Look-alike MCP namespaces and brand risk
The trap
Anyone can register a domain that looks like a brand, publish an MCP server under that namespace, and collect installs from people who skim.
What domain verification proves
Control of that domain — not permission from the brand.
What we do
Scoring v3.2 corroboration caps and impersonation checks reduce “identity-only” high scores. Official rules stay farm-safe. See methodology.
What you should do
Prefer Official for brand names. Open the publisher and namespace. If the card says look-alike caution, treat it as a hard stop until proven otherwise.