State of Agent Security
A snapshot of 128,179 AI agents across the MCP ecosystem. Data from AgentGrade scans.
128,179Agents Indexed
8,475Scanned
7,347Online
Key Findings
- 99.9% of scanned agents use HTTPS.
- Only 14.0% require authentication on their endpoints.
- 27 agents expose credentials in public responses.
- 1823 agents use wildcard CORS (
Access-Control-Allow-Origin: *). - 2503 agents have exposed admin panels.
Grade Distribution
| Grade | Count | |
|---|---|---|
| A | 280 |
|
| B | 1719 |
|
| C | 5173 |
|
| D | 448 |
|
| F | 1 |
|
| N/A | 854 |
|
Top Rated Agents
Based on 7,778 scans of publicly accessible agent endpoints.
All checks are passive HTTP GETs. See methodology.
Data updates daily. Search all agents.