# Official vs Local-Community MCP Server Types in ADR: Key Distinctions Explained

> Understand ADR MCP server types. Explore official Uber curated servers versus community contributed options. Learn key distinctions for secure and feature-rich development.

- Repository: [Uber Open Source/ADR](https://github.com/uber/ADR)
- Tags: deep-dive
- Published: 2026-08-06

---

**Official MCP servers are curated by Uber's ADR core team with full protocol support and strict security controls, while local-community servers are contributed by users with variable feature completeness and optional security policies.**

The ADR (Automated Detection & Response) framework organizes MCP (Meta-Control-Plane) servers into two primary categories that determine trust boundaries, security posture, and production suitability. These distinctions are enforced through the **MCP servers registry** and validation logic throughout [`Detection/main_detector.py`](https://github.com/uber/ADR/blob/main/Detection/main_detector.py) and [`Detection/guardrail/base_detector.py`](https://github.com/uber/ADR/blob/main/Detection/guardrail/base_detector.py).

## How MCP Server Types Are Defined in ADR

The classification system lives in [`Detection/mcp_servers_registry.json`](https://github.com/uber/ADR/blob/main/Detection/mcp_servers_registry.json), which maps each server to its trust level, capabilities, and maintenance source. This registry is the single source of truth that downstream components consult when loading servers for detector execution.

### Official MCP Servers

**Official MCP servers** represent the production-grade tier maintained directly by Uber's ADR engineering team. According to the registry structure, these servers are marked with:

- **High-confidence metadata** indicating core team ownership
- **Full MCP protocol compliance** including persistent memory, knowledge-graph storage, and dynamic reflective reasoning
- **Mandatory security controls**: strict access-control configuration, audit logging, and vetted authentication mechanisms
- **Regular update cadence** with security patches and feature releases

The registry entry for the official secure file-system server demonstrates this structure (line 10):

```json
// Detection/mcp_servers_registry.json#L10
{
  "name": "official-secure-fs",
  "trust_level": "official",
  "description": "Official MCP server for secure file system operations with configurable access controls",
  "maintainer": "ADR Core Team",
  "security_policy": "strict"
}

```

### Local-Community MCP Servers

**Local-community MCP servers** encompass user-contributed implementations with more flexible constraints. The registry marks these with:

- **Community-driven maintenance** without guaranteed update frequency
- **Variable feature coverage** — some implement full protocols, others target specific use cases
- **Optional security policies** relying on contributor-defined defaults
- **Experimental or specialized scopes**, such as the FastMCP framework (line 767)

```json
// Detection/mcp_servers_registry.json#L767
{
  "name": "fastmcp-py",
  "trust_level": "community",
  "description": "FastMCP framework for rapid MCP prototyping",
  "maintainer": "Community",
  "security_policy": "optional"
}

```

## Trust Validation in the Guardrail System

The [`Detection/guardrail/base_detector.py`](https://github.com/uber/ADR/blob/main/Detection/guardrail/base_detector.py) file implements the runtime enforcement layer that distinguishes official vs community servers. When a detector initializes, the guardrail validates the requested server's trust level against the operation context.

```python

# Detection/guardrail/base_detector.py - trust validation excerpt

class BaseDetector:
    def _validate_mcp_server(self, server_config: dict) -> None:
        trust_level = server_config.get("trust_level")
        
        if self.production_mode and trust_level != "official":
            raise SecurityException(
                f"Production mode requires official MCP servers. "
                f"Received: {trust_level}"
            )
        
        # Community servers allowed in development/experimental contexts

        self.mcp_server = MCPRegistry.load_server(server_config)

```

This enforcement ensures **official MCP servers** are mandatory for benchmark suites and production deployments, while **community servers** remain accessible for prototyping workflows.

## Practical Usage Patterns

### Selecting an Official Server for Production

```python
from adr_detection import MCPRegistry

registry = MCPRegistry.load()
official_server = registry.get_server(
    name="official-secure-fs",
    trust_level="official"  # Enforces official tier only

)

detector = ProductionDetector(mcp_server=official_server)
detector.run_benchmark_suite()

```

### Using Community Servers for Rapid Prototyping

```python
from adr_detection import MCPRegistry

registry = MCPRegistry.load()
community_server = registry.get_server(
    name="fastmcp-py",
    trust_level="community"
)

# Experimental context bypasses production guardrails

client = MCPClient(server=community_server)
client.execute_test_query()

```

## Security and Feature Comparison

| Aspect | Official MCP Servers | Local-Community MCP Servers |
|--------|----------------------|----------------------------|
| **Source** | ADR Core Team (Uber) | Community contributors |
| **Protocol compliance** | Full specification | Variable subset |
| **Security controls** | Mandatory, audited | Optional, contributor-defined |
| **Update guarantee** | Regular, patched | Best-effort |
| **Production eligibility** | Permitted | Blocked by guardrail |
| **Documentation** | Comprehensive official docs | Community-authored, variable quality |

## Summary

- **Official MCP servers** in ADR are Uber-maintained, fully protocol-compliant, and required for production workloads with strict security validation in [`Detection/guardrail/base_detector.py`](https://github.com/uber/ADR/blob/main/Detection/guardrail/base_detector.py)
- **Local-community MCP servers** enable flexible experimentation but are restricted by trust-level checks when operating in production mode
- The [`Detection/mcp_servers_registry.json`](https://github.com/uber/ADR/blob/main/Detection/mcp_servers_registry.json) file serves as the authoritative classification source, with trust metadata consumed by both `MCPRegistry` and guardrail components
- Runtime enforcement ensures users cannot accidentally deploy community servers in benchmark or production contexts

## Frequently Asked Questions

### What happens if I try to use a community MCP server in a production ADR deployment?

The guardrail system in [`Detection/guardrail/base_detector.py`](https://github.com/uber/ADR/blob/main/Detection/guardrail/base_detector.py) raises a `SecurityException` when `production_mode=True` and a non-official trust level is detected. This prevents accidental deployment of unaudited servers in sensitive contexts while preserving community server access for development workflows.

### Can I convert a local-community server to official status?

Official status requires Uber ADR core team review, security audit, and assumption of maintenance responsibility. The registry structure does not support self-promotion; community servers remain in their classification unless explicitly adopted by the core team and updated in [`Detection/mcp_servers_registry.json`](https://github.com/uber/ADR/blob/main/Detection/mcp_servers_registry.json).

### Where does ADR store the complete list of available MCP servers?

The authoritative registry is [`Detection/mcp_servers_registry.json`](https://github.com/uber/ADR/blob/main/Detection/mcp_servers_registry.json) at the repository root. This JSON file contains all server definitions with their trust levels, descriptions, and configuration URLs. The `MCPRegistry.load()` method parses this file to provide server instances to detectors.

### Are official MCP servers always more feature-complete than community alternatives?

Official servers guarantee full protocol implementation, but community servers may implement specialized extensions not yet standardized. The FastMCP framework (line 767) exemplifies this: it offers rapid prototyping capabilities beyond the official server's scope, albeit without production support guarantees.