mcpx — security grade SAFE, quality 59/100

Security audit verdict: SAFE · quality 59/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by opentokenz · MCP Server · ★ 416

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcpx safe to install? View the security audit →

About mcpx

MCPX 连接 AI 与本地开发环境的 MCP Runtime。 MCPX 是运行在开发环境中的 MCP Runtime(网关)。ChatGPT、Claude、Cursor、Grok 及其他支持 Streamable HTTP 的 MCP 客户端,可以通过统一工具面理解项目、查看 Unified Diff、修改源码、运行任务、采集环境信息,并调用本地 MCP 与 Skill。 开发状态保存在 SQLite Remote Session 中,不依赖某个 AI 厂商或单次 。不同客户端可以查询、授权接力并继续同一项开发工作。 文档语言: 中文(默认) · 点击阅读英文版 它能做什么 扫描 / ,可执行或返回文档

Quick Facts

Stars416
Forks83
LanguageGo
CategoryMCP Server
LicenseApache-2.0
Quality Score59.1343336836338/100
Last Updated2026-09-17
Created2026-07-30
Platformsclaude-code, go, mcp
Est. Tokens~21k

Compatible Skills

These tools work well together with mcpx for enhanced workflows:

  • peoples-post-generator — semantic(0.19)+complementary+similar_pop+shared_platform (47%)
  • chatgpt-share-web — semantic(0.18)+complementary+similar_pop+shared_platform (46%)
  • trpc-mcp-go — semantic(0.32)+same_lang+similar_pop+shared_platform (46%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is mcpx?

mcpx is MCPX 是运行在开发环境中的 MCP Runtime(网关)。ChatGPT、Claude、Cursor、Grok 及其他支持 Streamable HTTP 的 MCP 客户端,可以通过统一工具面理解项目、查看 Unified Diff、修改源码、运行任务、采集环境信息,并调用本地 MCP 与 Skill。. It is categorized as a MCP Server with 416 GitHub stars.

What programming language is mcpx written in?

mcpx is primarily written in Go.

How do I install or use mcpx?

You can find installation instructions and usage details in the mcpx GitHub repository at github.com/opentokenz/mcpx. The project has 416 stars and 83 forks, indicating an active community.

What license does mcpx use?

mcpx is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools