MCPMateBLOCK
MCPMate is a progressive MCP management center for organizing servers, clients, profiles, capabilities, and runtime visibility in one local workspace.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文 | 日本語
Your progressive MCP management partner.
Import MCP once. Start simple, then add profiles, per-client tools, and setup modes as your workflow grows. MCPMate is a local-first assistant that grows with you—not just another config file editor.
MCPMate sits between your AI apps and MCP servers so you manage connections once and send the right tools to each app. It works with Claude Desktop, Cursor, Codex, Zed, VS Code, CLI tools, and other clients that follow the standard MCP config format.
Easy to begin, built to scale: one import with low friction; the same setup still fits as MCP spreads across more clients, servers, and scenarios—no product swap, no restart ritual.
8593e67b44e1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcpmate -- docker run -i --rm ghcr.io/loocor/mcpmate:0.1.0
Exposed tools (9)
9 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Default | read | Primary operator profile |
Name | read | Description |
Research | read | Focused research tools |
sequentialthinking | read | Think through a problem step by step. |
server_a__analyze | read | Analyze a payload |
server_a__lookup | read | Look up a record by identifier. |
weather | read | Old description |
名前 | read | 説明 |
名称 | read | 描述 |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (23)
server-import-payload.ts
icon.icns
"MCPMate": {"url": "http://127.0.0.1:8000/mcp"},r#"{"mcpServers":{"MCPMate":{"url":"http://127.0.0.1:8000/mcp"}}}"#,"{}: {} acquisitions, avg_wait={}μs, avg_hold={}μs, slow={}%, max_wait={}μs, max_hold={}μs",client-tools.webm
configure.webm
scenarios.webm
setup-modes.webm
server-import-payload.test.ts
const BUNDLED_PROJECTION_CONFIG: &str = include_str!("../../../config/projection.json5");const BUNDLED_UCAN_PROMPT_CONFIG: &str = include_str!("../../../config/ucan.json5");header.set_link_name("../../outside").expect("set link path");import { cn } from "../../lib/utils";import { cn } from "../../lib/utils";--cli 'http://127.0.0.1:8000/mcp?client_id=inspector' \
- Use Inspector to discover offerings. In proxy-inheriting terminals, run `env -u HTTPS_PROXY -u HTTP_PROXY -u ALL_PROXY -u https_proxy -u http_proxy -u all_proxy npx @modelcontextprotocol/inspector -
--cli 'http://127.0.0.1:8000/mcp?client_id=inspector' \
const binary = atob(normalized);
const cursorConfig = JSON.parse(atob(configB64));
const cursorConfig = JSON.parse(atob(configB64));
@hookform/resolvers, @radix-ui/react-accordion, @radix-ui/react-alert-dialog, @radix-ui/react-avatar, @radix-ui/react-dialog, @radix-ui/react-dropdown-menu, @radix-ui/react-label, @radix-ui/react-popo
@formspree/react, lucide-react, react, react-dom, react-ga4, react-router-dom, @eslint/js, @types/node
Gates applied: no_behavioural_pass.
8593e67b44e1full audit observations/trust-audit/mcp-server/loocor__mcpmate-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 8593e67b44e1 | BLOCK | D | 69 | first audit |
Questions
What is the MCPMate MCP server?
MCPMate is a progressive MCP management center for organizing servers, clients, profiles, capabilities, and runtime visibility in one local workspace.
What tools does MCPMate expose?
9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MCPMate safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does MCPMate need?
No credential environment variables were found in its source, so it appears to need none.
How does MCPMate run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as vite-react-typescript-starter at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (8593e67b44e1), read on 2026-10-08. The repository is watched and re-audited when it changes.