Evidence-backed facts
- The official MCP Registry hosts standardized server metadata and points to public packages or remote servers; it does not host the implementation artifacts themselves. informative
- Publishing uses a server.json record and the mcp-publisher workflow; package metadata is validated before publication, and a successful listing can be checked independently through the Registry API. informative
- Namespace authentication ties a server name to a GitHub identity or domain, while the official Registry relies on the wider ecosystem for security scanning of server code; namespace verification is not a security audit. informative
- The Registry is a primary metadata source for downstream aggregators, and host applications commonly consume downstream registries; publication or aggregation is not evidence of installation, successful initialization, tool calls, or repeat use. informative