Originally published at curatedmcp.com/blog/week-2026-30
MCP Ecosystem Week 30: When Your Developers' AI Tools Connect to Everything—What's in Your Allowlist?
This week, the MCP ecosystem holds steady at 74 risk-classified servers, with no new entries but climbing demand signal across integrations that matter most to platform teams: GitHub, OpenAI, Figma, and Claude itself. The real story isn't what's new—it's what your teams are already running without formal governance.
This Week in MCP
No new servers joined the catalog this week, but that quiet tells you something important: the ecosystem is consolidating around a core set of high-value integrations. The marketplace isn't growing by unit count; it's deepening. All 74 servers in the policy library remain available for review, each with risk classification and audit context baked in.
If you're running Week 30 governance checks, focus on what's already in use rather than what's arriving. The adoption signal below will tell you where your real governance gaps are.
On the Radar
The top five most-viewed servers reveal developer intent—and where platform teams need decision clarity:
GitHub Copilot MCP (98k views) and GitHub MCP (76k views) dominate. Both grant AI agents direct access to repo state, PRs, and workflows. Governance question: Does your team need agents modifying issues or workflows, or just reading them? Risk profile depends on whether you're granting write access or read-only. Allowlist these with scope limits.
OpenAI MCP (87k views) pipes GPT-4o, DALL-E, and Whisper into any MCP client. Critical: this creates dual-model risk. If a developer runs this and Claude through CuratedMCP, you now have two LLM supply chains to audit. Token spend visibility becomes essential here—developers may not realize they're splitting workload between vendors.
Figma MCP (82k views) is the design-to-code bridge. Lower security risk than GitHub, but introduces IP exposure risk if design tokens or component definitions leak into logs or cached contexts. Allowlist selectively to design-heavy teams.
Anthropic Claude MCP (76k views) nests Claude-within-Claude. Useful for agentic workflows, but creates context fragmentation and harder audit trails. Each nested invocation is a separate token event—spending becomes harder to track across your org without instrumentation.
Governance Take
Here's the sharp problem platform teams are missing right now: your allowlist is only as good as your audit visibility.
A developer can allowlist GitHub MCP in Cursor, but that same GitHub MCP running in Windsurf on their laptop stays invisible to your policy if you're only monitoring one IDE. Allowlist drift across Claude Code, Cursor, Windsurf, and GitHub Copilot is already happening in teams running five or more developers.
Worse: when developers chain multiple servers (OpenAI + GitHub + Claude MCP stacked), your token spend becomes a mystery. A developer runs one Claude prompt that triggers a nested Claude inference, which pulls GitHub context, which logs to your spend dashboard as three separate events—but you see it as one request. TokenShield solves this with a live ledger that shows you token flow across every server call and every IDE, giving you real visibility into where spend is actually going before you think about optimization.
The governance win this week: audit your current IDE deployments for which MCP servers are already installed and used. Compare that to your formal allowlist. That gap is your governance debt. Once you close it, you can enforce uniformly.
Govern MCP usage across your team with CuratedMCP — or scan your own stack free at https://www.curatedmcp.com/auditor.
Top comments (0)