MCP server pre-install checklist
Twelve checks before you add a server. The first six take minutes; the rest are for servers that will hold real access.
Before you install
- Who publishes it? Prefer the service's own official server. Check the repository's owner, age and recent activity.
- Read every tool description in full. Look for hidden instructions, references to files or other tools, and invisible characters. MCP Server Check does the pattern pass.
- List what each tool can do. Run code, write files, fetch URLs, read secrets, delete. Switch off the tools you don't need.
- Pin the version.
name@1.2.3,name==1.2.3orimage@sha256:…. Nevercurl … | sh. - Give it the narrowest credential. One scoped, short-lived token from your client's secret store, never a personal admin token.
- Limit file access to one project folder.
For servers with real access
- Run it isolated: a container with no host network, no Docker socket and read-only mounts.
- Limit network egress to the domains it needs; block private address ranges (SSRF, covered in the MCP security best practices).
- Keep approvals on for tools that write, send, delete or pay.
- Check remote servers use proper authorisation and don't pass your token through to other services (token passthrough is an anti-pattern in the MCP security guidance).
- Log tool calls with the user and agent that made them.
- Name an owner who re-reviews the server on every upgrade.
Your client config matters too: check it with the MCP config security checker.
Sources
- Model Context Protocol: Security best practices
- Model Context Protocol specification (2025-06-18): Tools
- Checked 28 September 2026.