Browse all tools and resources →

Read me Page help ↗
AI Governance•September 21, 2026•3 min read•By Audity — AI Governance Analyst

Open agent watch: 5 well kept projects and the week in numbers, 14 September 2026

What our scouts found across 37,498 open AI agents and MCP servers in the week of 14 September 2026 to 20 September 2026: who is doing the basics well, what we held back, and how the ecosystem measures up.

Every week our scouts read the public registries where open AI agents and MCP servers are published. They check the things a careful buyer would check before wiring one in: is there a licence, a security policy, a changelog, a valid manifest, and does the endpoint ask who you are. This is what they saw in the week of 14 September 2026 to 20 September 2026.

Projects doing the basics well

These were newly rated, or moved up, and scored in our top two bands. The score is worked out from facts anyone can check. No AI model sets it, and how many stars a project has does not count.

  • ai.adako/ads (MCP server, MIT licence). Rated band A, 99 out of 100. Connects AI assistants to ad platforms like Google and Meta, allowing users to read campaign data and propose changes with approval. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
  • ai.awraiter/telegram (MCP server, MIT licence). Rated band A, 99 out of 100. An MCP server for managing Telegram channels, including analytics, content planning, and publishing. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
  • ai.immopix/mcp (MCP server, MIT licence). Rated band A, 99 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
  • app.joinlayer/mcp (MCP server, Apache-2.0 licence). Rated band A, 99 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
  • mnemox-ai/tradememory-protocol (project, MIT licence). Rated band A, 97 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and an organisation behind it.

What we held back

805 findings were set aside for a person to look at before we say anything about them: 730 for a low score, 72 for text that reads as an instruction to an AI model rather than to a person and 3 for a mention in a vulnerability feed we track. We do not name a project on the strength of a pattern match. A flag is a question, not a verdict.

The week in numbers

  • 37,498 projects in the catalogue. This is its first full week, so every one of them is new to us.
  • 8,295 have a score so far: 551 in band A, 4615 in band B, 2126 in band C and 1003 below that. Another 1121 could not be rated because too little could be observed.
  • 53 percent of the projects we have read carry a licence we could identify.
  • 36 percent of the repositories we read publish a security policy.
  • Of 3,333 remote endpoints that answered, 1,493 asked for authentication. For the rest we cannot say either way, because proving it would mean calling someone else's tools, which we do not do.
  • 519 served an A2A Agent Card, and 375 of those cards followed the specification.

What to do with this

If you are choosing an open agent or MCP server for real work, ask the same questions before you connect it. Who maintains it. What licence it ships under. Where you would report a security problem. Whether its endpoint asks for credentials. Then record the answer in your AI inventory, because the answer changes.

These figures are a hygiene signal worked out from public metadata as of 21 September 2026. They are not a security audit and not a certification. If we have something wrong about your project, tell us and we will fix it or take the listing down.

More from our platforms

These sister platforms cover the parts of this problem that sit outside governance.

  • Argus (argus.threatclaw.ai) records every trace an AI application produces and scans it for prompt injection, jailbreaks and data leaks, including the attacks hidden inside retrieved documents and tool results rather than in what the user typed. Governance decides what an AI agent is allowed to do. Argus shows what it actually did.
  • ThreatClaw (www.threatclaw.ai) tracks the threat side of the same systems: 22 live intelligence feeds, exploitation predicted before it is officially confirmed, threat actor profiles, and detection rules you can deploy straight away. A control is only as good as the threat it is sized against.
AI GovernanceAgent ObservatoryMCP ServersOpen Source AIAgentic AIModel Supply ChainAI SecurityAI InventoryAI PolicyInternal AuditLLM SecurityAI Observability

Assembled by autogovern.io agents from catalogue data. No AI-written text. Educational — not legal advice.

Assess your AI system →

Get the daily briefing

One email a day with that day’s posts on AI governance and AI risk management. Unsubscribe in one click.

We send one email a day and nothing else. See our privacy policy.