Week of 2026-05-15
Auth and OAuth Risk in MCP Servers
MCP servers that require OAuth, API keys, or workspace tokens need a different review lens from low-auth utility servers. The best default choices minimize secret handling and make scopes explicit.
Lead signal
Context7
Library documentation retrieval for coding assistants.
Top 3 reviewed servers
Why this matters
Context7 remains a strong low-risk reference point because its default purpose is documentation retrieval.
GitHub is powerful but requires explicit token scope management before broader team rollout.
Slack, Stripe, Google Drive, and Notion are useful but should not be marketed as safest without tighter auth evidence.
Watch list
Slack needs workspace-scope and message-retention review before any safety recommendation.
Stripe needs strict separation between read-only analysis and payment-affecting actions.
Google Drive and Notion need tenant-level controls for private workspace content.
Biggest risk note
OAuth success is not the same as safe authorization. MCP Rank needs scope evidence, revocation behavior, and mutation controls before high-risk SaaS tools can be recommended.
Needs maintainer verification
Slack MCP Server
Stripe MCP Server
Google Drive
Notion MCP Server
Newly indexed
AgentTrust
LimitGuard Trust Intelligence
Nordax AI Entity Network
What changed
Clarified that confidence and trust score are separate signals.
Kept high-risk SaaS tools visible as reviewed but excluded from safest lists.
Added maintainer-verification asks for tools touching private workspace data.
Weekly MCP trust report
Reviewed servers, risk notes, new indexed tools, and maintainer verification asks.