How to evaluate an MCP server before you install it
First gate (2–5 minutes)
- Search the exact name or brand on lookup.
- Check Official for brand installs.
- Read health and problem flags (archived, deprecated, gone).
- Open the drawer: trust factors, remote alive, citations.
- Watch for look-alike / impersonation cautions.
Second gate (you still own this)
- What tools does it expose?
- What secrets does it need?
- Who maintains it, and is the repo the real upstream?
- Any community incidents?
Agents
Automate the first gate: census_search then census_stamp (or census_preflight) with a named policy. Stop on BLOCK. Ask a human on REVIEW. PASS is not a sandbox. See Census stamp vs mcp-scan.
Limits
We say when evidence is missing. Unknown is not “probably fine.”