Mcp-getBLOCK
Archived: mcp-get is no longer maintained.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This repository is no longer actively maintained.
We want to extend our heartfelt thanks to everyone who contributed to mcp-get, submitted packages, reported issues, and helped build this community. Your contributions and support have been invaluable in advancing the Model Context Protocol ecosystem.
🎯 Recommendation
We recommend [Smithery](https://smithery.ai) for discovering, installing, and managing MCP servers.
Smithery provides:
- A comprehensive, curated registry of MCP servers
- Simple installation and management
- Better discovery and documentation
- Active maintenance and support
Visit [smithery.ai](https://smithery.ai) to get started.
Note: This tool will continue to work, but will no longer receive updates or new features.
mcp-get (Archived)
A powerful command-line tool for discovering, installing, and managing Model Context Protocol (MCP) servers. This tool simplifies the process of connecting Large Language Models (LLMs) to external data sources, tools, and services.
With mcp-get, you can:
- Discover available MCP servers from our curated registry
- Install servers with a single command
- Manage environment variables and configurations
- Update and uninstall servers as needed
Quick Start
Try mcp-get immediately:
npx @michaellatman/mcp-get@latest list npx @michaellatman/mcp-get@latest install @modelcontextprotocol/server-brave-search
All packages added to the registry are automatically displayed on mcp-get.com, making them discoverable to other users.
About Model Context Protocol
The Model Context Protocol (MCP) is an open protocol that enables seamless integration between LLM applications and external data sources and tools. Whether you're building an AI-powered IDE, enhancing a chat interface, or creating custom AI workflows, MCP provides a standardized way to connect LLMs with the context they need.
Learn more about MCP at [mode
ff3dd34e6b8fOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-get -- npx -y @michaellatman/[email protected]
{
"mcpServers": {
"mcp-get": {
"command": "npx",
"args": [
"-y",
"@michaellatman/[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
test-package | read | A test package |
test-python-pkg | read | Test python package |
Trust audit
BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
const { stdout } = await exec(`npm view ${packageName} --json`);const { stdout: repoDataStr } = await exec(`gh api repos/${owner}/${repo}`);const { stdout: packageJsonData } = await exec(`gh api repos/${owner}/${repo}/contents/package.json --raw`);const { stdout: pyprojectData } = await exec(`gh api repos/${owner}/${repo}/contents/pyproject.toml --raw`);const { stdout: readmeData } = await exec(`gh api repos/${owner}/${repo}/contents/README.md --raw`);const tempDir = path.join(__dirname, '../../temp');
const packagesDir = path.join(__dirname, '../../packages');
const commitMsgPath = path.join(__dirname, '../../temp/commit-msg.txt');
const ROOT_DIR = path.join(__dirname, '../../');
const ROOT_DIR = path.join(__dirname, '../../');
@iarna/toml, @octokit/rest, @types/iarna__toml, chalk, cli-table3, dotenv, fuzzy, inquirer
Gates applied: no_behavioural_pass.
ff3dd34e6b8ffull audit observations/trust-audit/mcp-server/michaellatman__mcp-get.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | ff3dd34e6b8f | BLOCK | D | 63 | first audit |
Questions
What is the Mcp-get MCP server?
Archived: mcp-get is no longer maintained.
What tools does Mcp-get expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcp-get safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (63/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Mcp-get need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (ff3dd34e6b8f), read on 2026-09-30. The repository is watched and re-audited when it changes.