MCP Security Guides
Practical guidance, not an academic audit. Start with the MCP security best practices checklist.
How TrustedMCP Scores Servers
Every listing gets a 0–100 trust score from four public signals — authentication, maintenance, known CVEs, and transport safety — mapped to an A–D grade. It is a signal, not a manual audit.
Read September 3, 2026Linear MCP Server: Setup and Security
How to connect the official Linear MCP server to Claude, Cursor, and VS Code, and why its OAuth-over-HTTP model makes it an A-grade listing.
Read September 3, 2026markdownify-mcp: Setup and Why It Grades D
How to run the markdownify MCP server to convert PDFs, Office docs, images, and audio to Markdown — and the shell-out risk that pulls its grade to D.
Read September 3, 2026MCP Security Best Practices: A Practical Checklist
The short version: authenticate every server, avoid stdio for anything networked, treat all tool output as untrusted input, and scope credentials to the smallest surface that works.
Read September 3, 2026The OWASP MCP Top 10: Risks and How They Map to a Trust Score
The ten security risks that matter most for Model Context Protocol servers, drawn from OWASP's LLM Top 10 and MCP security research — and how each maps to the four signals TrustedMCP scores.
Read September 3, 2026Stack Overflow MCP Server: Setup and Trust Assessment
How to connect the Stack Overflow MCP server to an agent, what it can and cannot do, and why it currently grades C.
Read September 3, 2026VS Code MCP Server: Setup and Security
How to enable MCP servers in VS Code, and what the editor does and does not secure for you.
Read