Last reviewed
Correct answer: A. Security scanning is delegated elsewhere, so a listing says who published a server and not that it is safe.
Explanation
The principle — Read what a directory claims to check before treating its listing as a check.
Why the key is correct — The registry is explicit about the boundary. The MCP Registry delegates security scanning to: the underlying package registries, which do their own scanning, and downstream aggregators, which may add checks and curation. Its own remit is stated just as plainly — the MCP Registry focuses on namespace authentication and metadata hosting, while relying on the broader ecosystem for security scanning of actual server code. So a listing is a statement about provenance, and the review the policy skipped has not happened anywhere the team can point to.
Why the others are wrong — There is no shallow audit to lean on, no submission-time content scan, and the flaw is not about takedown timing.
Remember this — Listing proves who published it, not what it does.
Sources — MCP first-party documentation.
Sources
“The MCP Registry delegates security scanning to:”
“The MCP Registry focuses on namespace authentication and metadata hosting, while relying on the broader ecosystem for security scanning of actual server code.”
Practise 10 questions on this topic
Take MCP Fundamentals — Timed Test 1 (10 questions) — scored instantly, explanation for every question, no login.