7-Frame trust gap · 2026 edition
The State of AI-Built Software · 2026
We ran Legit.Show’s 7-Frame production-readiness benchmark across 190 open-source AI, MCP and developer tools — straight from their repositories. AI coding ships a flawless demo; this is what quietly never makes it to production.
The findings
- No API rate limiting — 97%No rate limit — one user can overload the server or run up the bill.
- No error tracking — 96%No crash monitoring — failures happen silently and nobody finds out.
- Committed .env — 5%Credentials checked into the repo — leaked to anyone who clones it.
- Secrets in the browser — 0%Secret keys shipped to the client — anyone can steal them.
How many controls are missing
- Clean — 0 gaps — 1%
- 1–2 gaps — 79%
- 3 or more gaps — 20%
By category
- Developer Tools — 99% no error tracking
- MCP & Integrations — 87% no error tracking
- AI & Agents — 100% no error tracking
- Infrastructure & DevOps — 100% no error tracking
- Frameworks & Starter Kits — 100% no error tracking
- Productivity — 100% no error tracking
Why these seven
The demo always works — that’s what AI coding is *great* at. The gap is everything a demo never forces you to add: monitoring for when it breaks, limits for when it’s abused, access rules for when there’s more than one user. 1 of 190 (1%) had none of these gaps. The rest are one incident away from finding out.
The basics most get right
It isn’t carelessness with the obvious stuff: 0% shipped a hard-coded secret key in client code, and only 5% committed a `.env`. The misses are the *invisible* controls a human senior adds by reflex and a model rarely does.
What this is not
A health check, not a verdict. A missing rate limit correlates with “shipped fast, hardened never” — it doesn’t prove the product is bad. Every number is a count over a stated sample, measured from the public repository, fully reproducible.
Sample composition
Not a random sample — this is what we measured. The mix below is the caveat; judge it for yourself.
- Developer Tools: 77
- MCP & Integrations: 47
- AI & Agents: 42
- Infrastructure & DevOps: 6
- Frameworks & Starter Kits: 5
- Productivity: 3
- Largest single maker: 1% (github, 2)
What we measured (190)
The full list, so anyone can spot-check. Every item links to its public benchmark.
- ripgrep
- @angular/cli
- dive
- react-native-debugger
- FinSight-AI
- humanizer
- @swc/cli
- @langchain/mcp-adapters
- frontend-slides
- hotel
- @react-native-community/cli
- @types/cli-progress
- cli-columns
- chromedp
- huashu-design
- @inngest/ai
- n8n-mcp
- glance
- @google/gemini-cli
- bat
- @modelcontextprotocol/ext-apps
- cli-cursor
- cli-tableau
- @formatjs/cli
- cli-table3
- cli
- cli-sprintf-format
- redux-devtools-extension
- n8n-nodes-mcp
- meow
- cli-table
- @ui5/cli
- ndb
- stack-on-a-budget
- deploy-your-own-saas
- argocd-mcp
- mcp-handler
- GhidraMCP
- @shortcut/mcp
- @mcp-use/inspector
- Claude-Code-Game-Studios
- @notionhq/notion-mcp-server
- @traceloop/instrumentation-mcp
- @storybook/mcp
- planning-with-files
- github-mcp-server
- pal-mcp-server
- webpack-dashboard
- autoresearch
- Mindwalk
- free-claude-code
- aws-blocks
- Shadowbroker
- butterbase
- react-native-grab
- memory-os
- bug-hunter
- discord-reward-claimer
- chrome-devtools-mcp
- omk
- psique-workflow-clinic
- clicky
- WorkShadow
- engram
- agent-watch-approve
- spec-kit
- graphiql
- gsd-browser
- obscura
- hyperframes
- OpenSpace
- ultraship
- Vane
- deepseek-saas-starter-vue
- k8s-unix-system
- mcpsnoop
- notebooklm-py
- CDP-Enable-BOF
- sequelize-cli
- chrome-devtools-axi
- vphone-cli
- openwiki
- cli
- claudetop
- anything-analyzer
- ostack-saas
- octanet-landing-page-starter
- cli-printing-press
- llm-task-orchestrator
- claude-code-production-grade-plugin
- pi-extensions
- inkos
- OB1
- claude-code
- arkon
- coc.nvim
- glazepkg
- prompt-master
- open-claude-in-chrome
- SkillSpector
- Agent-Reach
- simvyn
- Tradingview-MCP
- gpt-pilot
- ai-video-generator-claude
- django-boilerplate
- soft-ue-cli
- stainful
- TencentDB-Agent-Memory
- tradingview-mcp
- SearchCLI
- tradingview-mcp
- add-mcp
- agent-cli-detector
- @agentclientprotocol/claude-agent-acp
- @agentmemory/mcp
- @allurereport/plugin-agent
- @aws-sdk/util-user-agent-browser
- @azure-devops/mcp
- @clerk/mcp-tools
- @convex-dev/agent
- default-user-agent
- @egjs/agent
- @expo/mcp-tunnel
- forever-agent
- @genkit-ai/ai
- @google/generative-ai
- hostinger-api-mcp
- infinity-agent
- mcp-framework
- @mobilenext/mobile-mcp
- @nestjs/cli
- @penpot/mcp
- next-devtools-mcp
- @payloadcms/plugin-mcp
- @pm2/agent
- @posthog/ai
- @rekog/mcp-nest
- @reportportal/agent-js-playwright
- @salesforce/mcp
- @sanity/cli-core
- @sap-ux/fiori-mcp-server
- @scalar/agent-chat
- @sentry/cli-linux-x64
- @supabase/mcp-utils
- tunnel-agent
- @ui5/mcp-server
- universal-user-agent
- @vercel/mcp-adapter
- workers-ai-provider
- @expo/cli
- playwright-mcp
- Langchain-Chatchat
- @azure/mcp
- lazygit
- agency-agents
- GEOFlow
- tavily-mcp
- gpt-engineer
- OpenMontage
- cc-connect
- mcp-searxng
- SaaS-Bench
- vue-element-admin
- Hermes One
- @postman/tunnel-agent
- webpack-cli
- pi
- telecom-mas-agent
- ponytail
- @upstash/context7-mcp
- RCLI
- postcss-cli
- @firebase/ai
- product-architect
- react-devtools
- mcp-chrome
- llmfit
- bb-browser
- iosm-cli
- Windows-MCP
- superpowers-zh
- llm_wiki
- Conformiti
- @newrelic/security-agent
- MasterHttpRelayVPN-RUST
- @eslint/mcp
- @npmcli/agent
- Elpis
- ratel