Methodology
How we measure MCP servers
Token cost (“context tax”)
We start each server in an isolated sandbox, perform the MCP initialize handshake and call tools/list. We tokenize the tool definitions exactly as a client sends them to the model (name, description, input_schema) plus any server instructions. That total is resent on every turn unless your client caches or defers tools, so it is a worst-case per-turn cost.
Bands: lean under 1,000 tokens · moderate 1,000–5,000 · heavy 5,000–15,000 · bloated over 15,000.
Security signals
Static analysis runs on the published package or a shallow clone — nothing is executed during scanning. Signals: secrets scanning, dependency vulnerabilities (OSV), risky code patterns, npm install scripts, tool-description prompt-injection screening, and capability flags (shell execution, arbitrary file writes, arbitrary outbound HTTP). Every deduction is listed on the server page with its evidence. A high score means no known issues found as of the scan date — never a guarantee of safety.
Security signals are powered by Vectra Guard, an open-source agent security CLI built by the MCPSkillHub team.
Performance
Measured in a Linux container with no network, a read-only filesystem, 512 MB memory and 1 CPU: cold start (spawn → initialize, with container overhead subtracted), tools/list latency, resident memory after initialization, and install size. Compare servers relative to each other; absolute numbers vary by machine.
Overall score
Hub score = 35% security + 30% token cost + 20% performance. If a part couldn't be measured (for example, the server needs real credentials to start), the remaining weights are renormalized and the score is marked partial. Popularity is shown but never part of the score.
Disputes
Maintainers who claim their listing can request a re-scan or dispute a finding. Heuristic findings are labeled as such.