SaSameFor people and AI systems
live reportdeclared surfaceno LLM

What is visible on the public MCP tool surface?

This report summarizes what SaSame could observe from public endpoints and declared tool metadata. It separates measurable annotation and exposure facts from claims about vulnerabilities, intent or safety.

Endpoints observed
57,114
Enumerable servers
7,508
Declared tools
129,957
Updated
2026-09-16
Current finding

52.7% of state-changing tools on the enumerable surface publish NO machine-readable safety annotation — a calling agent cannot automatically tell a read from a write, delete, or payment before invoking them.

CAP

Evidence capsule

Conclusion first

52.7% of state-changing tools on the enumerable surface publish NO machine-readable safety annotation — a calling agent cannot automatically tell a read from a write, delete, or payment before invoking them.

Observed at
2026-09-16T20:19:40.186Z
Generated at
2026-09-16T20:19:40.186Z
Classifier
capability-classify/0.1

Quotable text: SaSame observed 129,957 declared tools across 57,114 public MCP endpoint(s); this is an outside-in measurement, not a safety verdict.

Methodology: Protocol methodology mcp-census-methodology/0.4; probe profile mcp-era-census/1.0; historical rows rewritten: no. Attack-surface classifier: capability-classify/0.1.

Caveat: This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.

Source freshness: Each raw Observatory source carries its own generated_at/observed_at semantics; page generation never fabricates freshness. Source snapshot as of 2026-09-16T20:19:40.186Z. 1_source(s)_older_than_their_own_configured_freshness_window

Suggested citation: State of MCP public tool surface. SaSame Protocol Observatory. https://srl-sasame.com/observatory/state-of-mcp. Raw evidence: https://live-vps.sasame.online/observatory/attack-surface.json. Generated 2026-09-16T20:19:40.186Z.

01

Annotation and discoverability

State-changing tools
37,295
Unlabeled state-changing
19,636
Unlabeled share
52.7%
Annotation coverage
32.2%

This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.

02

Declared capability landscape

One tool can match more than one class. Percentages describe the declared surface and therefore do not sum to 100%.

Payment / funds movementstate-changing class

12,540 tools

9.6% of declared tools
Code / command executionstate-changing class

3,086 tools

2.4% of declared tools
Identity / credential / accountstate-changing class

16,104 tools

12.4% of declared tools
State change / write / deletestate-changing class

14,261 tools

11% of declared tools
Outbound fetch (SSRF-relevant)read/network class

34,227 tools

26.3% of declared tools
Send message / post / notifystate-changing class

3,167 tools

2.4% of declared tools
Read / search / listread/network class

104,765 tools

80.6% of declared tools
03

Surface tiers

High-capability servers
4,638
Moderate-capability servers
2,001
Read-oriented servers
869
Payment surface
4,425
Code-execution surface
2,631
Credential-operation surface
4,628

Tier means the highest declared capability class SaSame observed. It is not a risk rating and does not establish whether a tool is implemented, permission-gated or safe to invoke.

04

Method and limits

The classifier is capability-classify/0.1 against agent-tool-discoverability-standard/0.4. Deterministic: yes. LLM used for classification: no.

The corpus is: Public MCP servers observed by SaSame (official MCP registry + multi-source crawl). Credential-gated or private surfaces that cannot be enumerated are not silently inferred.

RF

Evidence files