State of the Agent Attack Surface

An independent, continuously re-run, ed25519-signed measurement of the public MCP agent attack surface. Measured from outside — a third-party observation, not a vulnerability scan, not malware detection, and not a claim any server is unsafe. Edition 2026-08-02 · classifier capability-classify/0.1 · standard agent-tool-discoverability-standard/0.4.

19.7% of state-changing tools on the enumerable surface publish NO machine-readable safety annotation — a calling agent cannot automatically tell a read from a write, delete, or payment before invoking them.
Classification of the DECLARED tool surface (published tools/list name + description) — an observation, NOT a vulnerability/malware scan, NOT proof of runtime behavior, and NOT a claim any server is unsafe or compromised. 'Unlabeled state-changing' means no ToolAnnotations safety hint was published (a hygiene/discoverability gap a caller must gate manually), not evidence of harm.

The externally-observable surface

Capability landscape (declared tools)

ClassWhat it can doKindTools% of declared
paymentPayment / funds movementstate-changing787012.5%
code_execCode / command executionstate-changing16462.6%
fs_writeState change / write / deletestate-changing1281920.3%
credentialIdentity / credential / accountstate-changing1148618.2%
network_outOutbound fetch (SSRF-relevant)read921814.6%
messagingSend message / post / notifystate-changing13822.2%
data_readRead / search / listread5338184.7%

Safety labeling of state-changing capability

This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.

Exposure tiers

Tier is derived ONLY from the declared surface's highest capability class (high = payment or code-execution declared; moderate = write/credential/network; read-oriented = retrieval only). It is a description of exposure, not a safety verdict.

Capability change over time

4648 servers now have 2+ capability snapshots; 89 newly exposed a higher-risk class since first observed. Capability-surface tracking is YOUNG (per-tool capture began 2026-07). This longitudinal signal — 'a server newly exposed a higher-risk class since first observed' — is the part an agent cannot self-produce, and it compounds with every crawl. Small counts here reflect the short history, not a claim of stability.

Verify it yourself

ed25519-signed, offline-verifiable, reproducible. Issuer pubkey 302a300506032b6570032100439ce47d…. Re-run the audit + classifier against any server to reproduce it — no callback to SaSame required.


SaSame MCP Observatory — a neutral, third-party measurement layer for the AI agent economy. Capability classes are observations of the declared surface, never safety, malware, or trust verdicts. Corrections & delistings: consulting@srl-sasame.com. Per-server defensive pre-call checks are available over MCP (capability_profile) — aggregate report never names individual servers.