Small Printthe tool description is the small print. we read it every day.

MCP server statistics, 2026

as of 2026-09-21 ·

This page answers a few plain questions. How many MCP servers, agent skills and plugins exist? How many tools do they expose? How often does their small print change? How many security advisories name them? How many remote servers answer when asked? Every number below is counted from Small Print's own record, which is read again every night. Each number says how it was counted and on what day. You are welcome to quote any line with its link. The numbers move every night, so please cite the date.

Key figures

How many MCP servers, agent skills and plugins are there?

As of 2026-09-21, Small Print lists 84,544 entries across 12 public sources. That is 55,363 MCP servers, 24,553 agent skills and 4,628 plugins. Each package counts once, no matter how many versions it has or how many places list it.

  • 84,544 MCP servers, skills and plugins are listed across 12 public sources. One entry per package identity (an npm or PyPI name, a container image, a registry id, a skill's repository path). Versions and mirrors are not counted twice. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#entries
  • 55,363 of them are MCP servers. Entries of kind mcp. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#servers
  • 24,553 are agent skills and 4,628 are plugins. Entries of kind agent-skill and agent-plugin. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#skills
  • 40,331 entries (47.7%) have had their small print read: tool definitions extracted, a tool list fetched, or every file hashed. Entries with at least one version carrying a content hash. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#read
  • 3,130 repositories are listed under more than one entry, such as the same server on npm and in a container registry. Distinct repository URLs that appear on two or more entries. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#shared-repos
  • 111,157 versions are on record, 51,614 of them read. Rows in the version table; read means a content hash is stored. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#versions
sourcelistedread
the official MCP registry22,65914,721
skills.sh20,8262,402
npm11,2653,150
Hugging Face Spaces10,6603,004
Smithery6,3516,139
PyPI3,8522,778
ClawHub3,7273,257
Claude Code marketplaces2,7072,604
Gemini CLI extensions1,9211,868
Docker's MCP registry325205
advisory-named repositories178132
Zed7371

"Listed" means the source publishes the entry under its own name. "Read" means Small Print has fetched the entry and fingerprinted its small print. Here is what counts as one entry for each source.

How many tools does an MCP server expose, and how long is a tool description?

Small Print has read the latest version of 29,514 servers, and those servers define 1,238,393 tools between them. The typical server exposes 8 tools, and the typical tool description is 162 characters long.

  • 1,238,393 tool definitions are on record across 29,514 MCP servers. Length of the extracted tool list on the latest read version of each server. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#tools-total
  • The median MCP server exposes 8 tools. Median of per-server tool counts on the latest read version. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#tools-median
  • 1,684 servers expose 50 or more tools. Servers whose latest read version lists at least 50 tools. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#tools-big
  • 5,954 servers were read and declare no tools statically, which usually means the tool list is built at run time from an API description or a database. Latest versions read with an empty extracted tool list. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#tools-none
  • The median tool description is 162 characters long. Median length of the description field across tool definitions on latest read versions. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#desc-median
  • 5,805 tool descriptions run to 500 characters or more. Descriptions of at least 500 characters on latest read versions. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#desc-long

The five largest tool lists on record: ghcr.io/mcparmory/agentql:1.0.8 (8,978), ghcr.io/mcparmory/ahrefs:1.0.3 (8,978), ghcr.io/mcparmory/airtable:1.0.3 (8,978), ghcr.io/mcparmory/alchemy-nft:1.0.3 (8,978), ghcr.io/mcparmory/algolia-search:1.0.11 (8,978).

How often does the small print change between versions?

45,064 changes are on record. A change is any edit to a tool description, a tool's input form, the list of tools, or a skill's instructions. Those changes are spread across 4,718 entries and 6,257 releases, and 45,064 of them happened in the last 30 days.

  • 45,064 changes to the small print are on record. Drift events other than a plain version bump: a tool added or removed, a description, schema or instruction change. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#drift-total
  • 45,064 changes were recorded in the last 30 days, 30,736 in the last 7. Drift events by detection date. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#drift-30
  • 30,736 changes were recorded in the last 7 days. Drift events by detection date, last seven days. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#drift-7
  • 4,718 entries have changed their small print at least once since being read. Distinct entries with at least one drift event. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#drift-assets
  • 6,257 releases changed the small print. Distinct (entry, new version) pairs with at least one change. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#drift-releases
  • 14,330 of the changes rewrote a tool description; 15,010 changed an input schema. Drift events by field. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#desc-changes
  • 11,895 tools were added in a release and 2,023 removed. Drift events of kind tool.added and tool.removed. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#tools-added
  • 1,244 changes rewrote a skill's instructions. Drift events of kind skill.instructions. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#instr-changes
  • 5,899 of 11,967 version bumps (49.3%) changed nothing in the small print. Version bumps whose canonical content hash is identical to the previous version. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#bumps-same

The five entries with the most recorded changes: @respira/wordpress-mcp-server (4,280), @jshookmcp/jshook (670), @oracle-agent/oracle (439), @browserstack/mcp-server (366), @avallon-labs/mcp (343). A high count means the server is being developed actively. It does not mean there is a problem with it.

How many changes name a secret, a destination, or an instruction to hide something?

326 recorded changes are graded high under Small Print's written rules. 224 of them add text that names a file holding secrets, a network address, or words about moving data out. The other 102 add text that tells the agent to hide something from the user or to ignore its instructions. A grade is the result of a published rule applied to public text. It is not a verdict on anyone.

  • 224 changes added text that names a secret-bearing file, a named address, or the vocabulary of exfiltration. Drift events graded high under the exfiltration rule; the rule and its patterns are on the grading page. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#high-exfil
  • 102 changes added an instruction to hide something from the user or to ignore prior instructions. Drift events graded high under the override rule. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#high-override
  • 0.7% of all recorded changes grade high. High-graded events over all drift events other than version bumps. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#high-share

How many security advisories name MCP servers and agent skills?

3,326 security advisories are on record, from 6 sources. 3,185 of them are matched to an entry in the catalog and to the versions they affect. 1,395 entries carry at least one advisory.

  • 3,326 security advisories about MCP servers, skills and their dependencies are on record. Advisories ingested from ghsa (1,224), osv (1,058), nvd (989), vulnerablemcp (46), incident-backfill (8), csa-mcps (1), each attributed to its source. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#adv-total
  • 3,185 advisories are linked to an exact package and version range. Advisories with at least one affected entry and range resolved in the catalog. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#adv-linked
  • 2,255 advisories are critical and 640 high, by CVSS score or the source's own rating. Grades follow the printed advisory rules: CVSS bands first, then the source label. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#adv-critical
  • 1,131 advisories carry a malware identifier from the GitHub Advisory Database. Advisories whose id or alias is a MAL- record; the word is the database's, attributed. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#adv-malware
  • 1,395 entries carry at least one advisory. Distinct entries with an advisory link. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#adv-assets

How many remote MCP servers answer a tools/list request?

Small Print asked 36,098 remote servers for their tool list, using one request each. 20,041 of them (55.5 percent) answered with a list of tools. 4,311 asked for a sign-in first. 9,509 did not answer at all. 2,212 answered with something that was not MCP.

  • 20,041 of 36,098 remote MCP servers (55.5%) return a tool list without a sign-in. Remote reads with status ok: initialize then tools/list over streamable HTTP or SSE, nothing called. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#remote-ok
  • 4,311 (11.9%) require a sign-in before listing tools. Remote reads answered 401 or 403. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#remote-auth
  • 9,509 (26.3%) did not answer at all. Remote reads with no usable response inside the deadline. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#remote-down
  • 2,212 answered with something that was not MCP. Remote reads that returned a non-MCP response. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#remote-protocol

What languages are MCP servers written in?

Of the versions that were read from their published code, the languages break down as follows: js 4,822, remote 4,501, python 2,987, ts 1,841, and others. A version counts under each language that contributed tool definitions to it.

  • 4,822 read versions carry tool definitions written in JavaScript. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-js
  • 4,501 read versions carry tool definitions written in Remote. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-remote
  • 2,987 read versions carry tool definitions written in Python. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-python
  • 1,841 read versions carry tool definitions written in TypeScript. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-ts
  • 456 read versions carry tool definitions written in Go. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-go
  • 348 read versions carry tool definitions written in Smithery-api. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-smithery-api
  • 276 read versions carry tool definitions written in Rust. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-rust
  • 96 read versions carry tool definitions written in C#. Versions whose extraction label includes the language; a version read from two languages counts once for each. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#lang-csharp

How often does the security press name a specific MCP server or skill?

Small Print has read 87 articles from the security news feeds it follows. 3 of them name a package in the catalog by its exact name, and those articles cover 5 entries.

  • 3 of 87 security articles name a catalog package outright. Articles matched to an entry by exact registry name, scoped name or repository URL; the headline stays the source's own. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#news-linked
  • 5 entries have been named in at least one article. Distinct entries with a press mention. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#news-assets

How can anyone check that the record was not edited after the fact?

Every night, Small Print writes one row to a chain. That row lists the fingerprints recorded that night, takes a fingerprint of the whole list, and combines it with the previous night's row. So far, 4 rows cover 76,806 recorded fingerprints. The latest row, for 2026-09-20, is 5ce942894a62563cc5f50d58c26b496d5eaf60f404c3079a395b72c9c657b65f. Every row, and the lines behind it, can be read at /api/chain. Anyone who saved an earlier row can recompute the chain and see whether any recorded fingerprint changed since then.

  • 4 nightly chain rows link 76,806 recorded version hashes. Rows in the record chain; each covers the versions whose content hash was recorded since the previous row, hashed with the previous row's chain hash. Method and every row: /api/chain. Cite: Small Print, MCP server statistics, 2026-09-21, https://smallprint.dev/stats#chain-days
The weekly reportevery Monday, by email, with one link to confirm

You do not need an account or a password. Every issue has an unsubscribe link.

How these numbers are made

Small Print counts one entry per package across twelve public sources, and it reads all of them again every night. For servers, it reads the tool definitions from the published code. For remote servers, it asks for the tool list without calling any tool. For skills, it fingerprints every file. Security advisories are matched to entries by the version range they name. When a source stops listing an entry, Small Print asks that source directly. Every grade follows a written rule. The word malicious appears on this site only inside a source's own statement. A machine-readable copy of these numbers is at /api/stats. To correct anything, use the dispute form or write to hello@smallprint.dev.