{"id":3218,"date":"2025-05-16T18:37:40","date_gmt":"2025-05-16T18:37:40","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=3218"},"modified":"2025-05-16T18:37:40","modified_gmt":"2025-05-16T18:37:40","slug":"is-it-secure-to-use-an-mcp-server","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=3218","title":{"rendered":"Is it secure to use an MCP server?"},"content":{"rendered":"<p>The Model Context Protocol (MCP) is a convenient open protocol for linking large-scale language models (LLMs) with external data sources and tools. However, since anyone can create an MCP server and publish it on GitHub, there is a possibility that it may contain malicious code. It is at your own risk if you embed vulnerabilities in your homemade MCP server, but how safe can you actually be when using a public MCP server via a marketplace? This article explains the current state of the MCP server marketplace and some points to note when using it.<\/p>\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#1.1.-tl%3Bdr\"><\/a>1.1. TL;DR<\/h2>\n<p>The premise is that \u201csomeone is guaranteeing something, so use it at your own risk.\u201d Among them, the following two are considered to be trustworthy to a certain extent. The rest are provided without any official guarantee.<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/tree\/main\/src\" target=\"_blank\" rel=\"noopener\"><\/a>Those registered under\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/tree\/main\/src\" target=\"_blank\" rel=\"noopener\">servers\/src in modelcontextprotocol org<\/a><\/p>\n<p>When the MCP server connects to the official repository of the service. Example:\u00a0<a href=\"https:\/\/github.com\/tavily-ai\/tavily-mcp\" target=\"_blank\" rel=\"noopener\">tavily\/mcp-server<\/a>\u00a0provided by\u00a0<a href=\"https:\/\/tavily.com\/\" target=\"_blank\" rel=\"noopener\">tavily<\/a><a href=\"https:\/\/github.com\/tavily-ai\/tavily-mcp\" target=\"_blank\" rel=\"noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#1.2-%E7%90%86%E7%94%B1\"><\/a>1.2 Reasons<\/h2>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\" target=\"_blank\" rel=\"noopener\">The official MCP GitHub repository<\/a>\u00a0is maintained by Anthropic and contains servers implemented by Anthropic itself as well as community contributed servers.<\/p>\n<p> Reference Servers: MCP servers implemented by Anthropic itself<\/p>\n<p> Third-Party Servers: MCP servers implemented by parties other than Anthropic<\/p>\n<p> Official Integrations: MCP servers implemented as official repositories for connected services<\/p>\n<p> Community Servers: MCP servers that can be provided by anyone who is not related to the service you are connecting to.<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers?tab=readme-ov-file#-community-servers\" target=\"_blank\" rel=\"noopener\">Community Servers have not been explicitly tested and are used at your own risk<\/a>\u00a0.<\/p>\n<p><a href=\"https:\/\/cline.bot\/mcp-marketplace\" target=\"_blank\" rel=\"noopener\"><\/a>I think the standards for trusting\u00a0<a href=\"https:\/\/cline.bot\/mcp-marketplace\" target=\"_blank\" rel=\"noopener\">Cline\u2019s MCP Marketplace should be almost the same as the official MCP (see Section 4.2 for details).<\/a><\/p>\n<h1 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#2.-mcp%2Fmcp%E3%82%B5%E3%83%BC%E3%83%90%E3%83%BC%E3%81%A8%E3%81%AF\"><\/a>2. What is MCP\/MCP Server?<\/h1>\n<p><a href=\"https:\/\/zenn.dev\/yamada_quantum\/articles\/465c4993465053\" target=\"_blank\" rel=\"noopener\"><\/a>\u201cI\u2019ve heard of MCP, but I haven\u2019t used it\u2026\u201d For those who have heard of it , I\u2019ll write a simple\u00a0<a href=\"https:\/\/zenn.dev\/yamada_quantum\/articles\/465c4993465053\" target=\"_blank\" rel=\"noopener\">explanation, from the basics to more advanced content<\/a>\u00a0, as there are already explanations in Japanese. For more information, please refer to\u00a0<a href=\"https:\/\/modelcontextprotocol.io\/introduction\" target=\"_blank\" rel=\"noopener\">the official MCP doc .<\/a><\/p>\n<p>MCP (Model Context Protocol) is an open protocol for applications to provide context to large-scale language models (LLMs). It is like a \u201cUSB-C port\u201d for AI applications (Claude Desktop, Cline, etc.) and standardizes how LLMs can be integrated with external data sources and tools.<\/p>\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<p>Confused about the hype around MCP (Model Context Protocol)?<\/p>\n<p>Here\u2019s a quick visual <\/p>\n<p>MCP is like a universal \u201cUSB-C\u201d for AI agents, letting them plug into tools &amp; data sources without juggling multiple APIs.<\/p>\n<p>I&#8217;ll break it down step by step  <a href=\"https:\/\/t.co\/q4k6pxhWtZ\">pic.twitter.com\/q4k6pxhWtZ<\/a><\/p>\n<p>\u2014 Norah Sakal (@norahsakal) <a href=\"https:\/\/twitter.com\/norahsakal\/status\/1898183864570593663?ref_src=twsrc%5Etfw\">March 8, 2025<\/a><\/p><\/div>\n<\/div>\n<p>MCP servers are lightweight programs that expose certain functions (such as web searches, file operations, API integration, and database access) through the MCP protocol. By connecting to these servers, MCP clients allow AI agents to use external knowledge and functions. For example, there are MCP servers for connecting to PostgreSQL. The MCP server itself does not function as a database, but acts as an intermediary for communication with PostgreSQL. In that sense, it may be more accurate to think of it as a \u201cconnector\u201d rather than an MCP server. Anyone can create an MCP server and publish it on GitHub.<\/p>\n<h1 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#3.-mcp%E3%82%B5%E3%83%BC%E3%83%90%E3%83%BC%E5%85%AC%E9%96%8B%2F%E6%89%BF%E8%AA%8D%E7%8A%B6%E6%B3%81\"><\/a>3. MCP server publication\/approval status<\/h1>\n<p>Similar to how Google Chrome has\u00a0<a href=\"https:\/\/chromewebstore.google.com\/?hl=ja\" target=\"_blank\" rel=\"noopener\">a Chrome Web Store<\/a>\u00a0for extensions , Anthropic, the creators of MCP,\u00a0maintain an MCP server repository on GitHub (\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/modelcontextprotocol\/servers ) that contains both Anthropic\u2019s implementations of MCP servers as well as a list of community-contributed MCP servers.<\/a><\/p>\n<p><a href=\"https:\/\/github.com\/cline\/cline\" target=\"_blank\" rel=\"noopener\">In addition to the official Anthropic, Cline<\/a>\u00a0, a GitHub extension\u00a0, also\u00a0offers\u00a0<a href=\"https:\/\/cline.bot\/mcp-marketplace\" target=\"_blank\" rel=\"noopener\">Cline\u2019s MCP Marketplace<\/a>\u00a0. To register with this Cline\u2019s MCP Marketplace, you need to submit an issue to\u00a0<a href=\"https:\/\/github.com\/cline\/mcp-marketplace\" target=\"_blank\" rel=\"noopener\">the cline\/mcp-marketplace repository and have it reviewed. Example of a reviewed issue:\u00a0<\/a><a href=\"https:\/\/github.com\/cline\/mcp-marketplace\/issues\/44\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/cline\/mcp-marketplace\/issues\/44<\/a><\/p>\n<h1 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#4-mcp%E5%85%AC%E5%BC%8F%E3%83%AA%E3%83%9D%E3%82%B8%E3%83%88%E3%83%AA%E3%81%AE%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%85%A8%E8%88%AC\"><\/a>4. General security of MCP official repositories<\/h1>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/\" target=\"_blank\" rel=\"noopener\">It seems that the modelcontextprotocol<\/a>\u00a0organization is primarily run by Anthropic.<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/\" target=\"_blank\" rel=\"noopener\">The modelcontextprotocol<\/a>\u00a0organization on GitHub\u00a0has the following:<\/p>\n<p>The Model Context Protocol is an open source project run by Anthropic, PBC. and open to contributions from the entire community.<\/p>\n<p>It is stated as follows:<\/p>\n<p>Conversely, the anthropic.com site,\u00a0<a href=\"https:\/\/www.anthropic.com\/news\/model-context-protocol\" target=\"_blank\" rel=\"noopener\">Introducing the Model Context Protocol<\/a>\u00a0, states:<\/p>\n<p>The Model Context Protocol\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\" target=\"_blank\" rel=\"noopener\">specification and SDKs<\/a>(omitted)Contribute to our open-source repositories of connectors and implementations<\/p>\n<p>This statement indicates that this is an official Anthropic project.<\/p>\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#4.1-modelcontextprotocol%2Fserver-%E3%83%AA%E3%83%9D%E3%82%B8%E3%83%88%E3%83%AA\"><\/a>4.1 modelcontextprotocol\/server repository<\/h2>\n<p>Under modelcontextprotocol there is a repository called\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/\" target=\"_blank\" rel=\"noopener\">servers<\/a>\u00a0(hereinafter referred to as the official repository). This repository publishes the official implementation of the MCP server Anthropic and introduces other MCP servers.<\/p>\n<p>Regarding security,\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/blob\/main\/SECURITY.md\" target=\"_blank\" rel=\"noopener\">the Security Policy<\/a>\u00a0states the following:<\/p>\n<p>The security of our systems and user data is Anthropic\u2019s top priority.<\/p>\n<p>Furthermore, Anthropic, the developer of MCP, has obtained the following certifications, although it is unclear to what extent these have been applied to the development of MCP.<\/p>\n<p>SOC 2 Type I<\/p>\n<p>HIPAA<\/p>\n<p>SOC 2 Type II<\/p>\n<p>ISO 27001:2022<\/p>\n<p>ISO\/IEC 42001:2023<\/p>\n<p>Reference:\u00a0<a href=\"https:\/\/trust.anthropic.com\/\" target=\"_blank\" rel=\"noopener\">https:\/\/trust.anthropic.com\/<\/a><\/p>\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#4.2-%E3%81%A9%E3%81%93%E3%81%BE%E3%81%A7%E4%BF%A1%E7%94%A8%E3%81%97%E3%81%A6%E8%89%AF%E3%81%84%E3%81%8B%3F\"><\/a>4.2 How much can I trust it?<\/h2>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers?tab=readme-ov-file#-reference-servers\" target=\"_blank\" rel=\"noopener\"> I think you can trust the Reference Servers<\/a>\u00a0section to a certain extent, because\u00a0the sources it references are under\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/tree\/main\/src\" target=\"_blank\" rel=\"noopener\">the src directory of the modelcontextprotocol\/servers repository , which is the official MCP repository.<\/a><\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers?tab=readme-ov-file#%EF%B8%8F-official-integrations\" target=\"_blank\" rel=\"noopener\"> I think you can trust the Official Integrations<\/a>\u00a0section to a certain extent. (Note that Community Servers are not included.) For example,\u00a0<a href=\"https:\/\/github.com\/JetBrains\/mcp-jetbrains\" target=\"_blank\" rel=\"noopener\">the MCP server for JetBrains is created under\u00a0<\/a><a href=\"https:\/\/www.jetbrains.com\/\" target=\"_blank\" rel=\"noopener\">the JetBrains<\/a>\u00a0organization. If there\u00a0is a security incident on this MCP server, JetBrains will also be criticized, which will result in Jetbrains losing credibility and its business performance, so it is believed that they will make an effort to implement a secure MCP server.<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers?tab=readme-ov-file#-community-servers\" target=\"_blank\" rel=\"noopener\"> Community Servers<\/a>\u00a0are also listed in README.md<\/p>\n<p>Note: Community servers are untested and should be used at your own risk. They are not affiliated with or endorsed by Anthropic.<\/p>\n<p>Summary<\/p>\n<p>Please note: Community servers are untested, use at your own risk, and are not affiliated with or endorsed by Anthropic.<\/p>\n<p>So, the reliability is considered to be low. As stated, it is best to use it at your own risk.<\/p>\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#4.3.-%E5%85%B7%E4%BD%93%E7%9A%84%E3%81%AA%E3%83%AA%E3%83%9D%E3%82%B8%E3%83%88%E3%83%AA%E9%81%8B%E7%94%A8%E5%86%85%E5%AE%B9\"><\/a>4.3. Specific repository operations<\/h2>\n<p>This is a bit of a geeky section, so you can skip it. It\u2019s about reliable GitHub accounts and the people who are doing the reviews.<\/p>\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#4.3.1.-%E5%85%AC%E5%BC%8F%E3%83%AA%E3%83%9D%E3%82%B8%E3%83%88%E3%83%AA%E3%81%AE-src-%E3%83%87%E3%82%A3%E3%83%AC%E3%82%AF%E3%83%88%E3%83%AA%E9%85%8D%E4%B8%8B%E3%81%ABmcp%E3%82%B5%E3%83%BC%E3%83%90%E3%83%BC%E3%82%92%E5%AE%9F%E8%A3%85%E3%81%95%E3%82%8C%E3%82%8B%E9%81%8E%E7%A8%8B\"><\/a>4.3.1. The process of implementing an MCP server under the src directory of the official repository<\/h2>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/tree\/main\/src\" target=\"_blank\" rel=\"noopener\">To add it to the official MCP server under the src directory of modelcontextprotocol\/servers<\/a>\u00a0, you need to submit a pull request and have it approved, just like other OSS.<\/p>\n<p>As of March 26, 2025,\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/620\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/620<\/a>\u00a0is in the state shown below (Review Required image), so it is likely that\u00a0<a href=\"https:\/\/docs.github.com\/ja\/organizations\/organizing-members-into-teams\/about-teams\" target=\"_blank\" rel=\"noopener\">a Team<\/a>\u00a0has been defined that combines GitHub accounts registered in\u00a0<a href=\"https:\/\/github.com\/orgs\/modelcontextprotocol\/people\" target=\"_blank\" rel=\"noopener\">People<\/a>\u00a0and GitHub accounts approved by Anthropic using the\u00a0<a href=\"https:\/\/docs.github.com\/ja\/repositories\/configuring-branches-and-merges-in-your-repository\/managing-protected-branches\/about-protected-branches\" target=\"_blank\" rel=\"noopener\">protected branch<\/a>\u00a0function (\u203b).<a href=\"https:\/\/github.com\/orgs\/modelcontextprotocol\/people\" target=\"_blank\" rel=\"noopener\"><\/a><a href=\"https:\/\/docs.github.com\/ja\/organizations\/organizing-members-into-teams\/about-teams\" target=\"_blank\" rel=\"noopener\"><\/a><\/p>\n<p>As a first example, the official implementation of Anthropic PostgreSQL\u00a0is included in\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/commit\/37415258b914330d10ed0ea948d67ac8a410a384\" target=\"_blank\" rel=\"noopener\">the initial commit<\/a>\u00a0and was created by jspahrsummers, who\u00a0<a href=\"https:\/\/github.com\/jspahrsummers\" target=\"_blank\" rel=\"noopener\">is<\/a>\u00a0currently registered in\u00a0<a href=\"https:\/\/github.com\/orgs\/modelcontextprotocol\/people\" target=\"_blank\" rel=\"noopener\">the People section of the official MCP organization as of 2025\/03\/26.<\/a><\/p>\n<p>To take a second example,\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/413\/\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/413\/<\/a>\u00a0is a Redis MCP server implementation by Anthropic, judging from the directory where the source code was added. The person who approved the pull request is\u00a0<a href=\"https:\/\/github.com\/jerome3o-anthropic\" target=\"_blank\" rel=\"noopener\">jerome3o-anthropic<\/a>\u00a0. As of 2025\/03\/26,\u00a0<strong>he is not<\/strong>\u00a0registered in\u00a0<a href=\"https:\/\/github.com\/orgs\/modelcontextprotocol\/people\" target=\"_blank\" rel=\"noopener\">People<\/a>\u00a0! The account name seems to be related to anthropic, so he may have been registered in People as of\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/413\/#pullrequestreview-2600518025\" target=\"_blank\" rel=\"noopener\">2025\/2\/7 when he approved it<\/a>\u00a0. As noted in (\u203b), it is not strictly clear whether he is a member of Anthropic. Judging from the fact that this person can merge the pull request he approved into the main branch, I think he is probably the maintainer of Anthropic.<strong><\/strong><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/413\/#pullrequestreview-2600518025\" target=\"_blank\" rel=\"noopener\"><\/a><\/p>\n<p>(\u203b)This is just a guess, as the Team that brings together the GitHub accounts associated with Anthropic employees has not been made public.<\/p>\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#4.3.2.-official-integrations-%E3%81%AEmcp%E3%82%B5%E3%83%BC%E3%83%90%E3%83%BC%E3%81%8C%E5%85%AC%E5%BC%8F%E3%81%AEreadme.md%E3%81%AB%E8%BF%BD%E5%8A%A0%E3%81%95%E3%82%8C%E3%82%8B%E9%81%8E%E7%A8%8B\"><\/a>4.3.2. Official Integrations MCP Servers are added to the official README.md<\/h2>\n<p>The README.md file will be added once\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\" target=\"_blank\" rel=\"noopener\">the modelcontextprotocol\/servers pull request<\/a>\u00a0is approved.<\/p>\n<p>Prior to this, the referenced repository must implement an MCP server.<\/p>\n<p>Example: JetBrains<\/p>\n<p>Referenced MCP server:\u00a0<a href=\"https:\/\/github.com\/JetBrains\/mcp-jetbrains\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/JetBrains\/mcp-jetbrains<\/a><\/p>\n<p>Pull Request for README.md:\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/355\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/355<\/a><\/p>\n<p>A pull request was created in the official repository on\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/355#issue-2741682088\" target=\"_blank\" rel=\"noopener\">2024\/12\/16<\/a>\u00a0.<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/355#pullrequestreview-2506880955\" target=\"_blank\" rel=\"noopener\">The date of approval was December 17, 2024<\/a>\u00a0, so<\/p>\n<p>The MCP server that appears to have been reviewed is in\u00a0<a href=\"https:\/\/github.com\/JetBrains\/mcp-jetbrains\/tree\/39041ccc559055ce6e10ce068d74fd90f412b79f\" target=\"_blank\" rel=\"noopener\">39041cc<\/a>\u00a0condition.<\/p>\n<p>You can see that development continues after 2024\/12\/17.\u00a0See\u00a0<a href=\"https:\/\/github.com\/JetBrains\/mcp-jetbrains\/commits\/main\/\" target=\"_blank\" rel=\"noopener\">the commit history .<\/a><\/p>\n<p>It is unclear whether the official MCP Server side continues to check\u00a0<a href=\"https:\/\/github.com\/JetBrains\/mcp-jetbrains\" target=\"_blank\" rel=\"noopener\">JetBrains\/mcp-jetbrains<\/a>\u00a0. Therefore, it is possible that the repository of the MCP server referenced after approval could be hijacked or malicious code could be embedded. However, if that were to happen, JetBrains\u2019 credibility would also be damaged, which would lead to disadvantages for JetBrains, so this can be interpreted as Anthropic trusting that JetBrains continues to be vigilant about security.<\/p>\n<h1 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#5-cline%E5%85%AC%E5%BC%8F%E3%81%AEmcp%E3%82%B5%E3%83%BC%E3%83%90%E3%83%BC%E3%81%AE%E3%83%9E%E3%83%BC%E3%82%B1%E3%83%83%E3%83%88%E3%83%97%E3%83%AC%E3%82%A4%E3%82%B9\"><\/a>5. Cline\u2019s official MCP server marketplace<\/h1>\n<p>cline is\u00a0creating its own marketplace of MCP servers for direct use by cline in\u00a0<a href=\"https:\/\/github.com\/cline\/mcp-marketplace\" target=\"_blank\" rel=\"noopener\">the Cline MCP Marketplace repository .<\/a><\/p>\n<p>What is the MCP Marketplace?The MCP Marketplace is a curated collection of MCP servers that makes discovery and installation easy. With the marketplace, you can:<\/p>\n<p>Browse official and community-made MCP serversSearch by name, category, tags, and other metadataInstall MCP servers with one click, triggering Cline to autonomously handle cloning, setup, and configuration.<\/p>\n<p>Summary<\/p>\n<p>What is MCP Marketplace?MCP Marketplace is a curated collection of MCP servers that are easy to discover and install. With the Marketplace you can:<\/p>\n<p>Browse official and community-made MCP serversSearch by name, category, tags, and other metadataInstall your MCP server with one click and trigger Cline to handle cloning, setup, and configuration automatically.<\/p>\n<p>Here,\u00a0official and community-made MCP serversthe means<\/p>\n<p>Official Anthropic MCP server. In terms of the names mentioned above,\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\" target=\"_blank\" rel=\"noopener\"> Reference Servers<\/a><\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers?tab=readme-ov-file#%EF%B8%8F-official-integrations\" target=\"_blank\" rel=\"noopener\"> Official Integrations<\/a>\u00a0MCP Server<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers?tab=readme-ov-file#%EF%B8%8F-official-integrations\" target=\"_blank\" rel=\"noopener\"> Community Servers<\/a>\u00a0MCP Servers<\/p>\n<p><a href=\"https:\/\/github.com\/cline\/mcp-marketplace\/issues?q=is%3Aissue%20state%3Aclosed\" target=\"_blank\" rel=\"noopener\">MCP servers that clients have approved in their repository issues<\/a><\/p>\n<p>I think so. Here is my personal opinion on the credibility:<\/p>\n<p>I think it&#8217;s: 1 &gt; 2 &gt;&gt; 4 &gt;&gt;&gt; (an unbridgeable gap) &gt;&gt;&gt; 3 in terms of trustworthiness.<br \/>\n\u3010Trustworthy\u3011 \u2192 \u3010Untrustworthy\u3011<\/p>\n<p>The reason is that to register for this marketplace, you need to create a new issue in your GitHub repository and have it approved.<\/p>\n<p>Regarding 1, I think it is fair to trust it to a certain extent for the same reasons stated in Section 4.2.<\/p>\n<p>Regarding 2., I think it is fair to trust it to a certain extent for the same reasons stated in Section 4.2.<\/p>\n<p>As stated in Section 4.2, 3. is provided without warranty and is at your own risk.<\/p>\n<p>Regarding 4., the maintainers of cline have reviewed and added it, so I think it can be trusted to a certain extent. However, it is considered less trustworthy than Anthropic.<br \/>This is because cline is OSS, and although it is a bit misleading to call it a development company,\u00a0<a href=\"https:\/\/cline.bot\/\" target=\"_blank\" rel=\"noopener\">the developer of cline<\/a>\u00a0has not received as much security-related approval as Anthropic.<\/p>\n<h3 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#5.1-cline%E3%81%AEmcp%E3%83%9E%E3%83%BC%E3%82%B1%E3%83%83%E3%83%88%E3%83%97%E3%83%AC%E3%82%A4%E3%82%B9%E3%81%B8%E3%81%AE%E7%99%BB%E9%8C%B2%E9%81%8E%E7%A8%8B\"><\/a>5.1 cline\u2019s MCP Marketplace registration process<\/h3>\n<p>Like 4.3, this section is aimed at enthusiasts, so you can skip it if you like.<\/p>\n<p>Although the maintainer of the Cline MCP marketplace has not been specified,\u00a0I think it is safe to say that\u00a0<a href=\"https:\/\/github.com\/pashpashpash\" target=\"_blank\" rel=\"noopener\">pashpashpash<\/a><br \/>is the maintainer of the Cline repository. Reason<\/p>\n<p>As of 2025\/03\/26, there are no\u00a0<a href=\"https:\/\/github.com\/orgs\/cline\/people\" target=\"_blank\" rel=\"noopener\">people<\/a>\u00a0in cline\u2019s organization !<\/p>\n<p><a href=\"https:\/\/github.com\/cline\/mcp-marketplace\" target=\"_blank\" rel=\"noopener\"><\/a>The author of\u00a0<a href=\"https:\/\/github.com\/cline\/mcp-marketplace\/commit\/42c83a064cefa23bba573682515486919259ef14\" target=\"_blank\" rel=\"noopener\">the initial commit<\/a>\u00a0of\u00a0<a href=\"https:\/\/github.com\/cline\/mcp-marketplace\" target=\"_blank\" rel=\"noopener\">mcp-marketplace is\u00a0<\/a><a href=\"https:\/\/github.com\/pashpashpash\" target=\"_blank\" rel=\"noopener\">pashpashpash<\/a>\u00a0.<\/p>\n<p>MCP servers registered in the cline MCP Marketplace are<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\" target=\"_blank\" rel=\"noopener\"><\/a>The MCP servers registered in\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\" target=\"_blank\" rel=\"noopener\">modelcontextprotocol\/servers are reflected sequentially.<\/a><\/p>\n<p>Reflecting what was approved in the issue of\u00a0cline\u2019s\u00a0<a href=\"https:\/\/github.com\/cline\/mcp-marketplace\/issues\" target=\"_blank\" rel=\"noopener\">mcp-marketplace<\/a><\/p>\n<p>It seems that they are.<\/p>\n<p>Regarding the former, as of 2025\/03\/26,\u00a0<a href=\"https:\/\/github.com\/oceanbase\/mcp-oceanbase\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/oceanbase\/mcp-oceanbase\u00a0<\/a><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/pull\/1032\" target=\"_blank\" rel=\"noopener\">is registered<\/a>\u00a0in modelcontextprotocol\/servers\u00a0, but is not registered in cline\u2019s MCP marketplace.<\/p>\n<p>Regarding the latter,\u00a0<a href=\"https:\/\/github.com\/graphlit\/graphlit-mcp-server\" target=\"_blank\" rel=\"noopener\">graphlit-mcp-server<\/a>\u00a0was registered in\u00a0<a href=\"https:\/\/github.com\/cline\/mcp-marketplace\/issues\/44\" target=\"_blank\" rel=\"noopener\">#44<\/a>\u00a0, which is not registered in modelcontextprotocol\/servers as of 2025\/03\/25.<\/p>\n<h1 class=\"wp-block-heading\"><a href=\"https:\/\/zenn.dev\/arrowkato\/articles\/mcp_security#5.-%E3%81%BE%E3%81%A8%E3%82%81\"><\/a>5. Summary<\/h1>\n<p>The introduction of an MCP server is essentially at your own risk. In terms of security, the disadvantages of releasing or approving a risky MCP server are for Anthropic, the destination of that MCP server, and marketplace creators such as cline.<\/p>\n<p><a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/tree\/main\/src\" target=\"_blank\" rel=\"noopener\"><\/a>MCP servers under\u00a0<a href=\"https:\/\/github.com\/modelcontextprotocol\/servers\/tree\/main\/src\" target=\"_blank\" rel=\"noopener\">the src directory of the modelcontextprotocol\/servers repository<\/a><\/p>\n<p>An MCP server implemented by the official organization of the service to which the MCP server is connected<\/p>\n<p>If you are using cline, please\u00a0<a href=\"https:\/\/github.com\/cline\/mcp-marketplace\/issues?q=is%3Aissue%20state%3Aclosed\" target=\"_blank\" rel=\"noopener\">refer to the closed issues in cline\/mcp-marketplace<\/a>\u00a0for MCP servers.<\/p>\n<p>I think you can trust it to a certain extent.<\/p>\n<p>Anything else is at your own risk, so I think it\u2019s fine to read the source and have someone look up the relevant repository using DeepResearch or similar.<\/p>","protected":false},"excerpt":{"rendered":"<p>The Model Context Protocol (MCP) is a convenient open protocol for linking large-scale language models (LLMs) with external data sources and tools. However, since anyone can create an MCP server and publish it on GitHub, there is a possibility that it may contain malicious code. It is at your own risk if you embed vulnerabilities [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":3219,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/3218"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3218"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/3218\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/3219"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}