Official vs Local-Community MCP Server Types in ADR: Key Distinctions Explained
Official MCP servers are curated by Uber's ADR core team with full protocol support and strict security controls, while local-community servers are contributed by users with variable feature completeness and optional security policies.
The ADR (Automated Detection & Response) framework organizes MCP (Meta-Control-Plane) servers into two primary categories that determine trust boundaries, security posture, and production suitability. These distinctions are enforced through the MCP servers registry and validation logic throughout Detection/main_detector.py and Detection/guardrail/base_detector.py.
How MCP Server Types Are Defined in ADR
The classification system lives in Detection/mcp_servers_registry.json, which maps each server to its trust level, capabilities, and maintenance source. This registry is the single source of truth that downstream components consult when loading servers for detector execution.
Official MCP Servers
Official MCP servers represent the production-grade tier maintained directly by Uber's ADR engineering team. According to the registry structure, these servers are marked with:
- High-confidence metadata indicating core team ownership
- Full MCP protocol compliance including persistent memory, knowledge-graph storage, and dynamic reflective reasoning
- Mandatory security controls: strict access-control configuration, audit logging, and vetted authentication mechanisms
- Regular update cadence with security patches and feature releases
The registry entry for the official secure file-system server demonstrates this structure (line 10):
// Detection/mcp_servers_registry.json#L10
{
"name": "official-secure-fs",
"trust_level": "official",
"description": "Official MCP server for secure file system operations with configurable access controls",
"maintainer": "ADR Core Team",
"security_policy": "strict"
}
Local-Community MCP Servers
Local-community MCP servers encompass user-contributed implementations with more flexible constraints. The registry marks these with:
- Community-driven maintenance without guaranteed update frequency
- Variable feature coverage — some implement full protocols, others target specific use cases
- Optional security policies relying on contributor-defined defaults
- Experimental or specialized scopes, such as the FastMCP framework (line 767)
// Detection/mcp_servers_registry.json#L767
{
"name": "fastmcp-py",
"trust_level": "community",
"description": "FastMCP framework for rapid MCP prototyping",
"maintainer": "Community",
"security_policy": "optional"
}
Trust Validation in the Guardrail System
The Detection/guardrail/base_detector.py file implements the runtime enforcement layer that distinguishes official vs community servers. When a detector initializes, the guardrail validates the requested server's trust level against the operation context.
# Detection/guardrail/base_detector.py - trust validation excerpt
class BaseDetector:
def _validate_mcp_server(self, server_config: dict) -> None:
trust_level = server_config.get("trust_level")
if self.production_mode and trust_level != "official":
raise SecurityException(
f"Production mode requires official MCP servers. "
f"Received: {trust_level}"
)
# Community servers allowed in development/experimental contexts
self.mcp_server = MCPRegistry.load_server(server_config)
This enforcement ensures official MCP servers are mandatory for benchmark suites and production deployments, while community servers remain accessible for prototyping workflows.
Practical Usage Patterns
Selecting an Official Server for Production
from adr_detection import MCPRegistry
registry = MCPRegistry.load()
official_server = registry.get_server(
name="official-secure-fs",
trust_level="official" # Enforces official tier only
)
detector = ProductionDetector(mcp_server=official_server)
detector.run_benchmark_suite()
Using Community Servers for Rapid Prototyping
from adr_detection import MCPRegistry
registry = MCPRegistry.load()
community_server = registry.get_server(
name="fastmcp-py",
trust_level="community"
)
# Experimental context bypasses production guardrails
client = MCPClient(server=community_server)
client.execute_test_query()
Security and Feature Comparison
| Aspect | Official MCP Servers | Local-Community MCP Servers |
|---|---|---|
| Source | ADR Core Team (Uber) | Community contributors |
| Protocol compliance | Full specification | Variable subset |
| Security controls | Mandatory, audited | Optional, contributor-defined |
| Update guarantee | Regular, patched | Best-effort |
| Production eligibility | Permitted | Blocked by guardrail |
| Documentation | Comprehensive official docs | Community-authored, variable quality |
Summary
- Official MCP servers in ADR are Uber-maintained, fully protocol-compliant, and required for production workloads with strict security validation in
Detection/guardrail/base_detector.py - Local-community MCP servers enable flexible experimentation but are restricted by trust-level checks when operating in production mode
- The
Detection/mcp_servers_registry.jsonfile serves as the authoritative classification source, with trust metadata consumed by bothMCPRegistryand guardrail components - Runtime enforcement ensures users cannot accidentally deploy community servers in benchmark or production contexts
Frequently Asked Questions
What happens if I try to use a community MCP server in a production ADR deployment?
The guardrail system in Detection/guardrail/base_detector.py raises a SecurityException when production_mode=True and a non-official trust level is detected. This prevents accidental deployment of unaudited servers in sensitive contexts while preserving community server access for development workflows.
Can I convert a local-community server to official status?
Official status requires Uber ADR core team review, security audit, and assumption of maintenance responsibility. The registry structure does not support self-promotion; community servers remain in their classification unless explicitly adopted by the core team and updated in Detection/mcp_servers_registry.json.
Where does ADR store the complete list of available MCP servers?
The authoritative registry is Detection/mcp_servers_registry.json at the repository root. This JSON file contains all server definitions with their trust levels, descriptions, and configuration URLs. The MCPRegistry.load() method parses this file to provide server instances to detectors.
Are official MCP servers always more feature-complete than community alternatives?
Official servers guarantee full protocol implementation, but community servers may implement specialized extensions not yet standardized. The FastMCP framework (line 767) exemplifies this: it offers rapid prototyping capabilities beyond the official server's scope, albeit without production support guarantees.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →