Skip to content

Entry Criteria #31

Open
Open
@ChrisJBurns

Description

@ChrisJBurns

I believe we should have entry criteria to what makes its way onto the registry. I've spoken about this previously but I feel we have the opportunity to not just shift security left, but to start left.

Instead of making it the wild-west of what can make its way onto the registry, we should have some entry criteria that all MCP servers have to meet in order to get represented.

Some of the criteria should include:

  • Is the server maintained?
  • Is there any attestations that provide information about server signing or build proof?
  • Security risk (taking into account CVEs) so that users can see how vulnerable a server is before they pull it

Happy to work with people on this.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestnot go-live blockerThis issue has been reviewed and determined to not be a blocker to go-live

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions