State of Agent Security
A snapshot of 89,022 AI agents across the MCP ecosystem. Data from AgentGrade scans.
89,022Agents Indexed
6,709Scanned
5,785Online
Key Findings
- 99.9% of scanned agents use HTTPS.
- Only 12.2% require authentication on their endpoints.
- 25 agents expose credentials in public responses.
- 1291 agents use wildcard CORS (
Access-Control-Allow-Origin: *). - 2431 agents have exposed admin panels.
Grade Distribution
| Grade | Count | |
|---|---|---|
| A | 191 |
|
| B | 1015 |
|
| C | 4340 |
|
| D | 413 |
|
| F | 1 |
|
| N/A | 749 |
|
Top Rated Agents
Based on 6,121 scans of publicly accessible agent endpoints.
All checks are passive HTTP GETs. See methodology.
Data updates daily. Search all agents.