mcpm — security grade SAFE, quality 76/100

Security audit verdict: SAFE · quality 76/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by MCP-Club · MCP Server · ★ 106

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcpm safe to install? View the security audit →

About mcpm

MCPM CLI A command-line tool for managing MCP servers in Claude App. Highlights 🚀 Easy Server Management: Add, remove, and manage multiple MCP servers in Claude App with simple commands 🔄 Server Status Control: Enable/disable servers and view their status at any time 🛠️ Interactive CLI: User-friendly command-line interface with interactive prompts for easy configuration 🔌 Self-Integration: Can add MCPM CLI itself as a MCP server with a single command 📝 JSON Configuration: Manages servers through Claude's configuration file with proper error handling 🔍 Package Discovery: Search and discover MCP packages from the community RoadMap -

claudeclimcpmodel-context-protocol

Quick Facts

Stars106
Forks28
LanguageTypeScript
CategoryMCP Server
LicenseAGPL-3.0
Quality Score75.6759184996073/100
Open Issues3
Last Updated2025-01-06
Created2024-12-17
Platformsclaude-code, cli, mcp, node
Est. Tokens~90k

Compatible Skills

These tools work well together with mcpm for enhanced workflows:

  • nof1-tracker — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (52%)
  • qwen_cli_coder — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (51%)
  • linearis — semantic(0.16)+complementary+same_lang+similar_pop+shared_platform (50%)
  • fuxi-cli — semantic(0.15)+complementary+same_lang+similar_pop+shared_platform (50%)
  • mcp-manager — semantic(0.49)+same_lang+similar_pop+shared_platform (47%)

mcpm alternative? Top 6 similar tools

Looking for a mcpm alternative? If you're comparing mcpm with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcp-cli by apify · ⭐ 459

    mcpc is a CLI client for MCP. It supports persistent sessions, stdio/HTTP, OAuth 2.1, JSON output for code mod

  • ClaudeR by IMNMV · ⭐ 337

    Connect RStudio to Claude Code, Codex, Gemini, and other LLM agents via MCP. Multi-agent orchestration, automa

  • UnityMCP by isuzu-shiranui · ⭐ 314

    Drive the Unity Editor from an AI agent or the terminal. The Editor serves MCP itself over HTTP, so there is n

  • mcp-server-atlassian-bitbucket by aashari · ⭐ 160

    Node.js/TypeScript MCP server for Atlassian Bitbucket. Enables AI systems (LLMs) to interact with workspaces,

  • roam-code by Cranot · ⭐ 518

    Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 comman

  • agnix by agent-sh · ⭐ 422

    The missing linter and lsp for AI coding assistants. Validate CLAUDE.md, AGENTS.md, SKILL.md, hooks, MCP. Plug

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is mcpm?

mcpm is A command-line tool for managing MCP servers in Claude App. Also can run a MCP Server to help you manage all your MCP Servers. It is categorized as a MCP Server with 106 GitHub stars.

What programming language is mcpm written in?

mcpm is primarily written in TypeScript. It covers topics such as claude, cli, mcp.

How do I install or use mcpm?

You can find installation instructions and usage details in the mcpm GitHub repository at github.com/MCP-Club/mcpm. The project has 106 stars and 28 forks, indicating an active community.

What license does mcpm use?

mcpm is released under the AGPL-3.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to mcpm?

The top alternatives to mcpm on Agent Skills Hub include mcp-cli, ClaudeR, UnityMCP. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools