# How to evaluate an MCP server before you install it

A practical pre-install gate that pairs census checks with human review.

## First gate (2–5 minutes)
1. Search the exact name or brand on [lookup](/lookup).
2. Check **Official** for brand installs.
3. Read **health** and problem flags (archived, deprecated, gone).
4. Open the drawer: trust factors, remote alive, citations.
5. Watch for look-alike / impersonation cautions.

## Second gate (you still own this)
- What tools does it expose?
- What secrets does it need?
- Who maintains it, and is the repo the real upstream?
- Any community incidents?

## Agents
Automate the first gate: `census_search` then `census_stamp` (or `census_preflight`) with a named policy. Stop on `BLOCK`. Ask a human on `REVIEW`. `PASS` is not a sandbox. See [Census stamp vs mcp-scan](/learn/census-stamp-vs-mcp-scan).

## Limits
We say when evidence is missing. Unknown is not “probably fine.”
