How to Vet MCP Servers Before Installation

SelectionBitter6821 · reddit · 2026-07-15

The post asks if teams perform security reviews before pulling MCP servers and agent skills from GitHub. Concerns include: - Lack of npm lockfile/audit-like mechanism to detect risks like 'tool descriptions inducing model to exfiltrate data' - Static scanning only covers part of the problem, and remote behavior may change after installation - Wants to know industry practices: whitelisting, manual review, network egress controls, or accepting risks. Core discussion: **security governance of MCP/agent tools**, especially tool supply chain and runtime control.

Related event: Developers Discuss Security Audits for MCP Servers(2 posts)→

Original post →

More from coding & agent

coding & agent channel →