← Major Labs
Open data · The index

The Agent Trust Index

One number for a hard question: how safe is the agentic web to actually transact on? We fuse three firsthand, read-only measurements into a single score, updated every week. Higher is safer.

38 / 100
0 to 100, higher is safer. Latest sweep 2026-07-20. The series starts here.

The three pillars

Code Safety
64.6 / 100
no change wk/wk
35.4% of 2001 swept servers carry a risky code pattern
Identity
24.3 / 100
no change wk/wk
75.7% of network-facing, sensitive servers show no auth in source
Supply Chain
24.8 / 100
no change wk/wk
75.2% of servers ship a runtime dependency with a known advisory

Each pillar is 100 − the share at risk, so a low score means a large share of the population is exposed. The composite is the equal-weighted mean of the three.

What sits behind the score

2,802
servers measured
43/47
high-risk servers unchanged, pre-outreach
25.3M
on-chain agent settlements / month

The score measures whether agents are safe to transact; these measure that they already are transacting. Full data on /security and /data.

The series

The composite, captured every weekly sweep. The question it answers over time: is the agentic web getting safer as it professionalizes, or just bigger?

Methodology & honest caveats

Method v1 (2026-06). Every input is a firsthand, read-only static measurement of the public MCP server population. We never connect to, run, install, or probe a server. Aggregate statistics only; per-repo findings go to maintainers through coordinated disclosure, never into a public list.

Lower bounds. The detectors are tuned for precision over recall, so each pillar is conservative: the true exposure is at least this high. Equal weighting is a deliberate v1 choice, published so it can be argued with and versioned when it changes.

Cite this

Major Labs, The Agent Trust Index (2026). Composite 38/100, method v1 (2026-06). majorlabs.co/trust, accessed 2026-07-20. Machine-readable: trust-index.json.