Product Field Work All builds
BuildAccountable

Tool Label

AI agents now install tools the way phones install apps, and 36,000 MCP servers are listed in the official registry. This build reads each one’s actual code and prints a label anyone can understand: what it can read, change, run and reach, and what changed in its last update.

Every line on the label points to the file it came from. Nothing on it is a model’s opinion.

The problem

When a person connects an MCP server to an agent, that server’s code runs with the person’s access: their files, their credentials, their network. The listing shows a name and a one-line description. What the code can actually do is invisible unless someone reads it, and it can change with any update.

–MCP servers in the official registry today, of them installable from npm
1,184malicious skills pushed into one agent tool marketplace in a single campaign, ClawHavoc, in 2026
–of a random sample of registry servers can run commands on your machine, measured below

Most of these tools are fine. The problem is that nobody can tell which ones aren’t without reading the code, and nobody reads the code for every update.

How I measure the problem
  1. Share of servers with each risky capability, measured on a random registry sample
  2. Share whose capabilities changed in their latest update, the moment a trusted tool becomes a new one
  3. Minutes a reviewer spends per tool, with and without the label; an assumption you can change
Why I chose it

Agents are the fastest-moving part of AI, and the least audited. It’s the natural next step for the regulated-software habit of asking, before anything runs, exactly what it’s allowed to touch.

The ideaRead the package, not the pitch. Scan each server’s code for what it can actually touch, compare it with the previous version, and print the answer on a label a non-engineer can read.

Sources: Official MCP Registry API, counted ; ClawHavoc figure from ASTELD: A Six-Axis Classification Framework for Autonomous AI Agents, 2026.

Labels for a random sample of registry servers

What the label is worth

For a security or platform team approving the MCP servers its company’s agents may use. Measured rates come from the sample above.

–saved a year
–reviewer hours a year, down from
–reviews a year still done in depth, on the tools that need it

    From public data

    Median pay for information security analysts, BLS, May 2024.

    Private industry, BLS ECEC, June 2026.

    Assumptions you can change

    No public benchmark exists for these. They are conservative starting points, not findings.

    What it means for the people

    Today, security engineers approve agent tools by reading source, or by not reading it and hoping. Here is how a year of reviews shifts.

    Today
    Reading every tool and every update by hand
    With labels
    Reading labels
    Focused reviews
    Freed for policy and threat hunting

    They start where the risk isA tool that can run commands or rewrite files arrives flagged, with the exact files that gave it away. The rest get a quick read.
    Updates stop being blind spotsOnly updates that add a capability, a new host or a new secret come back for review. Everything else passes on the label.
    Non-engineers can decide tooThe label is written for the person connecting the tool. They can see that a “read-only” tool can write files before they click allow.
    What disappears, and what doesn’t

    Hand-reading harmless packages and unchanged updates goes away. Judging whether a capability is appropriate for the job, setting the policy, and deciding to allow or block stay human.

    Label any package

    How it works

    PackageThe exact tarball npm would install, latest and previous versions.
    ScanRules look for network, file, process and secret access, install scripts, and declared tools.
    ReviewFlagged tools and changed updates go to a person, with the files that triggered each line.
    LabelA plain-language label, and a diff against the previous version.

    Evidence

    –servers labeled from a seeded random sample of the npm-packaged registry
    –of servers with a previous version gained a capability, host or secret in their latest update
    –servers whose tools are all named like read-only tools, but whose code can write files or run commands
    Where it gets it wrong

    It reads the package’s own code, not its dependencies, so a risky library pulled in at install time won’t show. Rules see capabilities, not intent: a logging line that writes a file looks the same as one that overwrites your documents, which is why the label shows the file and a person decides. And servers that only run remotely, of the registry, have no code to read at all.

    Choices

    Static rules over “ask an AI if it’s safe”The code being judged can contain instructions aimed at the judge. Rules can’t be talked into anything, and every flag points to a file.
    The diff over the snapshotSupply-chain attacks arrive as updates to tools people already trust. A label that only describes the latest version misses the moment that matters.
    Capabilities, not a scoreA single risk number hides the reason. “Can run commands” is something a person can weigh against what the tool is for.