# Data notice

This research package describes publicly announced and inspectable MCP service surfaces at specific points in time. Inclusion does not imply endorsement, verification, conformance, maintenance, safety, or adoption.

## Provenance

Every observation must point to a capture record containing its source, retrieval time, and content hash. Publisher statements, directory-assigned metadata, source inspection, protocol enumeration, and researcher inference remain distinguishable.

A service can change after collection. The corpus reports only the captured version, configuration, authorization state, and evidence channel. Display names and URLs are not stable identity by themselves.

## Rights and redistribution

Public availability does not place source material in the public domain. Each capture records any stated license and redistribution restriction that could be found.

The public research release should prefer:

- factual metadata and researcher-authored descriptions;
- source URLs, timestamps, and content hashes;
- brief, necessary excerpts with attribution;
- publisher-provided schemas only when their license or applicable permission permits redistribution;
- generated measurements that do not reconstruct protected source text.

Full pages, documentation, repository contents, and directory responses are retained only where collection and redistribution are authorized. When raw material cannot be published, the release keeps a rights-safe manifest entry and hash so the analytical claim remains traceable to the extent permitted. `rights_withheld` is missingness, not evidence of absence.

This notice is a research-handling policy, not a legal determination about any particular source.

## Secrets and personal data

Do not collect or commit:

- access tokens, cookies, authorization headers, session identifiers, or private endpoints;
- credentials found in examples, logs, configuration files, or query strings;
- user records or tool results from a real account;
- private repository or package contents without authorization;
- analytics identifiers or personal data unnecessary to identify the publisher or evidence source.

Collectors must redact secrets before persistence and record that a redaction occurred without retaining the value. A suspected secret stops publication of the affected capture pending review.

Named maintainers and organizational contacts may be recorded only when already published for the service and necessary for provenance. Avoid reproducing unrelated profile information.

## Safe observation

Default collection is read-only inspection of listings, published technical material, protocol initialization, and list operations. It does not invoke arbitrary service tools or test announced behavior against production systems.

Do not create, update, delete, communicate, transact, schedule, execute code, control devices, change permissions, or incur cost for this corpus. Do not bypass authentication, rate limits, access controls, or source terms. A separate approved behavioral protocol is required before any such operation.

## Announced language

An announced claim records who supplied the words:

- `directory` for directory-authored or directory-assigned labels;
- `publisher` for listing text or documentation supplied by the service publisher;
- another explicit source role when neither applies.

Do not silently rewrite a claim as an observed capability. Normalized terms are researcher coding and retain links to the original claim and codebook version.

## Corrections and removal

Source owners and readers should be able to report a mistaken identity, stale source, rights concern, secret, or analytical error through the repository's public issue channel.

A correction creates a new, traceable record or release. Do not rewrite an old snapshot without an erratum. Material that exposes a secret, personal data, or content that should not be redistributed may be removed from the public package promptly; its manifest records only the minimum safe tombstone needed to explain the gap.

## Interpretation limits

The primary cohort is `smithery-use-300-2026-08-02` and is purposive. It is selected by capturing the complete 7,601-row Smithery registry snapshot, then sorting locally by `useCount` descending and `qualifiedName` ascending. Counts describe the resulting 300 listings. They do not estimate ecosystem prevalence, installs, active users, quality, or adoption.

Duplicate and family-equivalent listings remain in the cohort. Primary results count listings; a separately reported family-weighted sensitivity limits each adjudicated equivalence family to one total unit. Family links are researcher judgments with cited evidence, not source facts.

The legacy 30-entry PulseMCP material is reported only as a sensitivity tranche. Official Registry, Glama, and publisher material are provenance-labeled enrichment subject to their access policies; they do not alter primary-cohort membership.

An exposed member shows that an interface was presented; it does not verify implementation behavior. A publisher claim shows what was announced; it does not prove that the captured surface supports it. Missing evidence remains missing unless the protocol supports a narrower negative observation.

The frame observes MCP servers published to a directory. Capabilities delivered as host-native features or browser extensions are not observable through it. A low or zero count for such a shape describes the frame, not the ecosystem, and is not evidence of absence.
