AI Risk Knowledge Base
Assess model and MCP risk before components enter enterprise workflows
Assess model and MCP risk before components enter enterprise workflows
Open-source models and MCP servers give AI teams access to new capabilities, but adoption can outpace security review. A model may carry unsafe code, uncertain provenance, or weak operational controls. An MCP server can expose credentials, connect agents to sensitive systems, or introduce vulnerable dependencies that become difficult to trace later.
The PointGuard AI Risk Knowledge Base brings evidence-based assessments into selection and governance workflows. It draws on scans and tests of more than 300,000 open-source models and code analysis of more than 40,000 MCP servers. Ratings separate security, operational controls, provenance, and adoption maturity so teams can make informed decisions rather than relying on popularity alone.
Connect component intelligence to enterprise inventory, spot affected applications and agents, and review risk before approval or deployment.
models
Evaluate open-source models for security findings, provenance, operational controls, and adoption maturity. Compare risk signals across model sources and flag components that need deeper testing or approval. Development teams get practical selection context while security teams retain a consistent record of the models entering enterprise applications.
Review model security and provenance signals
Compare operational and adoption maturity ratings
Flag models needing further security review

MCP
Scan MCP server code and repository context for vulnerabilities, exposed secrets, risky patterns, publisher trust, and maintenance signals. Assess servers before agents rely on their tools, then keep risk intelligence current as integrations and dependencies change. This helps teams distinguish approved components from unmanaged or untrusted connections.
Find vulnerable code and exposed secrets
Check publisher trust and repository context
Review servers before connecting enterprise agents
scoring
Use separate ratings for security, operational controls, provenance, and adoption maturity rather than collapsing every signal into a single judgment. The four dimensions clarify why a model or MCP server needs review and help teams balance development value against the specific risks of deployment.
Separate security findings from operational readiness
Assess provenance and publisher trust signals
Compare adoption maturity across candidate components


context
Link knowledge-base entries to discovered AI applications, agents, MCP connections, and infrastructure. Dependency mapping shows which workflows consume a risky component and where a change could have downstream effects. Security and platform teams can prioritize widely used dependencies and focus review on the systems that matter most.
Map components to consuming AI applications
Identify agents using higher-risk MCP servers
Prioritize risk by downstream dependency impact
governance
Route model and MCP assessments into enterprise governance workflows. Teams can review findings, approve or reject new components, record exceptions, and track remediation when a dependency falls outside policy. A common evidence base makes decisions repeatable while allowing approved innovation to move forward with clear ownership.
Review risky components before enterprise adoption
Record component approvals, exceptions, and owners
Track remediation as component risk changes

industry
PointGuard AI collaborates with the Cloud Security Alliance on RiskRubric v2, contributing its unique MCP server assessment data and expertise to the public initiative. The work extends assessment beyond models to MCP servers and agents, helping the industry define consistent signals for tool integrity, provenance, vulnerabilities, and data exposure.
Contribute MCP assessment expertise to CSA
Support shared, evidence-based component risk evaluation
Extend risk intelligence across agentic systems
Clients Words
AppSOC brings it all together in one intuitive dashboard – helping me prioritize vulnerabilities and ensure compliance.
Customer Spotlight
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.

Find content, demos, case studies, guides, blogs, and more in our extensive library