State of Agent Security
A snapshot of 25,745 AI agents across the MCP ecosystem. Data from AgentGrade scans.
25,745Agents Indexed
4,140Scanned
4,008Online
Key Findings
- 99.9% of scanned agents use HTTPS.
- Only 9.1% require authentication on their endpoints.
- 17 agents expose credentials in public responses.
- 464 agents use wildcard CORS (
Access-Control-Allow-Origin: *). - 2364 agents have exposed admin panels.
Grade Distribution
| Grade | Count | |
|---|---|---|
| A | 34 |
|
| B | 381 |
|
| C | 3147 |
|
| D | 447 |
|
| F | 1 |
|
| N/A | 130 |
|
Top Rated Agents
Based on 4,140 scans of publicly accessible agent endpoints.
All checks are passive HTTP GETs. See methodology.
Data updates daily. Search all agents.