State of Agent Security
A snapshot of 92,409 AI agents across the MCP ecosystem. Data from AgentGrade scans.
92,409Agents Indexed
6,969Scanned
6,017Online
Key Findings
- 99.9% of scanned agents use HTTPS.
- Only 12.1% require authentication on their endpoints.
- 26 agents expose credentials in public responses.
- 1400 agents use wildcard CORS (
Access-Control-Allow-Origin: *). - 2440 agents have exposed admin panels.
Grade Distribution
| Grade | Count | |
|---|---|---|
| A | 196 |
|
| B | 1070 |
|
| C | 4509 |
|
| D | 416 |
|
| F | 1 |
|
| N/A | 777 |
|
Top Rated Agents
Based on 6,370 scans of publicly accessible agent endpoints.
All checks are passive HTTP GETs. See methodology.
Data updates daily. Search all agents.