Open agent watch: 5 well kept projects and the week in numbers, 21 September 2026
What our scouts found across 41,798 open AI agents and MCP servers in the week of 21 September 2026 to 27 September 2026: who is doing the basics well, what we held back, and how the ecosystem measures up.
Every week our scouts read the public registries where open AI agents and MCP servers are published. They check the things a careful buyer would check before wiring one in: is there a licence, a security policy, a changelog, a valid manifest, and does the endpoint ask who you are. This is what they saw in the week of 21 September 2026 to 27 September 2026.
Projects doing the basics well
These were newly rated, or moved up, and scored in our top two bands. The score is worked out from facts anyone can check. No AI model sets it, and how many stars a project has does not count.
- com.f1laps/mcp (MCP server, MIT licence). Rated band A, 99 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
- com.interviewflowai/mcp (MCP server, MIT licence). Rated band A, 99 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
- com.omnara/omnara (MCP server, Apache-2.0 licence). Rated band A, 99 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
- com.openephemeris/open-ephemeris (MCP server, MIT licence). Rated band A, 99 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and an endpoint that asked for authentication when we probed it.
- com.spytrend/spytrend (MCP server, MIT licence). Rated band A, 99 out of 100. What we could see: a published security policy, a changelog, a valid server.json manifest and a conformant A2A Agent Card.
What we held back
2335 findings were set aside for a person to look at before we say anything about them: 2033 for a low score, 268 for text that reads as an instruction to an AI model rather than to a person, 23 for a name very close to a much better known project and 11 for a published endpoint that points at a private network address. We do not name a project on the strength of a pattern match. A flag is a question, not a verdict.
The week in numbers
- 41,798 projects in the catalogue, 3,715 of them new this week.
- 40,646 have a score so far: 2698 in band A, 22728 in band B, 12438 in band C and 2782 below that. Another 1151 could not be rated because too little could be observed.
- 53 percent of the projects we have read carry a licence we could identify.
- 32 percent of the repositories we read publish a security policy.
- Of 20,876 remote endpoints that answered, 8,204 asked for authentication. For the rest we cannot say either way, because proving it would mean calling someone else's tools, which we do not do.
- 6061 served an A2A Agent Card, and 1223 of those cards followed the specification.
What to do with this
If you are choosing an open agent or MCP server for real work, ask the same questions before you connect it. Who maintains it. What licence it ships under. Where you would report a security problem. Whether its endpoint asks for credentials. Then record the answer in your AI inventory, because the answer changes.
These figures are a hygiene signal worked out from public metadata as of 28 September 2026. They are not a security audit and not a certification. If we have something wrong about your project, tell us and we will fix it or take the listing down.
Assembled by autogovern.io agents from catalogue data. No AI-written text. Educational — not legal advice.
Get the daily briefing
One email a day with that day’s posts on AI governance and AI risk management. Unsubscribe in one click.