Before you connect an MCP server: a checklist
Connecting an MCP server lets an assistant act with whatever access that server has. A few checks before connecting are worth the minute they take — the registry lists servers, it does not vouch for them.
Who publishes it
Look at the registry name: io.github.<account> means a GitHub account was verified, a reversed domain means control of that domain was. A wrapper for a well-known service published under someone else's account is not the service's own server. Check the repository and the website the entry gives.
What it can do
Read its tool list once connected. Prefer servers, or settings, that only read when reading is all you need. Note which tools change data, send messages or spend money, and keep the assistant's confirmation step on for them.
Which credentials it gets
The registry entry declares the secrets a server expects — environment variables for a local package, headers for a remote endpoint. Give each server its own key with the narrowest scope the service offers, and revoke it when you stop using the server. Where a sign-in through the service itself is offered, it can usually be scoped and revoked from the service's settings.
Local code and untrusted text
A local server runs with your permissions: install from the package the registry entry names, pin the version, and check that the package matches the repository. Tool results can carry text written by others — web pages, emails, documents — that tries to instruct the assistant; be careful combining a server that reads untrusted content with one that can act on your accounts in the same conversation.
What the MCP Registry is · Browse servers · Browse the directory →
More: What is an MCP server? · What is llms.txt? · How AI assistants find and book travel · How listings are verified · MCP transports: stdio, Streamable HTTP and SSE · Remote or local: which kind of MCP server to use · How to add an MCP server to an AI assistant · What is the official MCP Registry? · What goes in an llms.txt file · OpenAPI for AI agents · How AI assistants find travel availability