AI agents now install tools the way phones install apps, and 36,000 MCP servers are listed in the official registry. This build reads each one’s actual code and prints a label anyone can understand: what it can read, change, run and reach, and what changed in its last update.
Every line on the label points to the file it came from. Nothing on it is a model’s opinion.
When a person connects an MCP server to an agent, that server’s code runs with the person’s access: their files, their credentials, their network. The listing shows a name and a one-line description. What the code can actually do is invisible unless someone reads it, and it can change with any update.
Most of these tools are fine. The problem is that nobody can tell which ones aren’t without reading the code, and nobody reads the code for every update.
Agents are the fastest-moving part of AI, and the least audited. It’s the natural next step for the regulated-software habit of asking, before anything runs, exactly what it’s allowed to touch.
The ideaRead the package, not the pitch. Scan each server’s code for what it can actually touch, compare it with the previous version, and print the answer on a label a non-engineer can read.
Sources: Official MCP Registry API, counted ; ClawHavoc figure from ASTELD: A Six-Axis Classification Framework for Autonomous AI Agents, 2026.
For a security or platform team approving the MCP servers its company’s agents may use. Measured rates come from the sample above.
Today, security engineers approve agent tools by reading source, or by not reading it and hoping. Here is how a year of reviews shifts.
Hand-reading harmless packages and unchanged updates goes away. Judging whether a capability is appropriate for the job, setting the policy, and deciding to allow or block stay human.
It reads the package’s own code, not its dependencies, so a risky library pulled in at install time won’t show. Rules see capabilities, not intent: a logging line that writes a file looks the same as one that overwrites your documents, which is why the label shows the file and a person decides. And servers that only run remotely, of the registry, have no code to read at all.