MCP trust reports

Evidence-led notes on which MCP servers are safest, most useful, and most urgent to verify before installation. Each report is meant to be renewed as source evidence, maintainer verification, and risk signals change.

7 reports published

Featured report

First 50 Reviewed MCP Servers: Trust Layer Report

MCP Rank's first trust-layer report covers 50 reviewed or high-risk MCP pages: 20 Deep Reviews, 22 Source Reviewed listings, 6 install-tested/operational review pages, 2 high-risk reviewed pages, and 0 Maintainer Verified listings.

Indexed means discovered from public sources. Source Reviewed means public links and provenance signals were checked. Deep Review means MCP Rank performed stronger manual evidence and risk analysis. Maintainer Verified still requires maintainer confirmation.

Read report

Week of 2026-05-19

First 25 Source-Reviewed MCP Servers

MCP Rank's first serious source-review batch shows the real bottleneck in MCP trust: indexing is easy, but source provenance is uneven. EXA is the lead signal because it has active public source, strong adoption, a concrete provider endpoint, and a comparatively narrow web-retrieval risk surface.

Week of 2026-05-14

MCP Trust Report: GitHub Leads, Filesystem Needs Scoping

GitHub MCP Server leads this week because it combines first-party provenance, broad developer usefulness, and reviewable permission boundaries. The larger signal: teams should treat MCP installation as a security decision, not a directory browse.

Week of 2026-05-15

Safest MCP Servers for Codex Workflows

For Codex-style coding agents, the strongest reviewed MCP choices are the ones with clear source provenance, practical developer utility, and permission boundaries that can be scoped before rollout.

Week of 2026-05-15

Browser Automation MCP Risk Report

Browser automation MCP servers are valuable for QA and inspection, but they can also interact with authenticated sessions, admin consoles, and production data if deployed without guardrails.

Week of 2026-05-15

Auth and OAuth Risk in MCP Servers

MCP servers that require OAuth, API keys, or workspace tokens need a different review lens from low-auth utility servers. The best default choices minimize secret handling and make scopes explicit.

Week of 2026-05-15

First 10 High-Confidence MCP Reviews

The first high-confidence review batch focuses on servers with direct source evidence, repeatable install paths, and clear risk boundaries. High confidence is an evidence label, not a universal safety guarantee.