How to Vet MCP Servers Before Installation
SelectionBitter6821 · reddit · 2026-07-15
The post asks if teams perform security reviews before pulling MCP servers and agent skills from GitHub.
Concerns include:
- Lack of npm lockfile/audit-like mechanism to detect risks like 'tool descriptions inducing model to exfiltrate data'
- Static scanning only covers part of the problem, and remote behavior may change after installation
- Wants to know industry practices: whitelisting, manual review, network egress controls, or accepting risks.
Core discussion: security governance of MCP/agent tools, especially tool supply chain and runtime control.
Related event: Developers Discuss Security Audits for MCP Servers(2 posts)→
More from coding & agent
- Astra storyboards plus Minimax H3 per-shot generation boost video success rates — Hailuo_AI · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Agile co-author Ron Jeffries publishes 'Resist AI', urging developers to push back — mborch · 2026-09-11