Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Free checklist
All free tools & guides

Free checklist

Before you install an MCP server

An MCP server is software with privileges, not a library. This is the order to check things in, arranged so the questions most likely to stop you come first.

  1. 1

    Does it declare which hosts it may contact?

    Without a declared egress list, the honest answer to what can leave is everything. This is also the shape of the most common serious weakness in this category.

  2. 2

    Is command execution fixed or open ended?

    A fixed set of named commands can be read. An interface that runs whatever string it is given has a capability list decided at run time by a model.

  3. 3

    Does it need write access for a job that is reading?

    If it does, the usual reason is one broad integration where there should have been two narrow ones. Prefer the server that split them.

  4. 4

    Can you issue it a scoped credential?

    Never hand over a personal token carrying your own full access. If the setup instructions ask for one, ask the maker before you install.

  5. 5

    When was it last updated, and when was it last tested?

    A recent update next to an older test date means the thing you are about to install has not been checked in the form you are getting it.

  6. 6

    Read the tool descriptions yourself, once.

    They are free text the server controls and the model reads as instructions. Anything that reads like a command rather than a description is worth stopping for.

  7. 7

    Does it run locally or remotely?

    It changes what an attacker reaches if it is compromised. A local server sits inside your machine's trust boundary.

  8. 8

    Are there open findings, and are they reachable?

    Severity says how bad it could be. Reachability says whether it can happen to you. Neither is useful alone.

  9. 9

    What happens to data it processes?

    Where it sends data to a third party, that third party's terms now apply to you. Read who, not just whether.

  10. 10

    Is the licence one you can actually use?

    Check it against your own commercial position now rather than after you have built something on it.

  11. 11

    Is there a way back out?

    Know how to revoke its access before you grant it, and rotate anything you gave it when you stop.

  12. 12

    Would you be comfortable if it did the worst legal thing it is permitted to do?

    This is the whole checklist in one question. If the answer is no, the permissions are too broad, whatever the software's intentions.

Hear about new checklists

Leave your address to hear when a new checklist or free tool is published. Nothing else. This form does not email you a copy of this page.

No spam, no selling your address, unsubscribe in one click. The tools stay free either way.

Was this useful?

Educational information, not financial advice. Figures current as of July 2026 where dated; allowances and rates change, so check the source before acting.