Security clarity for agent builders

See risk. Build trust.

Paste an MCP server or agent URL. AgentGrade turns permissions, unsafe tool descriptions, auth handling, and data egress into a public scorecard people can verify.

Public by default Rubric v1.0
agentgrade.io/scorecard/mcp-server
AgentGradeScorecard

mcp-server

Scanned just now · Public scorecard

A−

78/100

Good

Permissions

Reviewed

Prompt safety

2 findings

Data egress

Mapped

Transparent evidence. Versioned score. Shareable trust.

01 / Public method

A grade you can audit, not a verdict you must trust.

Security trust starts with showing the work. Every scorecard points back to a public rubric and concrete evidence—no invented authority, no opaque risk model.

01

Public rubric

Every scoring rule is readable and versioned.

02

Reproducible findings

Every deduction points to evidence you can verify.

03

README badge

One signal users can scan before they install.

02 / The scorecard

Signals maintainers can act on.

Evidence first

Every grade opens into the evidence behind it.

Review requested permissions, risky tool copy, credential paths, and outbound data destinations. Findings include severity, rationale, and remediation—not just a letter grade.

Permission scopeWrite access exceeds declared taskHigh
Tool descriptionUntrusted instructions acceptedReview
Data egressTwo external destinations documentedClear

Agent surface

Capabilities made legible.

See what an agent can touch before a user has to guess.

Badge loop

Share trust everywhere.

[A−] AgentGrade Score 78 GOOD

03 / When public isn’t enough

Keep the trust loop inside your team.

CI policy

Block a PR when the score drops.

Monitoring

Re-scan when a dependency changes.

Audit exports

Give security review evidence, not promises.

04 / Access

Public trust stays free.

Pay when AgentGrade becomes part of your private development and security workflow.

Compare plans

Open source

Public

$0

free forever

  • Public URL scans
  • Public scorecard pages
  • Embeddable README badge
  • Versioned findings
Scan a public agent

Private assurance

Team

$49

workspace / month

  • Private repository scans
  • PR policy checks
  • Dependency monitoring
  • Audit-ready exports
Start private scanning

Questions, answered plainly

What happens behind the grade?

Your agent has a surface area

Make it visible before it becomes a surprise.

Scan an agent free
    AgentGrade — Security Scorecards for AI Agents