Atlas / MCP servers / milisp / Store

StoreBLOCK

mcp/milisp/store

MCP store. Discover, add & syncs configuration manager across clients like Claude code, Codex, Cursor💡mcphub

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
19 16r · 3w · 0d
Transport
streamable-http
License
AGPL-3.0
Stars
337
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/milisp/mcp-linker/stargazers) [](https://milisp.github.io/modern-github-release/#/repo/milisp/mcp-linker) [](#) [](CONTRIBUTING.md)

🌐 Languages: 中文 | 🌍 Other Languages

One-click add and sync MCP servers across AI clients — No LLM calls needed, Built-in marketplace

[!TIP] ⭐ Star the repo and follow milisp on Twitter and GitHub for more!

🚀 Why MCP Linker?

  • ⚡ Instant — Add MCP servers in seconds
  • 🧠 Multi-Client Support — Works with all major AI clients

✨ Features

  • Local Sync — Sync MCP server configs across multiple clients
  • Official MCP Registry — Browse and install servers straight from registry.modelcontextprotocol.io
  • Multi-Client Support — Claude Desktop/Code, Cursor, VS Code, Cline, Windsurf, Codex, Roo Code. see Detail
  • Cross-Platform — macOS, Windows, Linux
  • Smart Detection — Auto-detect Python, Node.js, uv environments
  • GUI for OpenAI Codex CLI — based on Codexia

🚀 Quick Start

Installation

macOS (Homebrew)

brew install mcplinker

Arch Linux (AUR)

yay -S mcp-linker-bin

Windows / Linux / macOS (Direct Download) Download the: 📥latest Releases

[!Note] If you have subscribed, please relaunch the app after logging in for the first time.

Getting Started

  1. Browse MCP servers in the built-in marketplace
  2. Click "Get" to show configuration
Read from source at commit 0c750ea6ad21OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-linker -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-linker": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (19)

16 read · 3 write · 0 destructive.

ToolRiskDescription
airtablewriteRead/write records, manage bases and tables
asanareadInteract with your Asana workspace to keep projects on track
atlassianreadManage your Jira tickets and Confluence docs
clickupreadTask management, project tracking
cloudflarereadBuild applications, analyze traffic, monitor performance, and manage security settings
figmareadAccess designs, export assets (Requires Figma Desktop with Dev Mode MCP Server)
intercomreadAccess real-time customer conversations, tickets, and user data
invideoreadBuild video creation capabilities into your applications
linearreadIntegrate with Linear
notionwriteRead docs, update pages, manage tasks
parallel-searchwriteOpt in by clicking Add. User-provided search objectives, search queries, and requested URLs are sent to Parallel.
paypalreadIntegrate PayPal commerce capabilities, payment processing, transaction management
plaidreadAnalyze, troubleshoot, and optimize Plaid integrations. Banking data, financial account linking
sentryreadMonitor errors, debug production issues
socketreadSecurity analysis for dependencies
squarereadUse an agent to build on Square APIs. Payments, inventory, orders, and more
stripereadPayment processing, subscription management, and financial transactions
workatoreadAccess any application, workflows or data via Workato, made accessible for AI
zapierreadConnect to nearly 8,000 apps through Zapier
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
src-tauri/src/installer.rs:168
"apt" => ("sudo", vec!["apt", "install", "-y", package_name]),
Why it matters. asks for elevated privileges
MEDIUMInventory / provenance · inv.binary · CWE-1104
src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/components/claude-code/PreConfiguredServersDialog.tsx:143
url: "http://127.0.0.1:3845/sse"
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/components/server/form/NetworkConfigSection.tsx:2
import { LabeledInput } from "../../shared/LabeledInput";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/components/server/form/ServerConfigForm.tsx:3
import { LabeledInput } from "../../shared/LabeledInput";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/components/server/form/ServerTemplateForm.tsx:2
import { LabeledInput } from "../../shared/LabeledInput";
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/hooks/useGithubReadmeJson.ts:47
const readme = atob(data.content.replace(/\n/g, ""));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/pages/InstallApp.tsx:26
const decodedConfig = atob(config);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/pages/InstallApp.tsx:30
return atob(config);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/utils/urlHelper.ts:21
const binary = atob(base64);
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/ci.yml:45
sudo apt update
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/ci.yml:46
sudo apt install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:77
sudo apt-get update
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:78
sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@hookform/resolvers, @radix-ui/react-accordion, @radix-ui/react-alert-dialog, @radix-ui/react-checkbox, @radix-ui/react-collapsible, @radix-ui/react-context-menu, @radix-ui/react-dialog, @radix-ui/rea
Why it matters. 64 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0c750ea6ad21full audit observations/trust-audit/mcp-server/milisp__store.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080c750ea6ad21BLOCKD69first audit
06

Questions

What is the Store MCP server?

MCP store. Discover, add & syncs configuration manager across clients like Claude code, Codex, Cursor💡mcphub

What tools does Store expose?

19 in total: 16 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Store safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Store need?

No credential environment variables were found in its source, so it appears to need none.

How does Store run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-linker at 2.3.0.

How current is this page?

The grade is for one exact copy of the source (0c750ea6ad21), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement