Editorial methodology
Evidence before availability.
Plugins and Connectors is an independent, third-party directory. We are not affiliated with or endorsed by OpenAI, Anthropic, Google, xAI or the providers listed. Our job is to make changing catalogue evidence and connection risk easier to evaluate without pretending the catalogue is static.
Methodology version 1.5 · Last updated 8 September 2026What counts as a verified listing
A listing enters ordinary directory results when it appears in an official first-party Plugin Directory or connector catalogue, or when current first-party platform documentation names it. We prefer live platform catalogues, platform documentation, platform help centres and the provider’s official product or security pages.
We do not treat a vendor’s MCP server, a third-party tutorial, an old press release or technical possibility as proof of a current catalogue listing.
Our security boundary: official catalogues only, permanently
This is a policy, not just a sourcing convenience. We only ever list a connector, plugin or workflow as available when a platform has put its own name behind it in an official catalogue. We do not list, rank or recommend self-hosted, custom or community MCP servers—no matter how well-documented, popular or technically impressive one is. If a tool shows “not found in checked sources” for a platform, that is not an invitation to go find an unofficial route to it. We simply don’t have evidence of a first-party listing, and we stop there.
The reason is specific, not general caution. An MCP server is, functionally, code that a connected AI model trusts and reads instructions from. A malicious or compromised one can hide instructions inside its own tool descriptions or returned data—invisible to the person using it—and steer the model into leaking data or taking actions the user never approved. Security researchers now track this as one of the fastest-growing categories of AI vulnerability, and 2026 has already produced real incidents: agents hijacked through instructions hidden in ordinary-looking GitHub pull request titles, and well over 100,000 exposed MCP instances found scanning the open internet. This is not just a vendor-blog concern—on 1 May 2026, CISA, the NSA and allied agencies from Australia, Canada and New Zealand issued a joint advisory naming agentic AI and MCP specifically as an emerging attack surface, and independent scans have since found that only a small fraction of public MCP servers use OAuth at all. An official platform catalogue is not a guarantee against this, but it means a company with its name and OAuth infrastructure on the line reviewed the listing before it appeared—a materially different trust position from an anonymous GitHub repository.
To be fair to the protocol itself: MCP’s own specification shipped a significant update on 28 July 2026 that hardens exactly this—issuer validation, issuer-bound client credentials and a formal path for enterprise-managed authorization. The mechanism is maturing. Our policy doesn’t change with it, because a hardened protocol still doesn’t tell us whether a given self-hosted server actually implements the hardening—only a platform’s own catalogue listing does that.
The community connector enumerations we cite alongside official docs (labelled “awesome-x-connectors” in our source links) are used only to help confirm what a platform’s own catalogue already contains. We never treat them as an installation recommendation in their own right, and we never will.
NSA — Model Context Protocol: Security Design Considerations (2026) ↗Model Context Protocol — The 2026-07-28 Specification ↗Checkmarx — MCP security risks, real incidents & controls (2026) ↗Aptible — Prompt injection in MCP: tool poisoning and blast radius ↗
What the badges mean
- Verified
- We confirmed that the tool or service is named in an official platform catalogue or current first-party platform documentation. This verifies the listing evidence—not suitability, endorsement or guaranteed access for every user.
- Not found in checked sources
- We did not find a current first-party listing for that platform. It is excluded from that platform’s directory filter, but we do not claim that it is technically incompatible or unavailable through every route.
Plan, workspace, role, region, supported surface, included apps and source-system permissions can still affect whether a verified listing can be installed or used. Those are availability facts shown separately, not reasons to downgrade the evidence badge.
How we describe capabilities
Read, search, sync, draft, write, send and interactive labels are summaries, not promises. The platform directory, workspace policy, provider account, OAuth grant and source permissions determine what a connection can actually do.
Where the source does not publish a stable price or permission scope, we say it is not independently confirmed and direct readers to the live provider or platform screen. We do not invent a price, scope or plan requirement.
Review rhythm and corrections
Every listing carries a last-checked date. We review platform-wide terminology and catalogue sources when a platform announces a material change, and prioritise popular or high-risk listings for more frequent checks. A checked date is evidence of a review, not a guarantee that nothing changed later.
If a source is removed, contradicts the listing or no longer confirms it, we mark the platform as not found in checked sources or remove the listing from ordinary results. Corrections should favour clear evidence over continuity.
Commercial independence
Rankings are not for sale, and this never changes: a sponsored listing or an affiliate link is held to the same evidence and verification standard as every other entry, and is always labelled on the card and detail page where it applies. As of this update, every listing’s sponsored and affiliate flags are still off—we have not activated a paid placement or an affiliate relationship with any provider. If that changes, the label appears next to the specific recommendation, not as a blanket disclaimer.
Reader support (a small, optional link to help cover hosting, domain and email costs) is shown in the footer and on guide pages. It funds the site; it does not buy or influence a listing, a badge or a comparison.
Business consultations are separate from catalogue placement. A provider cannot buy a verified badge or a favourable comparison.
Workflows: a different kind of evidence
A connector gives a platform access to a tool. A workflow is a finished, packaged job built on top of one or more connectors—a ready-made cash flow forecast, an invoice chaser, a weekly brief. Because these are assembled and shipped by very different kinds of publishers, we grade each platform's entry by provenance rather than treating every listing as equivalent:
- Official bundle
- The platform itself ships and maintains the workflow directly (for example, Anthropic's own
knowledge-work-pluginsrepository). We treat this the same as a first-party connector listing. - Open marketplace
- Independent builders publish and price their own versions; the platform provides the storefront, not the curation. More choice, less built-in vetting—we say so plainly rather than reviewing every individual listing.
- Mechanism only, not yet
- The underlying feature exists (a way to build and invoke a custom skill or workflow) but no vertical bundle for the job in question has surfaced in the sources we checked. This is a snapshot, not a permanent verdict—platforms ship new bundles often.
None of these labels is a value judgement on the platform as a whole—an open marketplace is a legitimate, different choice, not a lesser one. Browse the workflows we've reviewed →