There's a good checklist going around dev.to for vetting an MCP server before you wire it into an agent. Four things to look at. Tool surface area: how many tools, and are they atomic or coarse. Auth model: API key, OAuth, token scope. Maintenance: last commit, open issues, is anyone home. Token profile: does it dump a full document when a summary would do.
It's a genuinely good checklist. I've used a version of it. For most tooling categories it's exactly the right lens.
Then you point an agent at something that moves money, and three of those four rows go quiet.
Not because they stop mattering. Because one of them grows until it's the only thing you're really deciding.
A read tool and a write tool are not the same animal






