Right now trusted MCP tool detection is regex-driven and intentionally conservative. It would be useful to make this easier to tune for common environments.\n\nSuggested scope:\n- define a few preset bundles in docs or config examples\n- separate 'authoritative data' MCPs from 'workflow convenience' MCPs\n- document the tradeoff between broader trust patterns and false verification signals\n\nThis issue is a good fit for contributors who care about practical deployment hygiene.
Right now trusted MCP tool detection is regex-driven and intentionally conservative. It would be useful to make this easier to tune for common environments.\n\nSuggested scope:\n- define a few preset bundles in docs or config examples\n- separate 'authoritative data' MCPs from 'workflow convenience' MCPs\n- document the tradeoff between broader trust patterns and false verification signals\n\nThis issue is a good fit for contributors who care about practical deployment hygiene.