Is this MCP server safe to connect?
Five checks before giving an AI assistant access to client files, a database or another business tool through MCP.

How do I check an MCP server before connecting it?
Check who maintains it, which program or service you will actually connect to, what access it needs and how you can remove that access later. Start with test data and limited permissions. A directory listing, a familiar logo or a working demo does not establish that a connection is safe.
Name the access you are about to give
An MCP server lets an assistant work with another tool. For a small agency, that could mean finding a document, reading an issue tracker or changing a client’s website. Those jobs carry different consequences. Before connecting anything, finish this sentence: “This assistant needs to do this task, using this account, for this project.”
If the task is reading a project brief, access to every client folder needs an explanation. If the tool can publish, delete or send messages, identify when a person must approve those actions. Check the controls actually provided by the assistant and service. A rule written in a prompt is not a substitute for an enforced permission.
Check the supplier and the destination
Follow the setup link from the supplier’s own website or documentation. Compare the package name, publisher and server address with the instructions. A copied configuration from a forum may point somewhere different. Treat a local server as software you are installing and a remote server as a service you are trusting.
Look for a maintained project, clear installation instructions and a way to report security problems. Read what the service says about data handling. These checks reduce uncertainty; none is a safety certificate. If the maintainer or destination is unclear, ask a developer to review it before connecting a live client account.
Before you connect
- Source
Who supplies the server?
- Scope
What can the connection do?
- Exit
How will you remove access?
Example workflow.
Make the first test deliberately small
Use a test project or non-sensitive sample data. Where the service supports it, create a separate account or credential with only the permissions needed. Avoid reusing an administrator key simply because it is already in your password manager. Test whether the intended job works before widening access, and document any restriction you had to relax.
For example, an assistant summarising support issues can start with read access to a test project. It does not need permission to delete tickets or manage users. Watch which tool calls the assistant proposes. Unexpected requests for broader access are a reason to pause and understand the setup, not another box to click through.
Know how to disconnect it before you rely on it
Write down where the connection is configured and where the underlying access is controlled. These might be two different places. Disabling the MCP server in an editor can stop that editor using it, while a service credential remains valid. Check the issuing service’s instructions for revoking a grant or replacing a key.
Assign an owner and a review date tied to the project. Repeat the review when a tool changes substantially, a contractor leaves or the client changes what data you can use. Keep the name of the credential in your record, not the secret itself. A client handover should include these connections, alongside ordinary user accounts.
Keep the connection visible after setup
Cybee can show installed AI tools and mapped MCP connections on enrolled Macs, with available recorded tool activity. That helps you find a connection you forgot and ask who still needs it. Start with /cybee in your connected assistant to explore the available questions alongside the Mac’s security status.
This visibility does not certify a third-party server or impose permissions on every agent. It also does not prove that every configured connection has been used. Use the inventory to guide the access review, then make and verify changes in the relevant tool. The aim is a useful assistant with access you can explain.
What to remember
- Verify the supplier and the actual destination.
- Test with limited access and non-sensitive data.
- Document how to remove the connection and its underlying access.
Sources and further reading
Product scope and provider guidance can change. Check the linked source for your own setup.
Put it to work.
Continue with a practical guide or see how cybee helps with the work.