An independent, continuously re-run, ed25519-signed measurement of the public MCP agent attack surface. Measured from outside — a third-party observation, not a vulnerability scan, not malware detection, and not a claim any server is unsafe. Edition 2026-08-02 · classifier capability-classify/0.1 · standard agent-tool-discoverability-standard/0.4.
| Class | What it can do | Kind | Tools | % of declared |
|---|---|---|---|---|
payment | Payment / funds movement | state-changing | 7870 | 12.5% |
code_exec | Code / command execution | state-changing | 1646 | 2.6% |
fs_write | State change / write / delete | state-changing | 12819 | 20.3% |
credential | Identity / credential / account | state-changing | 11486 | 18.2% |
network_out | Outbound fetch (SSRF-relevant) | read | 9218 | 14.6% |
messaging | Send message / post / notify | state-changing | 1382 | 2.2% |
data_read | Read / search / list | read | 53381 | 84.7% |
This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.
Tier is derived ONLY from the declared surface's highest capability class (high = payment or code-execution declared; moderate = write/credential/network; read-oriented = retrieval only). It is a description of exposure, not a safety verdict.
4648 servers now have 2+ capability snapshots; 89 newly exposed a higher-risk class since first observed. Capability-surface tracking is YOUNG (per-tool capture began 2026-07). This longitudinal signal — 'a server newly exposed a higher-risk class since first observed' — is the part an agent cannot self-produce, and it compounds with every crawl. Small counts here reflect the short history, not a claim of stability.
ed25519-signed, offline-verifiable, reproducible. Issuer pubkey 302a300506032b6570032100439ce47d…. Re-run the audit + classifier against any server to reproduce it — no callback to SaSame required.
SaSame MCP Observatory — a neutral, third-party measurement layer for the AI agent economy. Capability classes are observations of the declared surface, never safety, malware, or trust verdicts. Corrections & delistings: consulting@srl-sasame.com. Per-server defensive pre-call checks are available over MCP (capability_profile) — aggregate report never names individual servers.