Journal
Guides & analysis
How the Model Context Protocol works, how to tell a trustworthy server from a risky one, and what the data actually says about the ecosystem. Written for developers wiring MCP servers into real agents.

MCP governance for enterprises: taming shadow AI sprawl
Developers wire in MCP servers faster than security teams can review them. Real MCP governance: visibility, policy, audit trail, monitoring.

MCP Inspector: how to test and debug an MCP server
MCP Inspector is the official tool for testing MCP servers live — how to run it, read a server's real tool schemas, and use it alongside a Trust Score.

What is llms.txt? The file that helps AI cite your site
llms.txt is a proposed markdown file at /llms.txt that gives AI systems a curated summary to cite from — how it works, plus Vouchity's own real example.

How to use MCP servers with Claude Desktop and Cursor
A step-by-step guide to adding an MCP server to Claude Desktop and Cursor: real config paths, field names, a worked example, and common setup problems.

How to build an MCP server: a step-by-step guide
A hands-on guide to building an MCP server: choosing TypeScript or Python, defining a tool with a real schema, and what changes when you go remote.

MCP prompt injection: how it works and how to spot it
Tool descriptions and results are both read by the model as context — how MCP prompt injection works, two attack patterns, and the defenses that hold up.

MCP Directories Compared: mcp.so, Glama, PulseMCP, Smithery
mcp.so, Glama, PulseMCP and Smithery help you discover MCP servers, but none independently scores their trustworthiness. Here's how they compare.

Vouchity vs Smithery: which MCP directory should you trust?
Smithery is an MCP registry and hosted deployment platform, now part of Arcade.dev. Vouchity is an independent Trust Score layer. How they actually differ.
What is an MCP registry, and why does it need trust?
An MCP registry lists servers so agents can find them — it verifies who published one, not whether it's safe. Discovery vs. trust, with real numbers.

What is the Model Context Protocol? A complete guide
The Model Context Protocol is Anthropic's open standard connecting AI apps to tools and data. Its architecture, primitives and transports, fully explained.

MCP best practices for server authors: a checklist for trust
MCP best practices for server authors: license it, document honestly, scope permissions, use semver, and stay reachable. Mapped to a Trust Score.

Remote vs local (stdio) MCP servers: trust, auth and what to watch for
A local (stdio) MCP server has no network exposure; a remote one needs its own auth story. The trust model for each, and how MCP differs from a plain API.
How to vet an MCP server before you connect it to your agents
How to vet an MCP server: check its license, maintenance, versioning, auth and least-privilege scopes, and provenance before you connect it to an agent.

MCP server security in 2026: the risks nobody checks before installing
Over a third of remote MCP servers Vouchity tracks declare no auth, and over half carry no license. What MCP security risk looks like in the real data.

The best MCP servers in 2026 (and how to tell which ones you can trust)
The highest Trust Score MCP servers we track, plus per-category leaders — ranked from live GitHub and npm data, not a hand-curated awesome list.
What is an MCP server? A plain-English guide
An MCP server exposes tools, data or prompts to an AI agent over the Model Context Protocol. How it works, and why not every one deserves your trust.
Trust Score changes, in your inbox
A weekly digest of newly flagged risks and the biggest Trust Score movers across the MCP registry. No spam, unsubscribe anytime.
Vet before you connect.
Browse every MCP server's Trust Score free. Create an account to watch the servers you depend on and get notified when something changes.