Week of 2026-05-20

First 50 Reviewed MCP Servers: Trust Layer Report

MCP Rank now has its first usable trust layer: 50 reviewed or high-risk MCP pages, including 20 Deep Reviews, 22 Source Reviewed listings, 6 install-tested/operational review pages, 2 high-risk reviewed pages, and 0 Maintainer Verified listings. The main finding is simple: MCP discovery is already large, but trust depends on separating indexed records from reviewed evidence.

Lead signal

EXA

Fast, intelligent web search and web crawling. New mcp tool: Exa-code is a context tool for coding

84B
Open full review

Top 3 reviewed servers

Why this matters

EXA is the lead signal because it combines reachable public source, MIT license metadata, recent repository activity, a concrete hosted endpoint, and a comparatively narrow public web-retrieval surface.
The new Deep Review set includes ten registry-sourced candidates promoted only after stronger manual evidence review: EXA, MCP Registry Server, Docs MCP, Adeu, Anki MCP Server, Spotdb, HAPI MCP Server, BuyWhere MCP, BorealHost, and AgentTrust.
The report keeps Maintainer Verified at zero because MCP Rank has not received maintainer confirmation evidence. That restraint is the product: trust labels should become harder to earn, not easier to market.

Watch list

High-impact MCP categories are showing up quickly: hosting/DNS, Salesforce administration, payments, data sandboxes, analytics uploads, packet capture, identity/trust scoring, and browser automation.
Several indexed or source-reviewed rows still have broken or missing repository provenance, including ABMeter, AgentDM, Agentic News, Agentic Shelf, Contextlayer MCP, and Cirra AI Salesforce Admin MCP Server.
Some servers are useful but should stay bounded by caution labels: HAPI-style OpenAPI wrappers inherit downstream API risk, Spotdb and Analytics can touch sensitive data, and BorealHost can affect infrastructure.

Biggest risk note

The biggest MCP trust risk is not a single malicious server. It is ambiguity: directory presence can look like endorsement, source links can be broken, hosted endpoints can hide retention/auth behavior, and high-impact tools can be indexed before anyone has checked what they can actually do.

Needs maintainer verification

ABMeter - repository provenance was broken during source review.

AgentDM - messaging/agent communication surface needs maintainer evidence and current source links.

Agentic News - hosted news/search endpoint needs data-source and account-scope clarification.

Agentic Shelf - commerce/catalog surface needs source, freshness, and incentive disclosure.

Contextlayer MCP - personal context surface needs repaired repository provenance and retention docs.

Cirra AI Salesforce Admin MCP Server - Salesforce admin capability should not be trusted without source, OAuth, and tenant-scope evidence.

ByteRay AI - hosted binary security analysis needs source, retention, isolation, and auth evidence.

Baselight - finance/data catalog endpoint needs data provenance, licensing, and freshness evidence.

BorealHost - infrastructure/DNS/domain actions need maintainer confirmation of mutation controls.

HAPI MCP Server - generic API wrapper needs tool-generation and downstream API scoping evidence.

Reviewed batch

GitHub MCP Server

Filesystem

Context7

Brave Search

Sequential Thinking

Fetch

Git

Time

Playwright MCP

Everything

EXA

MCP Registry Server

Docs MCP

Adeu

Anki MCP Server

Spotdb

AgentTrust

HAPI MCP Server

BuyWhere MCP

BorealHost

Postgres

Memory

Notion MCP Server

Browserbase

SQLite

Linear MCP Server

Slack MCP Server

Stripe MCP Server

AnomalyArmor

Auxen

Baselight

BuyWhere Product Catalog

ByteRay AI

China Marketing AI Intelligence MCP

Cirra AI Salesforce Admin MCP Server

Contabo (VPS) MCP Server

Dreamlit

ABMeter

AgentDM

Agentic News

Agentic Shelf

Contextlayer MCP

Computeback

Analytics

Mcpcap

Openarx

Paper Lantern

Parallel Task MCP

PreClick

ProofSlip

What changed

Expanded MCP Rank from a mostly indexed/searchable directory into a visible trust layer with 50 reviewed or high-risk pages.
Promoted 10 registry-sourced candidates into Deep Review after stronger manual evidence and capability-surface analysis.
Added 7 more Source Reviewed listings: Parallel Task MCP, Paper Lantern, PreClick, ProofSlip, Openarx, Analytics, and Mcpcap.
Kept Maintainer Verified at zero because no maintainer confirmation evidence exists yet.
Corrected the HAPI MCP repository source link and kept broken-source findings visible as trust evidence rather than hiding them.

Weekly MCP trust report

Reviewed servers, risk notes, new indexed tools, and maintainer verification asks.