared tools16,104 tools
12.4% of declared tools14,261 tools
11% of declared tools34,227 tools
26.3% of declared tools3,167 tools
2.4% of declared tools104,765 tools
80.6% of declared toolsSurface tiers
- High-capability servers
- 4,638
- Moderate-capability servers
- 2,001
- Read-oriented servers
- 869
- Payment surface
- 4,425
- Code-execution surface
- 2,631
- Credential-operation surface
- 4,628
Tier means the highest declared capability class SaSame observed. It is not a risk rating and does not establish whether a tool is implemented, permission-gated or safe to invoke.
Method and limits
The classifier is capability-classify/0.1 against agent-tool-discoverability-standard/0.4. Deterministic: yes. LLM used for classification: no.
The corpus is: Public MCP servers observed by SaSame (official MCP registry + multi-source crawl). Credential-gated or private surfaces that cannot be enumerated are not silently inferred.