An independent, continuously re-run, ed25519-signed measurement of the public MCP agent attack surface. Measured from outside — a third-party observation, not a vulnerability scan, not malware detection, and not a claim any server is unsafe. Edition 2026-09-16 · classifier capability-classify/0.1 · standard agent-tool-discoverability-standard/0.4.
| Class | What it can do | Kind | Tools | % of declared |
|---|---|---|---|---|
payment | Payment / funds movement | state-changing | 12551 | 9.7% |
code_exec | Code / command execution | state-changing | 3088 | 2.4% |
credential | Identity / credential / account | state-changing | 16104 | 12.4% |
fs_write | State change / write / delete | state-changing | 14267 | 11% |
network_out | Outbound fetch (SSRF-relevant) | read | 34225 | 26.3% |
messaging | Send message / post / notify | state-changing | 3170 | 2.4% |
data_read | Read / search / list | read | 104761 | 80.6% |
This is a DISCOVERABILITY / hygiene finding (missing ToolAnnotations), not a vulnerability. It means automated gating is impossible without a human/policy layer; it is NOT a claim these tools are dangerous or misbehave.
Tier is derived ONLY from the declared surface's highest capability class (high = payment or code-execution declared; moderate = write/credential/network; read-oriented = retrieval only). It is a description of exposure, not a safety verdict.
10267 servers now have 2+ capability snapshots; 316 newly exposed a higher-risk class since first observed. Capability-surface tracking is YOUNG (per-tool capture began 2026-07). This longitudinal signal — 'a server newly exposed a higher-risk class since first observed' — is the part an agent cannot self-produce, and it compounds with every crawl. Small counts here reflect the short history, not a claim of stability.
ed25519-signed, offline-verifiable, reproducible. Issuer pubkey 302a300506032b6570032100439ce47d…. Re-run the audit + classifier against any server to reproduce it — no callback to SaSame required.
SaSame MCP Observatory — a neutral, third-party measurement layer for the AI agent economy. Capability classes are observations of the declared surface, never safety, malware, or trust verdicts. Corrections & delistings: consulting@srl-sasame.com. Per-server defensive pre-call checks are available over MCP (capability_profile) — aggregate report never names individual servers.