{"service":"SRI — MCP Server Inspector","analyzer_version":"rules-2026.08","ecosystems":["mcp"],"coverage":{"total":2963,"judged":2781,"not_judged":182,"not_judged_reason":"The published artifact was retrieved but contains no implementation code — metadata and documentation only. Nothing was read, so these are not 'clean'; there was simply nothing to read.","by_ecosystem":[{"ecosystem":"mcp","c":2963}]},"category_prevalence":[{"category":"credential_access","servers":479,"pct":17.2},{"category":"network_egress","servers":232,"pct":8.3},{"category":"install_script","servers":190,"pct":6.8},{"category":"prompt_injection_surface","servers":187,"pct":6.7},{"category":"other","servers":89,"pct":3.2},{"category":"excessive_permission","servers":16,"pct":0.6},{"category":"obfuscation","servers":3,"pct":0.1}],"prevalence_note":"Share of judged servers with at least one finding in the category. Counted per server, not per finding. Most findings describe the server's stated job — a GitHub server reads a GitHub token. These describe what you agree to on connect, not intent.","method":{"source":"published implementation source of each server","evidence_rule":"every finding carries a file:line and quotes the code; findings whose quoted evidence cannot be located in that file are dropped","run_to_run_agreement":"93% on a hand-labelled set of 84 servers","writeup":"https://sri-test.biz/research","raw_counts":"https://github.com/SRITEST0001/sri/tree/main/research"},"index_url":"/v1/corpus/index","detail":{"note":"The index tells you what was read. The findings themselves are returned per server by the endpoints below.","mcp":{"url":"https://sri-test.biz/mcp","tool":"check_mcp_server"},"http":"POST /v1/verify","price_url":"/v1/price","free_now":true},"corrections":"If a finding is wrong: POST /v1/disputes, or the form at https://sri-test.biz/contact — answered within 3 business days. Withdrawn findings stop being served."}