I looked at my terminal last week and realized my AI agent had the same access to deploy production as it did to search a README. No policy. No approvals. No audit trail. Three MCP servers wired directly in, side by side, identical trust.

The first two were fine — docs search, code search. Read-only. The third could promote builds to production. And that's when it clicked: MCP standardized how agents talk to tools, but did absolutely nothing for what happens after you connect more than a couple of them.

The official MCP servers repo has 88,900 stars and 11,300 forks. Claude, ChatGPT, VS Code, Cursor — they all speak MCP. There's a registry for browsing servers. The ecosystem is taking off, and I couldn't find a single governance tool for any of it.

What I tried first

Three paths. None of them worked.