Mmcp.market

mcpm MCP server

by getmcpm·io.github.getmcpm/cli·v0.42.0

MCP security guard + package manager: trust-scored installs, blocks prompt injection and rug-pulls.

B83/100grade B
What users say
No reviews yet
Be the first
Safety scan
B83/100

not scanned yet

Adoption
Growing

3 stars529 downloads/wk

Reviews

Write one

Nobody has reviewed mcpm yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

mcpm tools

No tool declarations could be read from the package source. They show once the server is installed.

Not scanned yet. New registry listings are scanned within a day of import.

Install directly

Runs npx -y @getmcpm/cli on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add cli -- npx -y @getmcpm/cli
Add to Cursor

mcpm: common questions

Is mcpm MCP server safe?
Mostly: it is graded B (83/100). Read the mcpm safety report
How do I install mcpm?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does mcpm need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is mcpm maintained?
The last commit was in the last day (2026-09-19). The latest release is v0.42.0.
What can I use instead of mcpm?
Servers from other publishers that do the same job: prompt-protection MCP server, Aletheia Runtime Safety & Scope Creep Filter MCP server and HOL Guard MCP server. Compare all mcpm alternatives.

Alternatives to mcpm

Same job from other publishers: the closest match first, then the best rated.

All mcpm alternatives →
  • prompt-protection
    Scan prompts, tool definitions and model output for injection, and guard agent tool calls.
    A
  • Aletheia Runtime Safety & Scope Creep Filter
    Deterministic pre-execution filter that blocks known scope-creep and prompt-injection tool calls
    B
  • HOL Guard
    Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.
    C
  • lurq
    Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
    A
  • Pkgtruth
    Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.
    A

More from getmcpm