Read what an MCP server does **before** you connect to it. Connecting an MCP server hands it a channel into your agent's context and its tool calls. SRI reads the server's published source and reports what it found — every observation anchored to a `file:line` with the code quoted verbatim. **It does not tell you whether a server is safe.** It tells you what the code