{"asOf":"2026-09-20","source":"Small Print, https://smallprint.dev/stats","licence":"Cite with the date and the link.","takeaways":[{"id":"entries","line":"84,544 MCP servers, skills and plugins are listed across 12 public sources.","value":84544,"method":"One entry per package identity (an npm or PyPI name, a container image, a registry id, a skill's repository path). Versions and mirrors are not counted twice."},{"id":"read","line":"40,331 entries (47.7%) have had their small print read: tool definitions extracted, a tool list fetched, or every file hashed.","value":40331,"method":"Entries with at least one version carrying a content hash."},{"id":"tools-total","line":"1,238,393 tool definitions are on record across 29,514 MCP servers.","value":1238393,"method":"Length of the extracted tool list on the latest read version of each server."},{"id":"tools-median","line":"The median MCP server exposes 8 tools.","value":8,"method":"Median of per-server tool counts on the latest read version."},{"id":"desc-median","line":"The median tool description is 162 characters long.","value":162,"method":"Median length of the description field across tool definitions on latest read versions."},{"id":"drift-total","line":"45,064 changes to the small print are on record.","value":45064,"method":"Drift events other than a plain version bump: a tool added or removed, a description, schema or instruction change."},{"id":"drift-30","line":"45,064 changes were recorded in the last 30 days, 30,736 in the last 7.","value":45064,"method":"Drift events by detection date."},{"id":"instr-changes","line":"1,244 changes rewrote a skill's instructions.","value":1244,"method":"Drift events of kind skill.instructions."},{"id":"high-exfil","line":"224 changes added text that names a secret-bearing file, a named address, or the vocabulary of exfiltration.","value":224,"method":"Drift events graded high under the exfiltration rule; the rule and its patterns are on the grading page."},{"id":"high-override","line":"102 changes added an instruction to hide something from the user or to ignore prior instructions.","value":102,"method":"Drift events graded high under the override rule."},{"id":"adv-total","line":"3,326 security advisories about MCP servers, skills and their dependencies are on record.","value":3326,"method":"Advisories ingested from ghsa (1,224), osv (1,058), nvd (989), vulnerablemcp (46), incident-backfill (8), csa-mcps (1), each attributed to its source."},{"id":"adv-malware","line":"1,131 advisories carry a malware identifier from the GitHub Advisory Database.","value":1131,"method":"Advisories whose id or alias is a MAL- record; the word is the database's, attributed."},{"id":"remote-ok","line":"20,041 of 36,098 remote MCP servers (55.5%) return a tool list without a sign-in.","value":20041,"method":"Remote reads with status ok: initialize then tools/list over streamable HTTP or SSE, nothing called."},{"id":"remote-auth","line":"4,311 (11.9%) require a sign-in before listing tools.","value":4311,"method":"Remote reads answered 401 or 403."}],"sections":[{"id":"how-many","question":"How many MCP servers, agent skills and plugins are there?","answer":"Small Print lists 84,544 entries across 12 public sources as of 2026-09-20: 55,363 MCP servers, 24,553 agent skills and 4,628 plugins, counting one entry per package identity, never per version and never per mirror.","stats":[{"id":"entries","line":"84,544 MCP servers, skills and plugins are listed across 12 public sources.","value":84544,"method":"One entry per package identity (an npm or PyPI name, a container image, a registry id, a skill's repository path). Versions and mirrors are not counted twice."},{"id":"servers","line":"55,363 of them are MCP servers.","value":55363,"method":"Entries of kind mcp."},{"id":"skills","line":"24,553 are agent skills and 4,628 are plugins.","value":24553,"method":"Entries of kind agent-skill and agent-plugin."},{"id":"read","line":"40,331 entries (47.7%) have had their small print read: tool definitions extracted, a tool list fetched, or every file hashed.","value":40331,"method":"Entries with at least one version carrying a content hash."},{"id":"shared-repos","line":"3,130 repositories are listed under more than one entry, such as the same server on npm and in a container registry.","value":3130,"method":"Distinct repository URLs that appear on two or more entries."},{"id":"versions","line":"111,157 versions are on record, 51,614 of them read.","value":111157,"method":"Rows in the version table; read means a content hash is stored."}]},{"id":"tools","question":"How many tools does an MCP server expose, and how long is a tool description?","answer":"Across 29,514 servers whose latest version has been read, 1,238,393 tool definitions are on record; the median server exposes 8 tools and the median tool description is 162 characters.","stats":[{"id":"tools-total","line":"1,238,393 tool definitions are on record across 29,514 MCP servers.","value":1238393,"method":"Length of the extracted tool list on the latest read version of each server."},{"id":"tools-median","line":"The median MCP server exposes 8 tools.","value":8,"method":"Median of per-server tool counts on the latest read version."},{"id":"tools-big","line":"1,684 servers expose 50 or more tools.","value":1684,"method":"Servers whose latest read version lists at least 50 tools."},{"id":"tools-none","line":"5,954 servers were read and declare no tools statically, which usually means the tool list is built at run time from an API description or a database.","value":5954,"method":"Latest versions read with an empty extracted tool list."},{"id":"desc-median","line":"The median tool description is 162 characters long.","value":162,"method":"Median length of the description field across tool definitions on latest read versions."},{"id":"desc-long","line":"5,805 tool descriptions run to 500 characters or more.","value":5805,"method":"Descriptions of at least 500 characters on latest read versions."}]},{"id":"change","question":"How often does the small print change between versions?","answer":"45,064 changes to tool descriptions, schemas, tool lists and skill instructions are on record across 4,718 entries and 6,257 releases, 45,064 of them in the last 30 days.","stats":[{"id":"drift-total","line":"45,064 changes to the small print are on record.","value":45064,"method":"Drift events other than a plain version bump: a tool added or removed, a description, schema or instruction change."},{"id":"drift-30","line":"45,064 changes were recorded in the last 30 days, 30,736 in the last 7.","value":45064,"method":"Drift events by detection date."},{"id":"drift-7","line":"30,736 changes were recorded in the last 7 days.","value":30736,"method":"Drift events by detection date, last seven days."},{"id":"drift-assets","line":"4,718 entries have changed their small print at least once since being read.","value":4718,"method":"Distinct entries with at least one drift event."},{"id":"drift-releases","line":"6,257 releases changed the small print.","value":6257,"method":"Distinct (entry, new version) pairs with at least one change."},{"id":"desc-changes","line":"14,330 of the changes rewrote a tool description; 15,010 changed an input schema.","value":14330,"method":"Drift events by field."},{"id":"tools-added","line":"11,895 tools were added in a release and 2,023 removed.","value":11895,"method":"Drift events of kind tool.added and tool.removed."},{"id":"instr-changes","line":"1,244 changes rewrote a skill's instructions.","value":1244,"method":"Drift events of kind skill.instructions."},{"id":"bumps-same","line":"5,899 of 11,967 version bumps (49.3%) changed nothing in the small print.","value":5899,"method":"Version bumps whose canonical content hash is identical to the previous version."}]},{"id":"graded","question":"How many changes name a secret, a destination, or an instruction to hide something?","answer":"326 recorded changes grade high under Small Print's printed rules: 224 add text that names a secret-bearing file, a named address or the vocabulary of exfiltration, and 102 tell the agent to hide something from the user or ignore its instructions. A grade is the output of a published rule applied to public text, not a verdict on anyone.","stats":[{"id":"high-exfil","line":"224 changes added text that names a secret-bearing file, a named address, or the vocabulary of exfiltration.","value":224,"method":"Drift events graded high under the exfiltration rule; the rule and its patterns are on the grading page."},{"id":"high-override","line":"102 changes added an instruction to hide something from the user or to ignore prior instructions.","value":102,"method":"Drift events graded high under the override rule."},{"id":"high-share","line":"0.7% of all recorded changes grade high.","value":326,"method":"High-graded events over all drift events other than version bumps."}]},{"id":"advisories","question":"How many security advisories name MCP servers and agent skills?","answer":"3,326 advisories are on record from 6 sources, 3,185 of them linked to a catalog entry and version range; 1,395 entries carry at least one.","stats":[{"id":"adv-total","line":"3,326 security advisories about MCP servers, skills and their dependencies are on record.","value":3326,"method":"Advisories ingested from ghsa (1,224), osv (1,058), nvd (989), vulnerablemcp (46), incident-backfill (8), csa-mcps (1), each attributed to its source."},{"id":"adv-linked","line":"3,185 advisories are linked to an exact package and version range.","value":3185,"method":"Advisories with at least one affected entry and range resolved in the catalog."},{"id":"adv-critical","line":"2,255 advisories are critical and 640 high, by CVSS score or the source's own rating.","value":2255,"method":"Grades follow the printed advisory rules: CVSS bands first, then the source label."},{"id":"adv-malware","line":"1,131 advisories carry a malware identifier from the GitHub Advisory Database.","value":1131,"method":"Advisories whose id or alias is a MAL- record; the word is the database's, attributed."},{"id":"adv-assets","line":"1,395 entries carry at least one advisory.","value":1395,"method":"Distinct entries with an advisory link."}]},{"id":"remote","question":"How many remote MCP servers answer a tools/list request?","answer":"Of 36,098 remote servers asked for their tool list in one conversation, 20,041 (55.5%) answered with tools, 4,311 asked for a sign-in first, 9,509 did not answer, and 2,212 answered with something that was not MCP.","stats":[{"id":"remote-ok","line":"20,041 of 36,098 remote MCP servers (55.5%) return a tool list without a sign-in.","value":20041,"method":"Remote reads with status ok: initialize then tools/list over streamable HTTP or SSE, nothing called."},{"id":"remote-auth","line":"4,311 (11.9%) require a sign-in before listing tools.","value":4311,"method":"Remote reads answered 401 or 403."},{"id":"remote-down","line":"9,509 (26.3%) did not answer at all.","value":9509,"method":"Remote reads with no usable response inside the deadline."},{"id":"remote-protocol","line":"2,212 answered with something that was not MCP.","value":2212,"method":"Remote reads that returned a non-MCP response."}]},{"id":"languages","question":"What languages are MCP servers written in?","answer":"Among versions read from source, js 4,822, remote 4,501, python 2,987, ts 1,841, and others, counting each language that contributed tool definitions to a version.","stats":[{"id":"lang-js","line":"4,822 read versions carry tool definitions written in JavaScript.","value":4822,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."},{"id":"lang-remote","line":"4,501 read versions carry tool definitions written in Remote.","value":4501,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."},{"id":"lang-python","line":"2,987 read versions carry tool definitions written in Python.","value":2987,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."},{"id":"lang-ts","line":"1,841 read versions carry tool definitions written in TypeScript.","value":1841,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."},{"id":"lang-go","line":"456 read versions carry tool definitions written in Go.","value":456,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."},{"id":"lang-smithery-api","line":"348 read versions carry tool definitions written in Smithery-api.","value":348,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."},{"id":"lang-rust","line":"276 read versions carry tool definitions written in Rust.","value":276,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."},{"id":"lang-csharp","line":"96 read versions carry tool definitions written in C#.","value":96,"method":"Versions whose extraction label includes the language; a version read from two languages counts once for each."}]},{"id":"press","question":"How often does the security press name a specific MCP server or skill?","answer":"Of 87 articles read from the security feeds, 3 name a package in the catalog by its exact name, covering 5 entries.","stats":[{"id":"news-linked","line":"3 of 87 security articles name a catalog package outright.","value":3,"method":"Articles matched to an entry by exact registry name, scoped name or repository URL; the headline stays the source's own."},{"id":"news-assets","line":"5 entries have been named in at least one article.","value":5,"method":"Distinct entries with a press mention."}]},{"id":"record","question":"How can anyone check that the record was not edited after the fact?","answer":"Every night one chain row is written: the version hashes recorded that night are listed and hashed, and that hash is hashed with the previous night's row. 4 rows link 76,806 recorded hashes so far; the latest, for 2026-09-20, is 5ce942894a62563cc5f50d58c26b496d5eaf60f404c3079a395b72c9c657b65f. Every row and the lines behind it are at /api/chain, so a reader who kept any earlier row can recompute the chain and see whether a recorded hash changed since.","stats":[{"id":"chain-days","line":"4 nightly chain rows link 76,806 recorded version hashes.","value":4,"method":"Rows in the record chain; each covers the versions whose content hash was recorded since the previous row, hashed with the previous row's chain hash. Method and every row: /api/chain."}]}],"sources":[{"registry":"mcp-registry","listed":22659,"read":14721},{"registry":"skills.sh","listed":20826,"read":2402},{"registry":"npm","listed":11265,"read":3150},{"registry":"huggingface","listed":10660,"read":3004},{"registry":"smithery","listed":6351,"read":6139},{"registry":"pypi","listed":3852,"read":2778},{"registry":"clawhub","listed":3727,"read":3257},{"registry":"anthropic-plugins","listed":2707,"read":2604},{"registry":"gemini","listed":1921,"read":1868},{"registry":"docker","listed":325,"read":205},{"registry":"github","listed":178,"read":132},{"registry":"zed","listed":73,"read":71}],"languages":[{"language":"js","versions":4822},{"language":"remote","versions":4501},{"language":"python","versions":2987},{"language":"ts","versions":1841},{"language":"go","versions":456},{"language":"smithery-api","versions":348},{"language":"rust","versions":276},{"language":"csharp","versions":96},{"language":"java","versions":22},{"language":"kotlin","versions":2}]}