What goes wrong without source management
- Different users pull extensions from different places with different trust assumptions.
- Support has no clear source of truth for what should be installed.
- Providers, plugins, and MCP endpoints drift into separate unofficial workflows.
- Team policy becomes hard to explain and harder to enforce.