Official vs Local-Community MCP Server Types in ADR: Key Distinctions Explained

Official MCP servers are curated by Uber's ADR core team with full protocol support and strict security controls, while local-community servers are contributed by users with variable feature completeness and optional security policies.

The ADR (Automated Detection & Response) framework organizes MCP (Meta-Control-Plane) servers into two primary categories that determine trust boundaries, security posture, and production suitability. These distinctions are enforced through the MCP servers registry and validation logic throughout Detection/main_detector.py and Detection/guardrail/base_detector.py.

How MCP Server Types Are Defined in ADR

The classification system lives in Detection/mcp_servers_registry.json, which maps each server to its trust level, capabilities, and maintenance source. This registry is the single source of truth that downstream components consult when loading servers for detector execution.

Official MCP Servers

Official MCP servers represent the production-grade tier maintained directly by Uber's ADR engineering team. According to the registry structure, these servers are marked with:

  • High-confidence metadata indicating core team ownership
  • Full MCP protocol compliance including persistent memory, knowledge-graph storage, and dynamic reflective reasoning
  • Mandatory security controls: strict access-control configuration, audit logging, and vetted authentication mechanisms
  • Regular update cadence with security patches and feature releases

The registry entry for the official secure file-system server demonstrates this structure (line 10):

// Detection/mcp_servers_registry.json#L10
{
  "name": "official-secure-fs",
  "trust_level": "official",
  "description": "Official MCP server for secure file system operations with configurable access controls",
  "maintainer": "ADR Core Team",
  "security_policy": "strict"
}

Local-Community MCP Servers

Local-community MCP servers encompass user-contributed implementations with more flexible constraints. The registry marks these with:

  • Community-driven maintenance without guaranteed update frequency
  • Variable feature coverage — some implement full protocols, others target specific use cases
  • Optional security policies relying on contributor-defined defaults
  • Experimental or specialized scopes, such as the FastMCP framework (line 767)
// Detection/mcp_servers_registry.json#L767
{
  "name": "fastmcp-py",
  "trust_level": "community",
  "description": "FastMCP framework for rapid MCP prototyping",
  "maintainer": "Community",
  "security_policy": "optional"
}

Trust Validation in the Guardrail System

The Detection/guardrail/base_detector.py file implements the runtime enforcement layer that distinguishes official vs community servers. When a detector initializes, the guardrail validates the requested server's trust level against the operation context.


# Detection/guardrail/base_detector.py - trust validation excerpt

class BaseDetector:
    def _validate_mcp_server(self, server_config: dict) -> None:
        trust_level = server_config.get("trust_level")
        
        if self.production_mode and trust_level != "official":
            raise SecurityException(
                f"Production mode requires official MCP servers. "
                f"Received: {trust_level}"
            )
        
        # Community servers allowed in development/experimental contexts

        self.mcp_server = MCPRegistry.load_server(server_config)

This enforcement ensures official MCP servers are mandatory for benchmark suites and production deployments, while community servers remain accessible for prototyping workflows.

Practical Usage Patterns

Selecting an Official Server for Production

from adr_detection import MCPRegistry

registry = MCPRegistry.load()
official_server = registry.get_server(
    name="official-secure-fs",
    trust_level="official"  # Enforces official tier only

)

detector = ProductionDetector(mcp_server=official_server)
detector.run_benchmark_suite()

Using Community Servers for Rapid Prototyping

from adr_detection import MCPRegistry

registry = MCPRegistry.load()
community_server = registry.get_server(
    name="fastmcp-py",
    trust_level="community"
)

# Experimental context bypasses production guardrails

client = MCPClient(server=community_server)
client.execute_test_query()

Security and Feature Comparison

Aspect Official MCP Servers Local-Community MCP Servers
Source ADR Core Team (Uber) Community contributors
Protocol compliance Full specification Variable subset
Security controls Mandatory, audited Optional, contributor-defined
Update guarantee Regular, patched Best-effort
Production eligibility Permitted Blocked by guardrail
Documentation Comprehensive official docs Community-authored, variable quality

Summary

  • Official MCP servers in ADR are Uber-maintained, fully protocol-compliant, and required for production workloads with strict security validation in Detection/guardrail/base_detector.py
  • Local-community MCP servers enable flexible experimentation but are restricted by trust-level checks when operating in production mode
  • The Detection/mcp_servers_registry.json file serves as the authoritative classification source, with trust metadata consumed by both MCPRegistry and guardrail components
  • Runtime enforcement ensures users cannot accidentally deploy community servers in benchmark or production contexts

Frequently Asked Questions

What happens if I try to use a community MCP server in a production ADR deployment?

The guardrail system in Detection/guardrail/base_detector.py raises a SecurityException when production_mode=True and a non-official trust level is detected. This prevents accidental deployment of unaudited servers in sensitive contexts while preserving community server access for development workflows.

Can I convert a local-community server to official status?

Official status requires Uber ADR core team review, security audit, and assumption of maintenance responsibility. The registry structure does not support self-promotion; community servers remain in their classification unless explicitly adopted by the core team and updated in Detection/mcp_servers_registry.json.

Where does ADR store the complete list of available MCP servers?

The authoritative registry is Detection/mcp_servers_registry.json at the repository root. This JSON file contains all server definitions with their trust levels, descriptions, and configuration URLs. The MCPRegistry.load() method parses this file to provide server instances to detectors.

Are official MCP servers always more feature-complete than community alternatives?

Official servers guarantee full protocol implementation, but community servers may implement specialized extensions not yet standardized. The FastMCP framework (line 767) exemplifies this: it offers rapid prototyping capabilities beyond the official server's scope, albeit without production support guarantees.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →