MCP trust reports
Evidence-led notes on which MCP servers are safest, most useful, and most urgent to verify before installation. Each report is meant to be renewed as source evidence, maintainer verification, and risk signals change.
7 reports published
Featured report
First 50 Reviewed MCP Servers: Trust Layer Report
MCP Rank's first trust-layer report covers 50 reviewed or high-risk MCP pages: 20 Deep Reviews, 22 Source Reviewed listings, 6 install-tested/operational review pages, 2 high-risk reviewed pages, and 0 Maintainer Verified listings.
Indexed means discovered from public sources. Source Reviewed means public links and provenance signals were checked. Deep Review means MCP Rank performed stronger manual evidence and risk analysis. Maintainer Verified still requires maintainer confirmation.
Week of 2026-05-19
First 25 Source-Reviewed MCP Servers
MCP Rank's first serious source-review batch shows the real bottleneck in MCP trust: indexing is easy, but source provenance is uneven. EXA is the lead signal because it has active public source, strong adoption, a concrete provider endpoint, and a comparatively narrow web-retrieval risk surface.
Week of 2026-05-14
MCP Trust Report: GitHub Leads, Filesystem Needs Scoping
GitHub MCP Server leads this week because it combines first-party provenance, broad developer usefulness, and reviewable permission boundaries. The larger signal: teams should treat MCP installation as a security decision, not a directory browse.
Week of 2026-05-15
Safest MCP Servers for Codex Workflows
For Codex-style coding agents, the strongest reviewed MCP choices are the ones with clear source provenance, practical developer utility, and permission boundaries that can be scoped before rollout.
Week of 2026-05-15
Browser Automation MCP Risk Report
Browser automation MCP servers are valuable for QA and inspection, but they can also interact with authenticated sessions, admin consoles, and production data if deployed without guardrails.
Week of 2026-05-15
Auth and OAuth Risk in MCP Servers
MCP servers that require OAuth, API keys, or workspace tokens need a different review lens from low-auth utility servers. The best default choices minimize secret handling and make scopes explicit.
Week of 2026-05-15
First 10 High-Confidence MCP Reviews
The first high-confidence review batch focuses on servers with direct source evidence, repeatable install paths, and clear risk boundaries. High confidence is an evidence label, not a universal safety guarantee.