Using Existing MCP Servers

Hundreds of MCP servers exist — filesystem, GitHub, databases. Using them well is a security and governance exercise wearing a configuration file.

▶ Watch this reel

What you'll learn

  1. The reference server zoo
  2. Connecting from hosts
  3. Trust: the supply-chain question
  4. MCP gateways

Remember this

Reference servers

Connecting

Trust (supply chain)

Gateways

Code: The server-vetting checklist

# Before adding ANY MCP server to your stack:

provenance:
  □ Official/reference impl, or vendor-authored for its own API?
  □ Known maintainers, public repo, issue responsiveness?

surface:
  □ Read the exposed tools — does each match the server's stated job?
  □ Any unexpected capabilities (shell, network, file writes)?

permissions:
  □ Minimum scopes? Read-only where possible?
  □ Credentials scoped to specific repos/paths, not broad?

operations:
  □ Version pinned (npx pkg@1.2.3 / lockfile), not latest?
  □ Tracks MCP spec revisions (post-2026-07-28 aware)?
  □ Logged in the team server registry (no shadow IT)?

# 2 minutes per server. Cheaper than one incident.