Policy before plugins — write the allowlist first
The catalog has passed 10,000 MCP servers. Your agent does not need another install this week. It needs a one-page allowlist before the next npx line ships.
Source: Influzer.ai
Policy before plugins. That is the sequencing most MCP teams still get backwards.
The directory has passed 10,000 servers — and only a few percent have indexed tools. Install UX is a copy-paste. This week the ecosystem is arguing about agent incidents and pre-execution policy gates for tool calls. The useful version for a product team is not a new gateway product. It is a one-page table: what may connect, what may write, what is banned — published before the next npx lands in shared config.
Why it matters: plugins without a policy are unreviewed production access with a friendly Connect button. Search can stay open (Discovery is read-only). Install should be default-deny for writes.
Steal the one-page allowlist, the five hallway refusals, and a 48-hour rollout: Policy Before Plugins. Pair with the demoware filter and .cursor/mcp.json as team policy.