No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by spences10 · MCP Server · ★ 94
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcpick safe to install? View the security audit →
McPick Claude Code extension manager — MCP servers, plugins (skills, hooks, agents), and marketplaces. Quick Start Use mcpick inline in Claude Code sessions. Tell Claude: McPick auto-detects non-TTY environments and shows structured help instead of launching the interactive TUI — so LLM agents can read and figure out the rest. Concepts Marketplaces contain plugins. Plugins contain skills (), hooks, agents, and MCP servers. Common Workflows Install skills from a marketplace Marketplace sources can be: — GitHub shorthand — full URL — local directory Toggle MCP serve
| Stars | 94 |
| Forks | 15 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 73.2086563412559/100 |
| Open Issues | 11 |
| Last Updated | 2026-10-01 |
| Created | 2025-09-28 |
| Platforms | claude-code, cli, mcp, node |
| Est. Tokens | ~15k |
Looking for a mcpick alternative? If you're comparing mcpick with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
The Ultimate Claude Code Toolkit: 180 skills, 10 agents, 29 commands, 7 hooks, and 81 marketplace repos (11,00
Claude Code Skills Marketplace: plugins, skills for ADR-driven development, DevOps automation, ClickHouse mana
Open source AI coding platform with Web IDE, multi-agent system, 37+ tools, MCP protocol. MIT licensed.
A curated list of awesome claude marketplaces and plugins
The missing linter and lsp for AI coding assistants. Validate CLAUDE.md, AGENTS.md, SKILL.md, hooks, MCP. Plug
Dashboard for monitoring claude code sessions.
Explore other popular mcp server tools:
mcpick is Vendor-neutral MCP configuration manager — one CLI to add, toggle, and audit MCP servers and skills across every AI client, with safety built in. It is categorized as a MCP Server with 94 GitHub stars.
mcpick is primarily written in TypeScript. It covers topics such as anthropic, claude, claude-code.
You can find installation instructions and usage details in the mcpick GitHub repository at github.com/spences10/mcpick. The project has 94 stars and 15 forks, indicating an active community.
mcpick is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to mcpick on Agent Skills Hub include .claude, cc-skills, claude-code-open. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: