How to evaluate an MCP server before you install it
First gate (2–5 minutes)
- Search the exact name or brand on lookup.
- Check Official for brand installs.
- Read health and problem flags (archived, deprecated, gone).
- Open the drawer: trust factors, remote alive, citations.
- Watch for look-alike / impersonation cautions.
Second gate (you still own this)
- What tools does it expose?
- What secrets does it need?
- Who maintains it, and is the repo the real upstream?
- Any community incidents?
Agents
Automate the first gate with census_search / census_lookup on our API. Keep a human or policy gate for production secrets.
Limits
We say when evidence is missing. Unknown is not “probably fine.”