1. Source check
We record the original repository, documentation, or publisher page and prefer first-party sources. Community sources are labeled separately.
Our methodology
We separate source evidence, metadata quality, installation checks, and editorial recommendations. This prevents one positive signal from being mistaken for a complete safety review.
We record the original repository, documentation, or publisher page and prefer first-party sources. Community sources are labeled separately.
We check the resource name, category, description, license, supported platforms, installation path, and update information. Missing information stays visible.
For tools such as MCP servers, we identify filesystem access, network access, secrets, external writes, and other meaningful permissions.
A resource is not marked Verified until the required installation and configuration checks have been performed by a human reviewer.
We add practical guidance: who the resource fits, where it may fail, what to watch for, and which alternatives are worth considering.
Source checks, metadata updates, and installation tests have separate timestamps so outdated verification does not look current.
Official source means the link points to a first-party source. Source checked means the source and basic metadata were reviewed. Install test needed means it has not yet completed our human installation check. Verified is reserved for resources that passed the required review scope.