Hi,
I am building MCP Rank, an independent trust/provenance index for MCP servers.
Baselight appears in our first MCP Rank trust-layer report:
https://mcprank.vercel.app/reports/first-50-reviewed-mcp-trust-layer
Listing:
https://mcprank.vercel.app/servers/baselight
During review, MCP Rank treated Baselight as high risk because it is a hosted data-catalog endpoint and the trust question is mostly about data provenance, auth mode, and rollout boundaries rather than local install code. This repository now gives useful public metadata for the remote MCP endpoint, but MCP Rank only uses Maintainer Verified after explicit maintainer confirmation.
If you maintain Baselight's MCP server, could you claim or correct the listing here?
https://mcprank.vercel.app/submit?claim=baselight
The useful confirmation would be:
- current source/metadata URL for the MCP server
- current hosted MCP endpoint
- supported MCP clients/transports
- OAuth/API-key behavior and recommended auth scope
- data provenance, licensing, or query-boundary cautions users should see before rollout
- anything the listing currently gets wrong
This is not meant as an accusation or vulnerability report. The goal is to make MCP server provenance and rollout notes clearer before users install servers into agent tools, repos, databases, or workspaces.
Thanks.
Hi,
I am building MCP Rank, an independent trust/provenance index for MCP servers.
Baselight appears in our first MCP Rank trust-layer report:
https://mcprank.vercel.app/reports/first-50-reviewed-mcp-trust-layer
Listing:
https://mcprank.vercel.app/servers/baselight
During review, MCP Rank treated Baselight as high risk because it is a hosted data-catalog endpoint and the trust question is mostly about data provenance, auth mode, and rollout boundaries rather than local install code. This repository now gives useful public metadata for the remote MCP endpoint, but MCP Rank only uses Maintainer Verified after explicit maintainer confirmation.
If you maintain Baselight's MCP server, could you claim or correct the listing here?
https://mcprank.vercel.app/submit?claim=baselight
The useful confirmation would be:
This is not meant as an accusation or vulnerability report. The goal is to make MCP server provenance and rollout notes clearer before users install servers into agent tools, repos, databases, or workspaces.
Thanks.