- What is it?
- A registry of community MCP servers with their declared scopes (file R/W, network, exec), trust tier, and known security advisories. Four tiers: official / partner / community / unverified.
- How do I use it?
- Before adding an MCP server to Claude Desktop / Cursor / Continue, look it up here to confirm scope and trust. Use the IDs as a whitelist when defining allowed servers in a corporate setting.
- Why does it matter?
- MCP servers can run arbitrary code inside your IDE/agent. A server with file + network + exec scopes is effectively RCE — installing one is a trust decision. Run unverified servers in a container or VM at minimum.