See e.g. PR #336 - when a contributor added an MCP server, understandably from a fork, our CI was failing. We should figure out why, and if the fix is ok from security perspective (e.g. avoid pull_request_target), fix this, alternatively document or throw a nicer error.