Skip to content

doc: the claims in security.md need updating to the current purpose of the repository which includes an inventory of community servers #2164

Closed
@wherka-ama

Description

@wherka-ama

The SECURITY.md in this repo states:

These servers are maintained by Anthropic as part of the Model Context Protocol project.

I think this is a very confusing and in fact misleading claim. It gives people who look at the list of the servers which goes in well over 500 (most of them are community driven) a false sense of security.

One might see it and think - okay, that's covered by Anthropinc - cool! I'm not going to check anything anymore. If something bad happens they will scream at you. It will not be a legal problem of course as it's very easy to point at full description contained in the README etc. Nevertheless, it could be a bit damaging to Anthropic and this community which I deeply care about.

Don't you think it would be better to rephrase it as:

The reference servers in this repo are maintained by Anthropic as part of the Model Context Protocol project.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions