← Back to catalog

B

MCP Reference Everything

Reference MCP test server exposing broad prompts, resources, and tools for client and scanner validation.

lowautomated scan
Danger score
5.6 / 10
Transparency
low
Last scanned
2026-07-04 08:18:08
Engine
mcpaudit 2.4.0
Source
npm: @modelcontextprotocol/server-everything

Automated danger grade: this page reports detected or inferred risk from a scan. It is not an endorsement, certification, or claim that the server is malicious.

Low transparency: this server declares few or no tool behavior annotations, so the danger score is inferred from defaults. Treat as cannot verify safe — not necessarily dangerous.

Grade history

14 scans on record between 2026-06-20 and 2026-07-04. The grade changed once in that time.

Scanned (UTC)GradeEngineAttributed cause
2026-06-20 06:52Fmcpaudit 2.1.0First scan on record
2026-06-20 07:10Fmcpaudit 2.1.0No change
2026-07-03 02:50Fmcpaudit 2.1.0No change
2026-07-03 09:44Bmcpaudit 2.3.0Scanner engine changed
2026-07-03 10:00Bmcpaudit 2.3.0No change
2026-07-03 10:01Bmcpaudit 2.3.0No change
2026-07-03 10:12Bmcpaudit 2.3.0No change
2026-07-03 10:16Bmcpaudit 2.3.0No change
2026-07-03 12:42Bmcpaudit 2.3.0No change
2026-07-03 13:21Bmcpaudit 2.4.0No change
2026-07-03 14:13Bmcpaudit 2.4.0No change
2026-07-04 08:13Bmcpaudit 2.4.0No change
2026-07-04 08:16Bmcpaudit 2.4.0No change
2026-07-04 08:18Bmcpaudit 2.4.0No change

History as recorded by this registry's own scans. The cause is an attribution from the inputs the registry records — the scanner engine identity and the declared tool surface — not proof of what changed on the server. Generated 2026-08-02.

How to read this grade

Spec-shift exposure

BREAKS against MCP 2026-07-28-rc · confidence high · ruled 2026-07-18

DimensionAreaVerdict
D1Stateless-core compatibilityBREAKS
D2Deprecated-capability relianceBREAKS
D3Authorization postureN_A
D4Schema and wire conformanceREADY
D5Extensions readinessNOTE

What to change

This is a point-in-time ruling against a release candidate, not the published specification, and it is independent of the danger grade above. Neither figure constrains the other.

Provenance & dispute

Add this badge to your README

Copy the Markdown below only if you want to link readers to the latest danger grade and scan caveats:

[![MCP Trust](https://img.shields.io/endpoint?url=https://mcp-trust.vercel.app/servers/mcp-reference-everything/badge.json)](https://mcp-trust.vercel.app/ui/servers/mcp-reference-everything)
MCP Trust badge

Findings

SeverityRuleTitleCategoryDetail
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
mediumMCP006Data exfiltration capabilityexfiltrationoutput
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
mediumMCP006Data exfiltration capabilityexfiltrationoutput
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
lowMCP005Destructive operation capabilitydestructivedestructiveHint=null (spec default: true)
lowMCP003Network access capabilitynetworkopenWorldHint=null (spec default: true)
mediumMCP001File read capabilityfile_readquery

Score breakdown

DimensionRaw (0–10)WeightWeighted
File access0.6×1.20.72
Network access1.5×1.01.50
Shell execution0.0×2.00.00
Destructive2.0×0.30.60
Exfiltration1.5×0.40.60