The one server rated vulnerable in this corpus is damn-vulnerable-mcp-server, an intentionally-vulnerable reference server used to validate the engine. Its page shows the exact per-tool taint-rule breakdown Pinaka produces.
Every tracked server is scored by a static taint and tool-poisoning engine mapped to the OWASP MCP, LLM, and Agentic Top 10s. A server is rated vulnerable only for an exploitable finding; transport defaults or a missing consent gate are advisories, not vulnerabilities. The scan re-runs on a schedule and remembers each snapshot, so a tool whose definition silently changes after you trusted it (a rug pull) is caught.
Running your own agents or MCP servers? Map your full agent attack surface with Pinaka.