An evaluation of 36 MCP servers, the standard for connecting AI agents to tools, revealed that 1 in 3 received a failing grade (D/F) and are at a level unsuitable for enterprise use due to security flaws.
Imagine this: You ask your AI assistant to “summarize the content of this morning’s meeting and upload it to Notion.” A very smart AI should be able to handle this task with ease. However, the reality is a bit different. Because the AI cannot handle the tools properly, it might upload information to the wrong place or, even worse, just stare blankly without doing anything at all.
Recently, the MCP (Model Context Protocol, a universal standard that helps AI agents interact with external tools), which is the solution for this “connection between AI and tools,” has been gaining attention [Source: Model Context Protocol(https://en.wikipedia.org/wiki/Model_Context_Protocol), Source: Builder.io(https://www.builder.io/blog/best-mcp-servers-2026)]. However, once investigated, it turned out that even servers from famous companies we commonly use were evaluated as being at a very inadequate level for agents to use.
Why Is This Important?
If an AI agent is a smart engine, an MCP server is like the “plug” that connects that engine to the outside world. If this plug does not fit the specification or is loose, the AI cannot read data or perform tasks.
Currently, many developers are adopting MCP for AI task automation [Source: BrightData(https://brightdata.com/blog/ai/best-mcp-servers)]. However, the results of this survey show that the tools we trust and use may not actually work properly in the field or could even be dangerous in terms of security. This can be a major risk for companies or individuals pursuing AI automation projects.
Easy to Understand: An Instruction Manual for AI Tools
Think of an MCP server as an “instruction manual for AI tools.”
To use an analogy, imagine you installed an app (tool) with many features on a new smartphone (AI agent), but the descriptions of where the buttons are located were vague and the names were confusing. The user would fail to press the buttons.
Technically, it is the same. Even if a server is 100% compliant with the specification and has no problems with installation, if the ‘descriptions’ required for an AI agent to call a tool are vague, if the data structure is too complex and consumes unnecessary costs (tokens), or if the tool names are confusing, the agent will ultimately fail to use the tool [Source: DEV Community(https://dev.to/tengbyte/i-lint-scanned-36-popular-mcp-servers-a-third-of-them-are-failing-your-agent-102d), Source: LobeHub(https://lobehub.com/mcp/tengbyte-mcpgrade)].
In this survey, 36 popular MCP servers were analyzed, and a whopping 11 (about one-third) received a D or F grade in agent usability evaluations [Source: DEV Community(https://dev.to/tengbyte/i-lint-scanned-36-popular-mcp-servers-a-third-of-them-are-failing-your-agent-102d)]. Official servers from companies familiar to us, such as MongoDB, Notion, Airtable, and GitHub, were also included in this list of failing grades [Source: DEV Community(https://dev.to/tengbyte/i-lint-scanned-36-popular-mcp-servers-a-third-of-them-are-failing-your-agent-102d)].
Current Situation: The Gap Between Security and Quality
What is even more serious is security. About 67% of the public MCP servers tested have serious security flaws, a level not recommended for use in enterprise environments [Source: PointGuard AI(https://www.pointguardai.com/blog/we-tested-36-500-public-mcp-servers-two-thirds-arent-safe-for-enterprise-use)].
Overall, fewer than 15% of the servers received an A or B grade for excellence [Source: PointGuard AI(https://www.pointguardai.com/blog/we-tested-36-500-public-mcp-servers-two-thirds-arent-safe-for-enterprise-use)]. In the case of Grafana, although it provides the most tools, it appeared that popularity does not necessarily guarantee high quality, as it received an F grade in terms of quality and accuracy [Source: DEV Community(https://dev.to/0coceo/i-graded-201-mcp-servers-the-most-popular-ones-are-the-worst-114i)].
What Will Happen in the Future?
AI is moving beyond just conversation into an “agent” era where it actually plans, codes, and organizes data. For this, connection standards like MCP are essential.
In the future, moving beyond simply building servers, quality indicators that measure how ‘easily’ an AI can understand and execute a corresponding tool will become important. Developers and companies must now consider ‘agent-friendliness’ as their top priority, beyond just ‘compliance with specifications’ [Source: DEV Community(https://dev.to/tengbyte/i-lint-scanned-36-popular-mcp-servers-a-third-of-them-are-failing-your-agent-102d)]. If you are planning to introduce AI agent tools, we recommend that you carefully check the server’s security rating and usability evaluation indicators [Source: MCP Scoreboard(https://mcpscoreboard.com/?page=734&sort=-security)].
AI’s Thought: MindTickleBytes’ Perspective
The speed at which AI is becoming smarter is astonishing, but the state of the tools that support those capabilities is still in its ‘infancy.’ For standardized protocols to succeed, strict quality control at the ecosystem level regarding how smoothly an actual AI agent operates must accompany specification compliance.
References
- I lint-scanned 36 popular MCP servers. A third of them are failing your agent. - DEV Community
- I Graded 201 MCP Servers. The Most Popular Ones Are the Worst. - DEV Community
- The Best MCP Servers for Developers in 2026 - Builder.io
- MCP Scoreboard — Quality Scores for MCP Servers
- Model Context Protocol - Wikipedia
- MCP Security: 67% of Public Servers Fail Enterprise Tests - PointGuard AI
- Top 10 MCP Servers for AI Workflows: Best Tools Compared - BrightData
-
[mcpgrade MCP Servers - LobeHub](https://lobehub.com/mcp/tengbyte-mcpgrade)
- Improving the learning speed of AI models
- Standardizing the connection between AI agents and external tools
- Setting ethical guidelines for AI
- Approximately 15%
- Approximately 50%
- Approximately 67%
- Vague tool descriptions
- Schemas with excessively large token requirements
- The server's installation speed is too fast