Skip to content
Field notes · Updated weekly

What 16 engines see
when nobody else is looking.

Methodology, raw numbers, and the awkward findings nobody asked us to publish. Written by the person who built the scanner — no editorial team, no embargo, no spin.

All posts Ecosystem data Methodology Cross-engine Threats
Latest scan corpus
Repos indexed 14,083
Active engines 16
Posts published 04
FREE TOOL · NO PAYWALL
01 — Reading list

Four pieces, one argument:
multi-engine beats single.

POST · 2026-04-02 · 8 min read ECOSYSTEM DATA

What 16 engines found in 2,900 MCP servers

91% of repos flagged by at least one of sixteen scanners. Half landed in the yellow zone — functional, maintained, and quietly carrying CVEs. The full breakdown, including which engines fire most often and which agree.

Read the report
[ chart · 16 engines × 2,896 repos ]
POST · 2026-03-22 · 12 min read METHODOLOGY

The MCP security landscape

A long-form essay on why the MCP ecosystem looks like npm circa 2014 — and which threat categories are unique enough to need new scanners. No vendors mentioned, no products pitched.

Read the essay
POST · 2026-03-06 · 9 min read CROSS-ENGINE

Where engines agree,
where they don't

We ran 16 scanners against 769 repos. They agreed on almost nothing. Co-occurrence tables, overlap diagrams, and the case for never trusting a single tool's "all clear".

Read the analysis
POST · 2026-02-18 · 6 min read METHODOLOGY

The scoring math, published in full

Severity weights, engine weights, the per-engine cap, and the published nonlinearity. If you cannot reproduce a score on your own machine, it does not count as a verdict.

Read the spec
POST · 2026-01-29 · 5 min read THREATS

Tool-shadowing in the wild

Three months of YARA matches: how often MCP tool descriptions contain instruction-like language that could quietly steer an agent's next step.

Read the dispatch

Archive · everything older

2025-12-11 First red-light: a leaked AWS key, two days early 4 MIN
2025-11-04 Why we picked oklch over hex (and what broke) 3 MIN
2025-10-22 v0.1 in a weekend: Trivy, TruffleHog, and a regex 7 MIN
2025-09-30 Posting on Hacker News, accidentally going front-page 5 MIN
Editorial line

No newsletter,
no popup, no "premium content."

MCPAmpel is free. The blog is free. The scoring methodology is on GitHub. There is one author — Nikita Frikh-Khar — and zero growth team. If a piece is worth reading, it shows up here. If not, it doesn't.

RSS lives at /blog/feed.xml. Bring your own reader.

Scan your MCP server now

Sixteen engines. Sixty seconds. No account, no credit card, no email gate.

Open the scanner See all 16 engines