← Back to Briefs
Brief
August 31, 2026 · MCP Ecosystem

Policy before plugins — write the allowlist first

The catalog has passed 10,000 MCP servers. Your agent does not need another install this week. It needs a one-page allowlist before the next npx line ships.

Source: Influzer.ai

Policy before plugins. That is the sequencing most MCP teams still get backwards.

The directory has passed 10,000 servers — and only a few percent have indexed tools. Install UX is a copy-paste. This week the ecosystem is arguing about agent incidents and pre-execution policy gates for tool calls. The useful version for a product team is not a new gateway product. It is a one-page table: what may connect, what may write, what is banned — published before the next npx lands in shared config.

Why it matters: plugins without a policy are unreviewed production access with a friendly Connect button. Search can stay open (Discovery is read-only). Install should be default-deny for writes.

Steal the one-page allowlist, the five hallway refusals, and a 48-hour rollout: Policy Before Plugins. Pair with the demoware filter and .cursor/mcp.json as team policy.