MCP Server & Tooling Landscape, September 2026
Public sample (redacted edition) of a custom research report
2026-09-25
MCP Server & Tooling Landscape, September 2026
Public sample, redacted edition. This is a real deliverable with client-identifying details removed (a redaction log is kept). The substance, tables and all 80 citations are unchanged. Everything below is a snapshot as of 2026-09-25. Versions, star counts, CVE status and prices will drift, so re-check anything before you rely on it.
Prepared for: [client name redacted], a small team building local-first agent tooling
Research date: Friday 2026-09-25 (all times PT unless marked). Everything here comes from live sources read on this date. Bracketed numbers like [3] point to the Sources list at the end.
Method: I read spec pages, official blogs, READMEs,
docs, NVD/OSV records, and security write-ups directly. GitHub facts
(license SPDX, archived flag, stars, latest commit, latest release) were
pulled from each repo’s public page and its commits.atom /
releases.atom feeds on 2026-09-25 [78]. Commit and release
dates are UTC dates. Star counts are a point-in-time
snapshot.
0. Executive answer
Adopt now: For new work, target the
2026-07-28 spec (it’s stateless, uses Streamable HTTP +
stdio, and moves Tasks into an extension) on the Tier-1 Python
(v2.x) or TypeScript (v2.x) SDK or FastMCP
4.x. Run a small, pinned set of mostly vendor-maintained
servers locally: Playwright MCP (browser),
GitHub MCP server in --read-only mode with
trimmed toolsets, MCP Toolbox for Databases / a DuckDB
local server (data), and SearXNG MCP pointed at your
own SearXNG (search). Put local memory on plain files
(basic-memory, or mcp-memory-service
with local ONNX embeddings). Run each server in a container through
ToolHive or Docker MCP Gateway. For
hosts that work with Ollama/vLLM, use opencode,
goose (now an AAIF/Linux Foundation project),
Zed, or Codex CLI. Codex has the
strongest per-tool approval and allow-list controls I found.
Watch: Registry GA (it’s still “preview”),
HTTP-over-stdio transport unification, DPoP and agent-identity auth, the
tools/call result-shape redesign, and progressive tool
discovery. All of these are on the 2026-08-22 roadmap [9].
Avoid: Unmaintained or archived hosts and servers:
Continue (repo read-only), Roo Code
(archived), mcphost (archived),
mcp-router (archived), the self-hosted
Browserbase MCP (archived), and the
servers-archived reference servers (Puppeteer, SQLite,
Postgres, and others). Don’t install random npm MCP packages without
pinning and scanning them; the malicious postmark-mcp is
the canonical example. Don’t let any tool-bearing server run with broad
tokens and auto-approve on. Prompt injection through tool
output is an architectural problem that no server patch fixes
[63].
1. Top “adopt now” table
| Layer | Pick | Maintainer | License | Latest release / last commit (UTC) | Self-host | Main risk / condition |
|---|---|---|---|---|---|---|
| Spec target | MCP 2026-07-28 (current) | MCP maintainers (AAIF / LF Projects) | Apache-2.0 for new contributions [10] | Released 2026-07-28 [3][4] | n/a | Breaking: no initialize handshake and no
Mcp-Session-Id. Plan migration of older servers [2] |
| Server SDK (Python) | mcp Python SDK v2.2.0 or
FastMCP v4.0.9 |
Official (Tier 1) / PrefectHQ | MIT / Apache-2.0 | 2026-09-07 / 2026-09-24 [78] | yes | FastMCP is a third-party framework on top of the protocol, so pin major versions |
| Server SDK (TS) | @modelcontextprotocol/server + /client
2.1.0 (v2 line) |
Official (Tier 1) | MIT badge on README; repo SPDX shows NOASSERTION during the MIT→Apache transition [18][20] | 2026-09-23 [78] | yes | v1.x gets fixes for at least 6 months after v2’s release [18] |
| Coding host (local models) | opencode v2.0.16 | anomalyco org (redirect from
sst/opencode) |
MIT | 2026-09-24 [78] | yes | MCP tools eat context. Disable per-agent with globs [23] |
| General agent host | goose | AAIF / Linux Foundation (formerly block/goose) |
Apache-2.0 | last commit 2026-09-25 [78] | yes | Supports Ollama plus 15+ providers [30] |
| Browser automation | Playwright MCP v0.0.82 | Microsoft | Apache-2.0 | 2026-09-18 [78] | yes (local) | “Not a security boundary.” Origin allow-lists aren’t security
controls. Use --isolated [38] |
| Browser debugging | Chrome DevTools MCP v1.10.1 | Google (ChromeDevTools org) | Apache-2.0 | 2026-09-23 [78] | yes (local) | Usage stats on by default. Pass
--no-usage-statistics and
--no-performance-crux [39] |
| GitHub | github-mcp-server 1.12.2 (local Docker) | GitHub | MIT | 2026-09-16 [78] | yes (local binary/Docker); remote is GitHub-hosted | Toxic-flow prompt injection via public issues [63]. Use
--read-only, --toolsets, lockdown mode
[37] |
| Databases | MCP Toolbox for Databases v1.13.0 | Google (googleapis/mcp-toolbox) |
Apache-2.0 | 2026-09-25 [78] | yes | Prebuilt execute_sql tools. Point it at a read-only DB
role [48] |
| Analytics (local) | DuckDB/MotherDuck local MCP v1.0.8 | MotherDuck | MIT | 2026-08-19 [78] | yes | Can read and write the local filesystem [51] |
| Search | mcp-searxng v2.4.0 + your own SearXNG | Community (ihor-sokoliuk) | MIT | 2026-09-22 [78] | yes (fully) | Only as trustworthy as the SearXNG instance you point it at [43] |
| Memory | basic-memory v0.23.2 (Markdown on disk) | Basic Machines | AGPL-3.0 | 2026-08-25 [78] | yes | AGPL matters if you redistribute or host it for others [46] |
| Memory (alt) | mcp-memory-service v11.14.0 | Community (doobidoo) | Apache-2.0 | 2026-09-25 [78] | yes | Local ONNX embeddings [47]. Single maintainer |
| Isolation / gateway | ToolHive v0.51.2 | Stacklok | Apache-2.0 | 2026-09-25 [78] | yes | Pre-1.0 [55] |
| Isolation / gateway (alt) | Docker MCP Gateway v0.44.1 | Docker | MIT | 2026-09-23 [78] | yes | README lists Docker Desktop 4.59+ as a prerequisite. The CLI plugin can also run on its own [54] |
| Config pinning | mcp-context-protector | Trail of Bits | Apache-2.0 | last commit 2026-02-13 [78] | yes | Low recent activity. Treat it as a pattern and a tool, not a long-lived product [60] |
2. State of the spec
2.1 Current revision
- Current protocol version is
2026-07-28. Revisions are dated with the date of the last backward-incompatible change [1]. The GitHub releases list shows2026-07-28(stable), preceded by an RC, then2025-11-25,2025-06-18,2025-03-26, and2024-11-05[4]. - The official blog announced it on July 28, 2026, calling out a stateless core, Multi Round-Trip Requests (MRTR), header-based routing, cacheable list results, authorization hardening, and a formal extensions framework [3].
- Adoption signal from the blog: “close to half-a-billion downloads a month” across Tier-1 SDKs, with TypeScript and Python each past 1 billion total downloads [3]. These are self-reported numbers.
2.2 What changed in 2026-07-28 (primary: changelog [2])
- Stateless. The
initialize/initializedhandshake is gone. Every request carries its protocol version and client capabilities in_meta. A mandatoryserver/discoverRPC advertises versions and capabilities (SEP-2575) [2]. - No protocol sessions.
Mcp-Session-Idhas been removed. Servers that need state mint explicit handles and pass them back as tool arguments (SEP-2567) [2]. - MRTR replaces server-initiated requests. Servers
return
resultType: "input_required", and the client retries withinputResponses. This replaces server-sentelicitation/create,sampling/createMessage, androots/list(SEP-2322) [2]. - Tasks moved out of core into the
io.modelcontextprotocol/tasksextension, now polling-based (tasks/get,tasks/update) (SEP-2663) [2]. subscriptions/listenreplaces the HTTP GET stream andresources/subscribe[2].- SSE resumability removed. A broken stream means you re-issue the request [2].
- Required
Mcp-Method/Mcp-Nameheaders on Streamable HTTP POSTs, so gateways can route and authorize without parsing bodies (SEP-2243) [2][3]. - Cache hints.
ttlMsandcacheScopeon list and read results. Tools should be listed in a deterministic order [2]. - Deprecated: Roots, Sampling, and Logging (SEP-2577). The legacy HTTP+SSE transport is now formally deprecated. OAuth Dynamic Client Registration is deprecated in favour of Client ID Metadata Documents (CIMD). Deprecated features stay for at least 12 months [1][2].
2.3 Transports
- There are two standard bindings: stdio (newline-delimited JSON-RPC to a client-launched subprocess) and Streamable HTTP (each message is a POST to a single endpoint, with replies as JSON or a request-scoped SSE stream) [5].
- Roadmap: collapse these into one HTTP model, spoken over stdio for local servers (“HTTP/2 over stdio”), and add ETag caching [9]. That makes stdio vs. HTTP a transport detail rather than a design fork. Good news for local-first setups.
2.4 Authorization
- Authorization is OPTIONAL. When it is implemented, it’s OAuth 2.1 (draft-13), servers MUST publish RFC 9728 Protected Resource Metadata, and clients SHOULD support CIMD. DCR is retained only for backward compatibility [6].
- 2026-07-28 hardening: RFC 9207
issvalidation (mix-up defence), a required DCRapplication_type(this fixeslocalhostredirect rejections for CLI/desktop clients), and credentials bound to their issuer [2][3]. - Roadmap next: DPoP, workload identity federation, ID-JAG, and RFC 8693 token exchange for agent and sub-agent delegation [9].
- For the client: local stdio servers don’t need
OAuth at all. OAuth matters for remote servers you expose (for example
on a hosted workspace or at the edge). If you build one, implement CIMD
and
issvalidation from day one.
2.5 Elicitation
- Two modes. Form is flat primitive schemas only. URL is out-of-band, for anything sensitive. Servers MUST NOT use form mode for passwords, API keys, or tokens [7].
- In 2026-07-28, elicitation is delivered inside an
InputRequiredResult(MRTR), not as a server-initiated request [7]. URL mode is still flagged as possibly changing in future revisions [7].
2.6 Structured output
- Tools may declare
outputSchema. Results can carrystructuredContent, which may be any JSON value. Schemas may use any JSON Schema 2020-12 keywords (SEP-2106) [2][8]. - Tool annotations MUST be treated as untrusted unless they come from trusted servers [8].
- Honest caveat: the roadmap says returning both
contentandstructuredContent“has confused server and client authors alike and produced diverging implementations,” and a redesign oftools/callis planned [9]. Expect this surface to change. Don’t over-invest in clever dual-format outputs.
2.7 Registry
- The official MCP Registry is still in preview: “Breaking changes or data resets may occur before general availability” [13]. The API has been frozen at v0.1 since 2025-10-24 [14].
- It’s a metadata registry (it points to npm/PyPI/Docker/remote URLs). It uses reverse-DNS namespaces verified via GitHub, DNS, or HTTP challenge. It delegates security scanning to package registries and downstream aggregators [13]. In other words, being listed ≠ being vetted.
- The official registry codebase is “not designed for self-hosting”. Private registries should implement its OpenAPI spec instead [13].
- Size: I paged the live API
(
/v0.1/servers?version=latest) and counted 35,953 latest-version server entries at 2026-09-25 06:51 PT [15]. That’s my own count. The API returned an HTTP 500 on one earlier full pass, so treat the figure as approximate. - Working-group lead is from Stacklok (the ToolHive vendor) [14]. Worth knowing when you weigh ToolHive’s registry features.
2.8 Governance
- Anthropic donated MCP to the Agentic AI Foundation (AAIF), a directed fund under the Linux Foundation, on 2025-12-09. Co-founders were Anthropic, Block, and OpenAI [11][12][80]. The LF says it “will not dictate the technical direction of MCP” [11].
- Technical governance is BDFL-style: two Lead Maintainers (David Soria Parra, Den Delimarsky) with final veto, six Core Maintainers, and membership that is individual rather than per-company [10].
- Licensing is in transition from MIT to Apache-2.0.
New contributions are Apache-2.0. Older MIT contributions stay MIT until
their authors consent to relicensing [10][20]. That’s why GitHub shows
NOASSERTIONfor many official repos. Practical effect for you: both licenses are permissive, so this isn’t a problem. - A formal feature lifecycle has been adopted (Active → Deprecated → Removed), with a minimum 12-month deprecation window [1][2].
3. SDKs
Official tiering: Tier 1 needs a 100% conformance pass, new spec features before release, triage within 2 business days, and critical fixes within 7 days. Tier 2 needs 80% conformance and new features within 6 months. Tier 3 is experimental [16].
| SDK | Tier (per docs [17]) | Latest release (UTC) [78] | Notes |
|---|---|---|---|
| TypeScript | 1 | @modelcontextprotocol/* 2.1.0 (2026-09-23), v1 line
1.30.1 |
v2 is the stable line for 2026-07-28. It’s split into client/server packages and uses Standard Schema (Zod v4, Valibot, ArkType). PRs are limited to 1 per new contributor while v2 settles [18] |
| Python | 1 | v2.2.0 (2026-09-07); v1 line 1.30.0 | v2.0.0 shipped 2026-07-28 alongside the spec [78] |
| Go | 1 | v1.8.0 (2026-09-14) | “Maintained in collaboration with Google” (repo description) |
| C# | 1 | v2.2.0 (2026-08-13) | “Maintained in collaboration with Microsoft” |
Rust (rmcp) |
1 on docs page | rmcp-v3.4.1 (2026-09-23) | Discrepancy: the 2026-07-28 blog said Rust supports the new spec “in beta” [3], while the SDK page lists it as Tier 1 [17] |
| Java | 2 | v2.0.1 (2026-08-19) | |
| Ruby | 2 | v1.6.0 (2026-09-21) | Reached 1.0 on 2026-07-27 [19] |
| Swift | 3 | 0.12.1 (2026-05-07) | Last commit 2026-04-29, so slowest-moving |
| PHP | 3 | v0.8.1 (2026-08-29) | |
| Kotlin | 3 | 0.15.0 (2026-07-28) | |
| FastMCP (framework) | n/a (third-party) | v4.0.9 (2026-09-24) | Apache-2.0. Its maintainers say 4.0 ships support for 2026-07-28 features: background tasks, stateless interactivity, enterprise auth [3][21] |
Recommendation. For a team building local-first
servers with a Python/TS split: Use FastMCP 4.x for
Python tools you write quickly, and the official TS v2
packages for anything that ships to edge runtimes (TS v2 runs on Node,
Bun, and Deno [18]). Build against the 2026-07-28 semantics, but test
that hosts still on 2025-11-25 can talk to you. The spec
defines backward compatibility for handshake-based versions [1].
4. Clients / hosts, with a focus on local models
Key fact first: Ollama is not an MCP client. A PR adding experimental MCP support to Ollama (#13700) was closed unmerged. The maintainer said they would “keep the surface area small and frozen” and pointed people to Pi instead [33]. So an MCP-aware host always sits between Ollama/vLLM and your servers.
| Host | Maintainer / license | Last commit (UTC) [78] | Local-model path | MCP support notes |
|---|---|---|---|---|
| opencode | anomalyco org (redirect from
sst/opencode), MIT |
2026-09-25 | Any OpenAI-compatible endpoint (Ollama/vLLM). Local-model setup not detailed on the MCP page I read | Local (stdio) and remote servers, OAuth with DCR, per-agent tool enable/disable via globs [23] |
| goose | AAIF/LF (aaif-goose/goose), Apache-2.0 |
2026-09-25 | Ollama listed among 15+ providers [30] | “70+ extensions via MCP”. Desktop, CLI, and API [30] |
| Zed | Zed Industries | 2026-09-25 | Not verified in this pass | Supports MCP Tools and Prompts only. No sampling or
elicitation yet. Per-tool permission rules
(mcp:<server>:<tool>), default
confirm [24] |
| Codex CLI / IDE / ChatGPT desktop | OpenAI, Apache-2.0 (CLI repo) | 2026-09-25 | Not verified in this pass | stdio + Streamable HTTP, CIMD + DCR,
enabled_tools/disabled_tools, per-tool
approval_mode
(auto/prompt/writes/approve),
per-tool output-token caps [25]. Best policy controls I found |
| Cline | Cline, Apache-2.0 | 2026-09-25 | Ollama, LM Studio [27] | MCP via mcpServers JSON. Omitting type
defaults to legacy SSE, so set
"type":"streamableHttp" [29]. Gotcha:
Cline’s own local-model guide recommends “compact prompt”, and that
removes MCP tools [28] |
| LM Studio | LM Studio (closed source) | n/a | Built-in runtime (MLX/GGUF) | MCP host since 0.3.17, local and remote, Cursor-style
mcp.json. Warns that MCP servers built for frontier models
can overflow local context [26] |
| Open WebUI | Open WebUI, GitHub SPDX = NOASSERTION | 2026-09-21 | Ollama-native UI | Native MCP from v0.6.31, Streamable HTTP only, admin-only. The docs say OpenAPI remains “the preferred integration path”. Use mcpo to bridge stdio servers [22] |
| ollmcp (mcp-client-for-ollama) | Community, MIT | 2026-09-11 | Ollama-first TUI | STDIO/SSE/Streamable HTTP, human-in-the-loop, multi-server [34] |
Pi (earendil-works/pi, formerly
badlogic/pi-mono) |
Earendil, MIT | 2026-09-25 | Recommended by an Ollama maintainer [33] | MCP is an extension you build or install, not built in [77] |
| Apache-2.0 | 2026-07-21 | “No longer actively maintained and is read-only”, final 2.0.0 release [31] | ||
| Apache-2.0 | 2026-05-15 | Repository archived [32][78] | ||
| MIT | 2026-04-13 | Repository archived [78]. Third-party 2026 guides still recommend it, which is exactly why you verify |
For a single-machine home lab: run the agent host
(opencode or goose) on that machine. Point it at Ollama or vLLM’s
OpenAI-compatible endpoint. Run stdio servers as child processes of that
host, or via ToolHive/Docker for isolation. LM Studio’s docs and Cline’s
blog both warn that MCP tool schemas can swamp local-model context
[26][28]. Keep your active toolset small per agent (opencode globs,
Codex enabled_tools, Zed profiles).
5. Servers worth adopting, by category
Legend: Official = the vendor that owns the product or API. Ref = MCP steering-group reference server. Community = independent.
5.1 Coding / git
| Server | Maint. | License | Latest rel. / last commit (UTC) | Self-host | Notes & risks |
|---|---|---|---|---|---|
| github/github-mcp-server | Official (GitHub) | MIT | 1.12.2 (2026-09-16) | Local Docker/binary; remote at
api.githubcopilot.com/mcp/ |
--toolsets to trim, --read-only, lockdown
mode that only surfaces public-repo content from authors with push
access [37]. Invariant showed a malicious public issue driving an agent
to leak private repo data. They call it architectural, not a server bug
[63] |
| mcp-server-git (reference) | Ref | MIT→Apache transition | repo release 2026.8.31 | Local | Three CVEs fixed in 2025.12.17 or earlier: path-validation bypass in
git_init (CVE-2025-68143), argument injection via
git_diff/git_checkout (CVE-2025-68144), and
--repository scope bypass (CVE-2025-68145) [69]. The
servers README says reference servers are “not production-ready
solutions” [20] |
| oraios/serena | Community (Oraios AI) | Changed: Serena app is now
GPL-3.0-or-later; the SolidLSP library stays MIT. Tag
mit-final dated 2026-09-14 [42] |
v1.7.0 (2026-08-09) | Local | LSP-based semantic code tools. License change affects anyone
embedding or redistributing it commercially. Pin to
mit-final or accept GPL |
| upstash/context7 | Official (Upstash) | MIT (MCP server only) | @upstash/context7-mcp 4.1.1 (2026-09-14) |
No. The API backend, parser, and crawler are private [41] | CVE-2026-75130 (NVD, 2026-08-18): prompt injection via “Custom AI Instructions”, CVSS 3.1 9.0 / CVSS 4.0 6.4, “through 2.1.2” [73]. Fix status for the hosted feature is unknown from the sources I read. The docs are community-contributed and Upstash disclaims their accuracy and security [41] |
5.2 Filesystem
- Reference filesystem server
(
@modelcontextprotocol/server-filesystem). Symlink escape and prefix-match escape (CVE-2025-53109/53110) were fixed in 0.6.4 / 2025.7.01 [67][68]. It’s fine for scoped local use, but it’s still a reference implementation [20]. Most coding hosts (opencode, Zed, Codex) have built-in file tools, so in a coding host you often don’t need this server. - DesktopCommanderMCP (community, MIT, v0.2.51, 2026-09-17 [78]) is active, but a shell-plus-filesystem server is maximal blast radius. Only use it inside a container.
5.3 Browser automation
| Server | Maint. | License | Latest rel. (UTC) | Notes |
|---|---|---|---|---|
| microsoft/playwright-mcp | Official (Microsoft) | Apache-2.0 | v0.0.82 (2026-09-18) | Accessibility-snapshot driven. The README says it is not a
security boundary,
--allowed-origins/--blocked-origins “do not
serve as a security boundary”, and secrets masking is “a
convenience and not a security feature”. It has --isolated
and --sandbox flags [38]. 0.0.x versioning, so pin it |
| ChromeDevTools/chrome-devtools-mcp | Official (Google) | Apache-2.0 | v1.10.1 (2026-09-23) | Debugging and performance traces. Google usage statistics on
by default. Trace URLs may go to the CrUX API. Opt out with
--no-usage-statistics, --no-performance-crux
[39]. Has a --slim mode |
| browser-use | Browser Use (company OSS) | MIT | 0.13.10 (2026-09-04) | Large agent-browser library. Its MCP mode was not verified in this pass |
| Apache-2.0 | archived | README: “archived and no longer maintained”; recommends the hosted version [40] | ||
| Community | MIT | last commits 2025-12-13 / 2026-01-06 | Stale. The official Playwright MCP supersedes them |
5.4 Search / research
| Server | Maint. | License | Status (UTC) | Self-host | Notes |
|---|---|---|---|---|---|
| ihor-sokoliuk/mcp-searxng | Community | MIT | v2.4.0 (2026-09-22) | Yes, end to end (needs your own SearXNG with JSON enabled) [43] | The best sovereign option |
| brave/brave-search-mcp-server | Official (Brave) | MIT | v2.1.4 (2026-09-17) | Server local, API remote | Replaced the archived reference Brave server [20]. Paid API; pricing not checked |
| firecrawl/firecrawl-mcp-server | Official (Firecrawl) | MIT | v3.24.1 (2026-08-26) | “Cloud and self-hosted support” [44] | 26 tools in the full profile, which is heavy for local context. Keyless tier limited to scrape/search/parse [44] |
| exa-labs/exa-mcp-server, tavily-ai/tavily-mcp, jina-ai/MCP, perplexityai/modelcontextprotocol | Official vendors | MIT / MIT / Apache-2.0 / MIT | commits Aug–Sep 2026 [78] | Server local, API remote | Paid APIs, so vendor-dependent. Not deep-read |
| Reference fetch server | Ref | active | Local | Simple fetch-to-markdown [20]. Pair it with an egress policy |
5.5 Memory / knowledge graphs
| Server | Maint. | License | Status (UTC) | Local-model friendly? | Notes |
|---|---|---|---|---|---|
| basic-memory | Basic Machines | AGPL-3.0 | v0.23.2 (2026-08-25) | Yes. Plain Markdown on disk, cloud optional [46] | Human-readable, git-able, no lock-in |
| mcp-memory-service | Community (doobidoo) | Apache-2.0 | v11.14.0 (2026-09-25) | Yes. “Embeddings run locally via ONNX” [47] | Knowledge graph with typed edges. Bus factor ≈ 1 |
| Graphiti MCP (getzep/graphiti) | Zep (company OSS) | Apache-2.0 | v0.30.2 (2026-09-08) | Partial. Default LLM is OpenAI; Ollama works “as an OpenAI-compatible endpoint” [45] | Temporal KG on FalkorDB (default) or Neo4j. Heaviest option; needs an LLM that handles structured output well |
| Reference memory server | Ref | active | Yes | JSON knowledge graph, fine for demos [20] | |
| mem0 / OpenMemory | Mem0 | Apache-2.0 | active (2026-09-25) | Not verified | I didn’t verify OpenMemory’s MCP docs (the README path returned nothing). Unknown |
5.6 Databases
| Server | Maint. | License | Status (UTC) | Notes |
|---|---|---|---|---|
| googleapis/mcp-toolbox (formerly genai-toolbox) | Official (Google) | Apache-2.0 | v1.13.0 (2026-09-25) | Prebuilt tools for PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, MongoDB, Redis, Elasticsearch, ClickHouse, and more, plus GCP databases [48]. Self-hosted binary |
| motherduckdb/mcp-server-motherduck | Official (MotherDuck) | MIT | v1.0.8 (2026-08-19) | Local DuckDB files, in-memory, S3, MotherDuck [51]. Great fit for local research data |
| crystaldba/postgres-mcp | Community (Crystal DBA) | MIT | last release v0.3.0 (2025-05-16), last commit 2026-08-16 | Restricted (read-only, safe SQL parsing) vs. unrestricted modes [49]. Release cadence has stalled |
| supabase/mcp | Official (Supabase) | Apache-2.0 | v0.13.0 (2026-09-17) | read_only=true, project_ref scoping. Local
via Supabase CLI at localhost:54321/mcp [50] |
| redis/mcp-redis | Official (Redis) | MIT | 0.5.1 (2026-08-05) | |
Kubernetes (mcp-server-kubernetes) |
Community | CVE-2026-46519: allow-list env vars were enforced
only at tools/list, not at call time. Fixed in 3.6.0 [72].
This is a general lesson: discovery-time filtering is not
authorization |
5.7 Local-model bridges
- mcpo (Open WebUI, MIT): wraps a stdio MCP server as an OpenAPI HTTP server [36]. It’s still what Open WebUI points to for stdio [22], but the last commit was 2026-02-27 [78]. Expect lag on 2026-07-28 features.
- ollmcp: see §4.
- mcphost: archived [78]. Don’t adopt it.
- Pattern: prefer a host with a native provider for Ollama/vLLM (opencode, goose, Cline, Zed) over a translation proxy.
5.8 Creative tooling
| Server | Maint. | License | Status | Notes |
|---|---|---|---|---|
Figma MCP server (remote
mcp.figma.com/mcp, or desktop) |
Official (Figma) | Proprietary service | active | Remote is available on all plans. Desktop needs a Dev or Full seat on a paid plan. Write-to-canvas is “free during the beta” and will become usage-based paid [53]. Budget and lock-in risk |
| GLips/Figma-Context-MCP (Framelink) | Community | MIT | v0.13.2 (2026-06-18) | Self-hosted, uses your Figma API token |
| mcp-for-blender (formerly ahujasid/blender-mcp) | Community | MIT | last commit 2026-09-25 | execute_blender_code runs arbitrary Python. Set
BLENDER_MCP_SAFE_MODE=1. Telemetry is opt-in [52] |
| joenorton/comfyui-mcp-server | Community | Apache-2.0 | v1.1.1 (2026-02-17) | Small and low-activity. Not deep-read |
6. Gateways, proxies, aggregators
| Project | Maint. | License | Latest rel. (UTC) | What it’s for | Notes |
|---|---|---|---|---|---|
| ToolHive | Stacklok | Apache-2.0 | v0.51.2 (2026-09-25) | Runs every server in an isolated container with minimal permissions. Self-hostable registry and gateway. K8s operator, OTel [55] | Best fit for sovereign isolation. Open-core (an Enterprise edition exists) [55] |
Docker MCP Gateway (docker mcp) |
Docker | MIT | v0.44.1 (2026-09-23) | Containerized servers, secrets via Docker Desktop, OAuth, catalog, call tracing [54] | Smoothest path is the Docker Desktop Toolkit (4.59+) [54] |
| ContextForge | IBM | Apache-2.0 | v1.0.7 (2026-09-21) | Federates MCP, A2A, and REST/gRPC. 40+ plugins, OTel [56] | Heavier and more enterprise-oriented |
| agentgateway | agentgateway project (governance not verified) | Apache-2.0 | v1.6.0-alpha.2 (2026-09-22) | MCP + A2A + LLM gateway [57] | Good for an edge proxy in front of remote MCP |
| microsoft/mcp-gateway | Microsoft | MIT | no releases; last commit 2026-08-25 | K8s-oriented | |
| TBXark/mcp-proxy | Community | MIT | v1.1.0 (2026-09-15) | Aggregate many servers behind one HTTP endpoint | |
| sparfenyuk/mcp-proxy | Community | MIT | v0.12.0 (2026-05-14) | stdio↔︎HTTP bridge | Slowing |
| metatool-ai/metamcp | Community | MIT | 2.4.22 (2025-12-19) | Aggregator | Stale releases |
| “v0.6.4 — Final release”, archived [78] | Avoid |
With 2026-07-28, gateways can route and authorize on the
Mcp-Method/Mcp-Name headers without parsing
JSON bodies [3]. Check that any gateway you pick has shipped 2026-07-28
support before relying on that.
7. Security
7.1 Incident / vulnerability classes, with real examples
| Class | Real example | Source |
|---|---|---|
| Tool poisoning (hidden instructions in tool descriptions) | Invariant Labs PoC: an add tool whose description
exfiltrates ~/.cursor/mcp.json and SSH keys,
2025-04-01 |
[62] |
| Rug pull (description changes after approval) | Same Invariant write-up; mitigation is pinning or hashing tool descriptions | [62] |
| Cross-server shadowing | A malicious server redirects a trusted send_email
tool |
[62] |
| Indirect prompt injection via tool output (“toxic flow”) | A malicious GitHub issue makes the agent leak private repo data into a public PR. Not fixable server-side | [63] |
| Prompt injection via a server’s content feature | Context7 “Custom AI Instructions”, CVE-2026-75130, CVSS 3.1 9.0 | [73] |
| Malicious package / supply chain | postmark-mcp on npm turned malicious in 1.0.16
(released 2025-09-17) and BCC’d every email to an attacker. 1,643
downloads |
[75][76] |
| Client-side RCE via OAuth metadata | mcp-remote OS command injection from a crafted
authorization_endpoint, CVE-2025-6514, CVSS 3.1 9.6 |
[65] |
| Unauthenticated dev tooling | MCP Inspector < 0.14.1 RCE (no auth between client and proxy), CVE-2025-49596, CVSS 4.0 9.4 | [66] |
| DNS rebinding on localhost HTTP servers | TS SDK < 1.24.0 didn’t enable DNS-rebinding protection by default, CVE-2025-66414 | [70] |
| Session hijack / authz bypass in SDK transports | Python SDK < 1.27.2 routed by session ID without checking the principal, CVE-2026-52869 (CVSS 7.1) | [71] |
| Path traversal / sandbox escape in servers | Filesystem symlink and prefix bugs (CVE-2025-53109/53110). mcp-server-git trio (CVE-2025-68143/4/5). MCP Atlassian file exfiltration in remote mode, CVE-2026-73496 (CVSS 7.7), fixed in 0.22.0 | [67][68][69][74] |
| Discovery-time filtering ≠ authorization | mcp-server-kubernetes CVE-2026-46519 (CVSS 8.8) | [72] |
| Over-broad tokens / scope creep | The spec’s Scope Minimization section; OWASP MCP02 | [61][64] |
OWASP’s MCP Top 10 is still at the beta/pilot stage,
with items labelled MCP01:2025–MCP10:2025
(token exposure, scope creep, tool poisoning, supply chain, command
injection, prompt injection, authn/authz, telemetry, shadow servers,
context over-sharing) [64].
7.2 What the spec requires or recommends (Security Best Practices, 2026-07-28 [61])
- Token passthrough is forbidden. Servers MUST NOT accept tokens not issued to them.
- Clients doing OAuth discovery must guard against SSRF: HTTPS only, block private and link-local ranges, validate redirects.
- State handles are not authentication. Bind them to the verified user.
- For local servers: one-click install MUST show the full command and get consent. Clients SHOULD sandbox servers. Servers should prefer stdio, or require auth or use unix sockets if they use HTTP.
- Validate authorization URLs: only
http(s), never launch them via a shell.
7.3 Scanners and guards (what they actually do)
| Tool | License | Status (UTC) | Runs fully local? | Notes |
|---|---|---|---|---|
Snyk Agent Scan (formerly invariantlabs
mcp-scan) |
Apache-2.0 | snapshot build 2026-09-25 | No. Sends tool names and descriptions to the Snyk
analysis API and requires SNYK_TOKEN. States it does not
store tool-call contents [58] |
Also executes stdio server commands from your config to fetch descriptions [58]. Run it inside a sandbox. Output format marked experimental |
| Cisco AI Defense mcp-scanner | Apache-2.0 | 4.8.4 (2026-08-28) | Partially. The YARA and static/offline JSON modes need no API. LLM and AI Defense engines are optional [59] | Good for CI with offline mode |
| Trail of Bits mcp-context-protector | Apache-2.0 | last commit 2026-02-13 | Yes | Trust-on-first-use pinning of server config, blocks unapproved changes (anti-rug-pull), quarantines tool responses, strips ANSI [60] |
| promptfoo, NVIDIA garak | MIT / Apache-2.0 | active | Yes | General LLM red-teaming. Not MCP-specific; not evaluated here |
7.4 Mitigations mapped to a local-first setup
- Pin everything. Exact npm/PyPI/container versions, plus tool-description pinning (context-protector) to catch rug pulls [60][62].
- Containerize servers (ToolHive or Docker Gateway). Mount only the project directory and deny network by default for filesystem and git servers [54][55][61].
- Separate trust zones per agent. Don’t load an untrusted-content server (web fetch, GitHub issues, Context7) in the same session as a secret-bearing or write-capable server. This is the toxic-flow lesson [63].
- Least-privilege tokens. GitHub fine-grained PAT
scoped to specific repos,
--read-onlyby default, lockdown mode on [37]. Read-only DB roles [48][49]. - Approval policy. Codex
default_tools_approval_mode = "writes", or Zedconfirm[24][25]. Never set a global “always allow” on write tools. - Keep SDKs patched. Python ≥ 1.27.2 (or v2.x). TS ≥ 1.24.0 (or v2.x). Inspector ≥ 0.14.1 [66][70][71].
- Turn off vendor telemetry where it exists (Chrome DevTools MCP) [39].
8. Mature vs. worth adopting vs. avoid
Mature (safe to build on): The spec process (dated revisions, a 12-month deprecation policy, conformance-tested tiers) [1][16]. The Tier-1 SDKs [17]. The stdio and Streamable HTTP transports [5]. Vendor-owned servers from Microsoft, Google, and GitHub that ship weekly or monthly releases [78].
Worth adopting, with conditions: FastMCP 4.x (third-party, but fast-moving and well-aligned [3][21]). ToolHive / Docker Gateway for isolation. SearXNG + basic-memory / mcp-memory-service for sovereign research and memory. MCP Toolbox and DuckDB MCP for data.
Not mature yet: The Registry (preview [13]). The tool-result shape (redesign planned [9]). URL-mode elicitation (flagged as possibly changing [7]). Agent-identity auth (roadmap [9]). Tasks (an extension, heading toward core [9]).
Avoid: - Archived or unmaintained hosts and tools:
Continue [31], Roo Code [32], mcphost, mcp-router, Browserbase self-host
MCP [40], servers-archived (Puppeteer, SQLite, Postgres,
and others) [20]. - Stale community bridges or aggregators as
critical-path components: metamcp (last release 2025-12-19), lastmile
mcp-agent (last commit 2026-01-25), mcpo (last commit
2026-02-27) [78]. - Building new features on deprecated Roots, Sampling,
Logging, or HTTP+SSE [2]. - Unvetted registry entries. The registry does
not scan code [13].
9. Recommendations tied to the client’s stated priorities
Local-first / sovereign - Default to stdio servers launched by your host, containerized through ToolHive. Expose remote Streamable HTTP only where you need edge access, and put agentgateway or ToolHive’s gateway in front with OAuth + CIMD [6][55][57]. - Search: self-host SearXNG and use mcp-searxng [43]. Memory: basic-memory (Markdown in git) [46]. Data: DuckDB MCP [51]. - Context7 is convenient, but its backend is closed and it carries a 2026 prompt-injection CVE [41][73]. For sovereign docs retrieval, consider indexing docs yourself into basic-memory or mcp-memory-service.
No vendor lock-in - Use servers that are open source and self-hostable: Playwright MCP, GitHub MCP (local), MCP Toolbox, DuckDB, SearXNG, basic-memory, mcp-memory-service, Graphiti. Hosted-only pieces are Context7’s backend, Figma write-to-canvas (future usage-based pricing [53]), and paid search APIs. - Watch licenses. Serena moved to GPL-3.0-or-later in September 2026 [42]. basic-memory and Cherry Studio are AGPL-3.0 [78]. Fine for internal use; review before any product redistribution.
Budget-conscious - Everything in the adopt table is free to self-host. The costs are optional APIs (Brave, Exa, Tavily, Firecrawl cloud), Figma after the beta, and Docker Desktop licensing for the Toolkit UI (Docker’s terms weren’t checked here, so unknown).
Production-grade - Build on 2026-07-28 and a Tier-1
SDK. Add OTel via the _meta trace context conventions [2].
Write explicit handles for state [2]. Keep tool lists deterministic for
prompt-cache hits [2]. Make pinning, containerization, and least
privilege non-negotiable (§7.4).
By type of work - Agentic coding: opencode
or Codex CLI + GitHub MCP (read-only, trimmed toolsets) + reference git
server (patched) or host-native git + Serena (mind the GPL) + Playwright
MCP for E2E. - Deep research: goose or opencode + mcp-searxng +
reference fetch + basic-memory / Graphiti + DuckDB MCP. Isolate this
“untrusted content” agent from write-capable coding tools. - Browser
+ creative: Playwright MCP (--isolated), Chrome
DevTools MCP (telemetry off), mcp-for-blender (safe mode), and Figma MCP
or Framelink.
10. Risks, unknowns, and things I could not verify
- Rust SDK status conflict. The blog says “beta” for 2026-07-28 support [3]; the SDK page says Tier 1 [17].
- Context7 CVE fix status for the hosted Custom AI Instructions feature: unknown. NVD lists “through 2.1.2”, but the npm MCP package is now 4.1.1 [73][78], and the version schemes may not correspond.
- Registry size. 35,953 is my own API count at 06:51 PT, and one earlier full pass hit an HTTP 500 [15]. There’s no official figure on the pages I read.
- Host-by-host support for 2026-07-28. I didn’t
verify which hosts (opencode, goose, Zed, Cline, LM Studio, Open WebUI)
have implemented the new stateless protocol vs.
2025-11-25. Open WebUI’s docs still referencesession.initialize()timeouts [22], which suggests older-protocol clients. - Local-model quality with MCP. I found no primary benchmark. Vendors (Open WebUI, LM Studio, Cline) warn about context bloat and weak tool use [22][26][28]. Model recommendations in third-party blogs weren’t used as evidence.
- [Redacted: one client-specific hosting platform] was not researched in this pass. Its MCP support is unknown here.
- mem0/OpenMemory MCP details, browser-use MCP details, comfyui-mcp-server details, exa/tavily/perplexity/jina server specifics: metadata only, not deep-read.
- Pricing for paid APIs and Docker Desktop: not checked.
- agentgateway governance (LF-hosted or not): not verified.
- GitHub star counts are snapshots from 2026-09-25 and are only a popularity signal, not quality.
- The unauthenticated GitHub API was rate-limited in the research
environment. Repo metadata came from public HTML pages and Atom feeds
instead [78]. License
NOASSERTIONmeans GitHub couldn’t classify the license file, not that there is no license.
Appendix A. Repo metadata snapshot (2026-09-25)
| Repo (as fetched → final) | License (GitHub SPDX) | Archived | Stars | Last commit (UTC) | Latest release (UTC date) |
|---|---|---|---|---|---|
| 1mcp-app/agent | Apache-2.0 | false | 507 | 2026-09-22 | Release v0.39.0-beta.0 (2026-09-20) |
| agentgateway/agentgateway | Apache-2.0 | false | 5,039 | 2026-09-25 | v1.6.0-alpha.2 (2026-09-22) |
| ahujasid/blender-mcp → ahujasid/mcp-for-blender | MIT | false | 29,326 | 2026-09-25 | — |
| AmoyLab/Unla | MIT | false | 2,235 | 2026-08-27 | v0.10.0 (2026-08-04) |
| awslabs/mcp | Apache-2.0 | false | 9,729 | 2026-09-23 | 2026.09.20260922000649 (2026-09-22) |
| badlogic/pi-mono → earendil-works/pi | MIT | false | 109,292 | 2026-09-25 | v0.87.1 (2026-09-22) |
| basicmachines-co/basic-memory | AGPL-3.0 | false | 4,037 | 2026-09-24 | v0.23.2 (2026-08-25) |
| block/goose → aaif-goose/goose | Apache-2.0 | false | 54,640 | 2026-09-25 | gdk-v0.1.0-alpha.10: chore(GDK): release v0.1… (2026-09-24) |
| brave/brave-search-mcp-server | MIT | false | 1,469 | 2026-09-17 | v2.1.4 (2026-09-17) |
| browser-use/browser-use | MIT | false | 116,250 | 2026-09-15 | 0.13.10 (2026-09-04) |
| browserbase/mcp-server-browserbase | Apache-2.0 | true | 3,413 | 2026-07-20 | v3.0.0 (2026-03-31) |
| CherryHQ/cherry-studio | AGPL-3.0 | false | 52,142 | 2026-09-25 | v2.1.3 (2026-09-24) |
| ChromeDevTools/chrome-devtools-mcp | Apache-2.0 | false | 52,592 | 2026-09-25 | chrome-devtools-mcp: v1.10.1 (2026-09-23) |
| cisco-ai-defense/mcp-scanner | Apache-2.0 | false | 1,079 | 2026-09-19 | 4.8.4 (2026-08-28) |
| cline/cline | Apache-2.0 | false | 69,283 | 2026-09-25 | Desktop v0.0.36 (2026-09-25) |
| cloudflare/mcp-server-cloudflare | Apache-2.0 | false | 4,283 | 2026-09-24 | workers-observability@0.5.5 (2026-08-11) |
| continuedev/continue | Apache-2.0 | false | 36,022 | 2026-07-21 | v2.1.0-vscode (2026-06-19) |
| crystaldba/postgres-mcp | MIT | false | 3,340 | 2026-08-16 | PostgreSQL MCP v0.3.0 (2025-05-16) |
| cyanheads/git-mcp-server | Apache-2.0 | false | 241 | 2026-08-24 | v2.15.3: Flag allow-list regression: working-… (2026-08-24) |
| danny-avila/LibreChat → LibreChat-AI/LibreChat | MIT | false | 44,933 | 2026-09-25 | v0.8.8-rc4 (2026-09-23) |
| docker/mcp-gateway | MIT | false | 1,584 | 2026-09-16 | v0.44.1 (2026-09-23) |
| docker/mcp-registry | MIT | false | 557 | 2026-09-16 | — |
| doobidoo/mcp-memory-service | Apache-2.0 | false | 1,965 | 2026-09-25 | v11.14.0 (2026-09-25) |
| envoyproxy/ai-gateway → theagentrouter/agent-router | Apache-2.0 | false | 2,142 | 2026-09-25 | v1.1.0 (2026-08-21) |
| exa-labs/exa-mcp-server | MIT | false | 5,049 | 2026-09-23 | — |
| executeautomation/mcp-playwright | MIT | false | 5,655 | 2025-12-13 | — |
| firecrawl/firecrawl-mcp-server | MIT | false | 7,512 | 2026-09-25 | v3.24.1: release: 3.24.1 (2026-08-26) |
| getzep/graphiti | Apache-2.0 | false | 31,152 | 2026-09-24 | v0.30.2 - FalkorDB updates (2026-09-08) |
| ggml-org/llama.cpp | MIT | false | 129,487 | 2026-09-25 | b11178 (2026-09-25) |
| github/github-mcp-server | MIT | false | 33,188 | 2026-09-16 | GitHub MCP Server 1.12.2 (2026-09-16) |
| GLips/Figma-Context-MCP | MIT | false | 15,910 | 2026-06-24 | v0.13.2 (2026-06-18) |
| google-gemini/gemini-cli | Apache-2.0 | false | 107,162 | 2026-09-24 | Release v0.62.0-nightly.20260925.gbedef96ef (2026-09-25) |
| googleapis/genai-toolbox → googleapis/mcp-toolbox | Apache-2.0 | false | 16,490 | 2026-09-25 | v1.13.0 (2026-09-25) |
| hangwin/mcp-chrome | MIT | false | 12,453 | 2026-01-06 | v1.0.0 (2025-12-29) |
| highflame-ai/ramparts | Apache-2.0 | false | 96 | 2026-08-21 | v0.8.9 (2026-09-10) |
| IBM/mcp-context-forge | Apache-2.0 | false | 4,528 | 2026-09-25 | v1.0.7-20260921 - Patch Fix - Upstream MCP Pa… (2026-09-21) |
| idosal/git-mcp | Apache-2.0 | false | 8,423 | 2026-05-08 | — |
| ihor-sokoliuk/mcp-searxng | MIT | false | 1,260 | 2026-09-22 | v2.4.0 (2026-09-22) |
| invariantlabs-ai/mcp-scan → snyk/agent-scan | Apache-2.0 | false | 3,090 | 2026-09-25 | Agent Scan v0.6.7-snapshot-a6af81c-1733 (2026-09-25) |
| jina-ai/MCP | Apache-2.0 | false | 865 | 2026-09-18 | — |
| joenorton/comfyui-mcp-server | Apache-2.0 | false | 410 | 2026-02-17 | v1.1.1 - QoL, Bugfixes, CI (2026-02-17) |
| jonigl/mcp-client-for-ollama | MIT | false | 826 | 2026-09-11 | Release v0.35.0 (2026-09-11) |
| Kilo-Org/kilocode | MIT | false | 27,415 | 2026-09-25 | v7.8.0 (pre-release) (2026-09-25) |
| Kong/kong | Apache-2.0 | false | 44,195 | 2026-09-23 | 3.9.3 (2026-06-17) |
| lasso-security/mcp-gateway | MIT | false | 390 | 2026-01-22 | Lasso Guardrails v3 API Support (2026-01-21) |
| lastmile-ai/mcp-agent | Apache-2.0 | false | 8,561 | 2026-01-25 | v0.2.6 (2025-12-05) |
| mark3labs/mcphost | MIT | true | 1,596 | 2026-04-13 | v0.34.0 (2026-03-09) |
| mcp-router/mcp-router | NOASSERTION | true | 2,147 | 2026-09-18 | v0.6.4 — Final release / サポート終了 (2026-09-18) |
| mcp-use/mcp-use | MIT | false | 10,676 | 2026-09-24 | mcp-use 2.7.1-canary.3 (2026-09-24) |
| mcpjungle/MCPJungle | MPL-2.0 | false | 1,280 | 2026-08-02 | 0.4.6 (2026-08-02) |
| mem0ai/mem0 | Apache-2.0 | false | 65,987 | 2026-09-25 | Mem0 Python SDK (v2.2.0) (2026-09-23) |
| metatool-ai/metamcp | MIT | false | 2,686 | 2026-06-22 | 2.4.22 Security updates, custom headers, tool… (2025-12-19) |
| microsoft/markitdown | MIT | false | 186,980 | 2026-09-21 | Version 0.1.8 (2026-09-21) |
| microsoft/mcp | MIT | false | 3,710 | 2026-09-24 | Azure.Mcp.Server 3.0.0-beta.47 (2026-09-24) |
| microsoft/mcp-gateway | MIT | false | 851 | 2026-08-25 | — |
| microsoft/playwright-mcp | Apache-2.0 | false | 37,559 | 2026-09-18 | v0.0.82 (2026-09-18) |
| Mintplex-Labs/anything-llm | MIT | false | 66,457 | 2026-09-24 | AnythingLLM v1.16.2 (2026-09-22) |
| modelcontextprotocol/conformance | NOASSERTION | false | 127 | 2026-09-11 | v0.1.16 (2026-03-27) |
| modelcontextprotocol/csharp-sdk | NOASSERTION | false | 4,541 | 2026-09-19 | v2.2.0 (2026-08-13) |
| modelcontextprotocol/ext-apps | NOASSERTION | false | 2,872 | 2026-09-25 | v2.0.1 (2026-09-24) |
| modelcontextprotocol/go-sdk | NOASSERTION | false | 5,147 | 2026-09-24 | v1.8.0 (2026-09-14) |
| modelcontextprotocol/inspector | NOASSERTION | false | 10,954 | 2026-09-23 | 2.8.0 (2026-09-23) |
| modelcontextprotocol/java-sdk | MIT | false | 3,711 | 2026-09-18 | v2.0.1 (2026-08-19) |
| modelcontextprotocol/kotlin-sdk | NOASSERTION | false | 1,462 | 2026-09-25 | 0.15.0 (2026-07-28) |
| modelcontextprotocol/modelcontextprotocol | NOASSERTION | false | 9,303 | 2026-09-24 | 2026-07-28 (2026-07-28) |
| modelcontextprotocol/php-sdk | NOASSERTION | false | 1,613 | 2026-09-15 | v0.8.1 (2026-08-29) |
| modelcontextprotocol/python-sdk | MIT | false | 24,394 | 2026-09-23 | v2.2.0 (2026-09-07) |
| modelcontextprotocol/registry | NOASSERTION | false | 7,285 | 2026-09-22 | v1.8.1 (2026-08-06) |
| modelcontextprotocol/ruby-sdk | NOASSERTION | false | 918 | 2026-09-25 | v1.6.0 (2026-09-21) |
| modelcontextprotocol/rust-sdk | NOASSERTION | false | 3,950 | 2026-09-24 | rmcp-v3.4.1 (2026-09-23) |
| modelcontextprotocol/servers | NOASSERTION | false | 90,586 | 2026-09-22 | Release 2026.8.31 (2026-08-31) |
| modelcontextprotocol/servers-archived | MIT | true | 304 | 2025-05-28 | — |
| modelcontextprotocol/swift-sdk | NOASSERTION | false | 1,498 | 2026-04-29 | 0.12.1 (2026-05-07) |
| modelcontextprotocol/typescript-sdk | NOASSERTION | false | 13,454 | 2026-09-23 | 1.30.1 (2026-09-23) |
| motherduckdb/mcp-server-motherduck | MIT | false | 524 | 2026-08-19 | v1.0.8 (2026-08-19) |
| NVIDIA/garak | Apache-2.0 | false | 9,353 | 2026-09-16 | v0.17.0 (2026-09-09) |
| obot-platform/obot | MIT | false | 1,050 | 2026-09-24 | v0.25.6 (2026-09-18) |
| ollama/ollama | MIT | false | 181,682 | 2026-09-24 | v0.40.0 (2026-09-25) |
| open-webui/mcpo | MIT | false | 4,386 | 2026-02-27 | v0.0.20 (2026-02-27) |
| open-webui/open-webui | NOASSERTION | false | 153,141 | 2026-09-21 | v0.11.4 (2026-09-21) |
| openai/codex | Apache-2.0 | false | 126,416 | 2026-09-25 | 0.158.0-alpha.14 (2026-09-25) |
| oraios/serena | NOASSERTION | false | 29,793 | 2026-09-24 | mit-final (2026-09-14) |
| perplexityai/modelcontextprotocol | MIT | false | 2,542 | 2026-08-27 | — |
| pomerium/pomerium | Apache-2.0 | false | 5,016 | 2026-09-25 | v0.33.3 (2026-09-09) |
| promptfoo/promptfoo | MIT | false | 25,447 | 2026-09-25 | 0.123.1 (2026-09-18) |
| punkpeye/awesome-mcp-servers | MIT | false | 95,514 | 2026-09-23 | — |
| redis/mcp-redis | MIT | false | 626 | 2026-09-21 | 0.5.1 (2026-08-05) |
| riseandignite/mcp-shield | MIT | false | 555 | 2025-04-26 | — |
| RooCodeInc/Roo-Code | Apache-2.0 | true | 24,297 | 2026-05-15 | Release v3.54.0 (2026-05-15) |
| smithery-ai/cli → arcadeai-labs/smithery-cli | AGPL-3.0 | false | 836 | 2026-05-31 | v1.2.0 (2026-05-31) |
| snyk/agent-scan | Apache-2.0 | false | 3,090 | 2026-09-25 | Agent Scan v0.6.7-snapshot-a6af81c-1733 (2026-09-25) |
| sparfenyuk/mcp-proxy | MIT | false | 2,767 | 2026-05-14 | v0.12.0 (2026-05-14) |
| sst/opencode → anomalyco/opencode | MIT | false | 209,973 | 2026-09-25 | v2.0.16 (2026-09-24) |
| stacklok/toolhive | Apache-2.0 | false | 2,206 | 2026-09-25 | v0.51.2 (2026-09-25) |
| stripe/agent-toolkit → stripe/ai | MIT | false | 1,832 | 2026-09-25 | — |
| supabase-community/supabase-mcp → supabase/mcp | Apache-2.0 | false | 2,921 | 2026-09-23 | mcp-server-supabase: v0.13.0 (2026-09-17) |
| tavily-ai/tavily-mcp | MIT | false | 2,407 | 2026-09-16 | — |
| TBXark/mcp-proxy | MIT | false | 734 | 2026-09-15 | v1.1.0 (2026-09-15) |
| trailofbits/mcp-context-protector | Apache-2.0 | false | 226 | 2026-02-13 | — |
| upstash/context7 | MIT | false | 62,417 | 2026-09-24 | @upstash/context7-tools-ai-sdk@1.0.2 (2026-09-22) |
| vllm-project/vllm | Apache-2.0 | false | 92,665 | 2026-09-25 | v0.30.1rc0: [ROCm][CI] Add MI355 dense NVFP4 … (2026-09-23) |
| wonderwhy-er/DesktopCommanderMCP | MIT | false | 9,742 | 2026-09-25 | Release Notes — v0.2.51 (2026-09-17) |
| zed-industries/zed | NOASSERTION | false | 90,869 | 2026-09-25 | nightly: cloud_api_client: Update yawc to 0.4… (2026-09-24) |
Sources
- MCP Versioning: https://modelcontextprotocol.io/specification/versioning
- MCP 2026-07-28 Changelog: https://modelcontextprotocol.io/specification/2026-07-28/changelog
- MCP Blog, “The 2026-07-28 Specification” (2026-07-28): https://blog.modelcontextprotocol.io/posts/2026-07-28/
- Spec releases on GitHub: https://github.com/modelcontextprotocol/modelcontextprotocol/releases
- Transports (2026-07-28): https://modelcontextprotocol.io/specification/2026-07-28/basic/transports
- Authorization (2026-07-28): https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization
- Elicitation (2026-07-28): https://modelcontextprotocol.io/specification/2026-07-28/client/elicitation
- Tools (2026-07-28): https://modelcontextprotocol.io/specification/2026-07-28/server/tools
- MCP Roadmap (updated 2026-08-22): https://modelcontextprotocol.io/development/roadmap
- Governance and Stewardship: https://modelcontextprotocol.io/community/governance
- MCP Blog, “MCP joins the Agentic AI Foundation” (2025-12-09): https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/
- Linux Foundation AAIF press release: https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation
- The MCP Registry (about): https://modelcontextprotocol.io/registry/about
- Registry repo README: https://github.com/modelcontextprotocol/registry
- Registry API (own count, 2026-09-25 06:51 PT): https://registry.modelcontextprotocol.io/v0.1/servers?version=latest
- SDK Tiering System: https://modelcontextprotocol.io/community/sdk-tiers
- SDK list with tiers: https://modelcontextprotocol.io/docs/sdk
- TypeScript SDK README: https://github.com/modelcontextprotocol/typescript-sdk
- MCP Blog index (Ruby SDK 1.0, 2026-07-27): https://blog.modelcontextprotocol.io/
- Reference servers README + LICENSE: https://github.com/modelcontextprotocol/servers
- FastMCP releases: https://github.com/PrefectHQ/fastmcp/releases
- Open WebUI MCP docs: https://docs.openwebui.com/features/extensibility/mcp/
- opencode MCP servers docs: https://opencode.ai/docs/mcp-servers/
- Zed MCP docs: https://zed.dev/docs/ai/mcp
- Codex MCP docs: https://developers.openai.com/codex/mcp
- LM Studio MCP docs: https://lmstudio.ai/docs/app/mcp
- Cline, running models locally: https://docs.cline.bot/running-models-locally/overview
- Cline blog, local models (compact prompt drops MCP): https://cline.bot/blog/local-models
- Cline MCP overview: https://docs.cline.bot/mcp/mcp-overview
- goose README: https://github.com/aaif-goose/goose
- Continue README (read-only notice): https://github.com/continuedev/continue
- Roo Code repo (archived): https://github.com/RooCodeInc/Roo-Code
- Ollama PR #13700 (closed, unmerged): https://github.com/ollama/ollama/pull/13700
- mcp-client-for-ollama (ollmcp): https://github.com/jonigl/mcp-client-for-ollama
- mcphost (archived): https://github.com/mark3labs/mcphost
- mcpo README: https://github.com/open-webui/mcpo
- GitHub MCP Server README: https://github.com/github/github-mcp-server
- Playwright MCP README: https://github.com/microsoft/playwright-mcp
- Chrome DevTools MCP README: https://github.com/ChromeDevTools/chrome-devtools-mcp
- Browserbase MCP (archived): https://github.com/browserbase/mcp-server-browserbase
- Context7 README: https://github.com/upstash/context7
- Serena LICENSE and
mit-finaltag: https://github.com/oraios/serena/blob/main/LICENSE ; https://github.com/oraios/serena/releases/tag/mit-final - mcp-searxng README: https://github.com/ihor-sokoliuk/mcp-searxng
- Firecrawl MCP README: https://github.com/firecrawl/firecrawl-mcp-server
- Graphiti MCP server README: https://github.com/getzep/graphiti/tree/main/mcp_server
- basic-memory README: https://github.com/basicmachines-co/basic-memory
- mcp-memory-service README: https://github.com/doobidoo/mcp-memory-service
- MCP Toolbox for Databases README: https://github.com/googleapis/mcp-toolbox
- postgres-mcp README: https://github.com/crystaldba/postgres-mcp
- Supabase MCP README: https://github.com/supabase/mcp
- DuckDB/MotherDuck local MCP README: https://github.com/motherduckdb/mcp-server-motherduck
- MCP for Blender README: https://github.com/ahujasid/mcp-for-blender
- Figma, Guide to the Figma MCP server: https://help.figma.com/hc/en-us/articles/32132100833559-Guide-to-the-Figma-MCP-server
- Docker MCP Gateway README: https://github.com/docker/mcp-gateway
- ToolHive README: https://github.com/stacklok/toolhive
- IBM ContextForge README: https://github.com/IBM/mcp-context-forge
- agentgateway README: https://github.com/agentgateway/agentgateway
- Snyk Agent Scan README: https://github.com/snyk/agent-scan
- Cisco AI Defense MCP Scanner README: https://github.com/cisco-ai-defense/mcp-scanner
- Trail of Bits mcp-context-protector README: https://github.com/trailofbits/mcp-context-protector
- MCP Security Best Practices (2026-07-28): https://modelcontextprotocol.io/specification/2026-07-28/basic/security_best_practices
- Invariant Labs, Tool Poisoning Attacks (2025-04-01): https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
- Invariant Labs, GitHub MCP Exploited (2025-05-26): https://invariantlabs.ai/blog/mcp-github-vulnerability
- OWASP MCP Top 10: https://owasp.org/www-project-mcp-top-10/
- NVD CVE-2025-6514 (mcp-remote): https://nvd.nist.gov/vuln/detail/CVE-2025-6514
- NVD CVE-2025-49596 (MCP Inspector): https://nvd.nist.gov/vuln/detail/CVE-2025-49596
- NVD CVE-2025-53109 (filesystem symlink): https://nvd.nist.gov/vuln/detail/CVE-2025-53109
- NVD CVE-2025-53110 (filesystem prefix): https://nvd.nist.gov/vuln/detail/CVE-2025-53110
- NVD CVE-2025-68143 / 68144 / 68145 (mcp-server-git): https://nvd.nist.gov/vuln/detail/CVE-2025-68143 ; https://nvd.nist.gov/vuln/detail/CVE-2025-68144 ; https://nvd.nist.gov/vuln/detail/CVE-2025-68145
- NVD CVE-2025-66414 (TS SDK DNS rebinding): https://nvd.nist.gov/vuln/detail/CVE-2025-66414
- NVD CVE-2026-52869 (Python SDK session authz): https://nvd.nist.gov/vuln/detail/CVE-2026-52869
- NVD CVE-2026-46519 (mcp-server-kubernetes): https://nvd.nist.gov/vuln/detail/CVE-2026-46519
- NVD CVE-2026-75130 (Context7 prompt injection): https://nvd.nist.gov/vuln/detail/CVE-2026-75130
- NVD CVE-2026-73496 (MCP Atlassian path traversal): https://nvd.nist.gov/vuln/detail/CVE-2026-73496
- OSV MAL-2025-47604 (postmark-mcp): https://osv.dev/vulnerability/MAL-2025-47604
- The Hacker News on postmark-mcp (2025-09-29): https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html
- Pi (pi.dev): https://pi.dev
- GitHub repo pages and Atom feeds (
/commits.atom,/releases.atom) for every repo in Appendix A, fetched 2026-09-25. Example: https://github.com/microsoft/playwright-mcp/releases.atom - mcp-router (archived, final release): https://github.com/mcp-router/mcp-router
- Anthropic, Donating MCP and establishing the AAIF: https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation