Week of 2026-05-14

MCP Trust Report: GitHub Leads, Filesystem Needs Scoping

GitHub MCP Server leads this week because it combines first-party provenance, broad developer usefulness, and reviewable permission boundaries. The larger signal: teams should treat MCP installation as a security decision, not a directory browse.

Lead signal

GitHub MCP Server

Repository, issue, pull request, and code search workflows for agentic coding.

94A
Open full review

Top 3 reviewed servers

Why this matters

First-party publisher and clear repository/package provenance.
High-value developer workflows across repository search, issue triage, and pull-request review.
Permission risk is manageable when teams pin repository scopes and separate read-only from write-capable actions.

Watch list

Filesystem remains essential but depends on strict path scoping.
Context7 is a strong low-risk documentation candidate for coding teams.
Slack and Stripe are high-utility but high-risk until OAuth scopes and mutation controls are verified.

Biggest risk note

High-utility servers increasingly touch sensitive systems: payments, chat history, local files, databases, and browser sessions. MCP Rank will not include those servers in safest lists unless confidence is medium/high and the risk surface is explicit.

Needs maintainer verification

Slack MCP Server

Stripe MCP Server

Google Drive

Redis

Sentry

Newly indexed

inference.sh

Trading

aTars MCP

AdAdvisor MCP Server

Google ADS

AdWeave — Meta Ads MCP Server

Graffeo Coffee Roasting

Agentra

What changed

Expanded the indexed dataset beyond 50 public MCP servers.
Promoted GitHub, Filesystem, and Context7 to high-confidence deep reviews.
Separated indexed listings from trusted rankings so unreviewed tools do not inflate leaderboard trust.

Weekly MCP trust report

Reviewed servers, risk notes, new indexed tools, and maintainer verification asks.