Both big AI platforms check an MCP server the same way before listing it: they verify the domain, read the self-declared annotations ( readOnlyHint , destructiveHint ), and scan the policy text. Then they contain the tool at runtime. Nobody checks whether the tool behaves the way it declares.
Source: [Dev.to](https://dev.to/agentavow/we-started-running-every-mcp-server-we-grade-heres-what-20-popular-ones-actually-did-53ik)