"An MCP server is untrusted input wearing the costume of infrastructure" is the sentence this whole topic has been missing, and scanning the full schema rather than the description string is the detail that separates this from every other MCP security post; enum values and nested field descriptions are exactly where payloads go once description-scanning becomes common. One honest addition to your registered-is-not-vetted point: discovery-side signals do not solve it either. I run Skillselion, a directory that ranks MCP servers by adoption, GitHub stars in their case since registries do not report install counts for servers (skillselion.com/mcp ; disclosure: mine), and I would be the first to say adoption numbers measure popularity, not safety; a widely installed server with a poisoned update is a bigger blast radius, not a smaller one. Directory metadata can tell you what exists and what changed between versions; your four checks are what earn the trust. The version-pinned scan logs are the piece I am stealing.