We're keeping an unofficial allow list at work. Basically just major software companies only. Third party mcp servers at this point are basically just attack vectors. How do you even vet them continuously?
Honestly vetting MCP seems like a YC company in and of itself.