StoreBLOCK
MCP store. Discover, add & syncs configuration manager across clients like Claude code, Codex, Cursor💡mcphub
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/milisp/mcp-linker/stargazers) [](https://milisp.github.io/modern-github-release/#/repo/milisp/mcp-linker) [](#) [](CONTRIBUTING.md)
🌐 Languages: 中文 | 🌍 Other Languages
One-click add and sync MCP servers across AI clients — No LLM calls needed, Built-in marketplace
[!TIP] ⭐ Star the repo and follow milisp on Twitter and GitHub for more!
🚀 Why MCP Linker?
- ⚡ Instant — Add MCP servers in seconds
- 🧠 Multi-Client Support — Works with all major AI clients
✨ Features
- Local Sync — Sync MCP server configs across multiple clients
- Official MCP Registry — Browse and install servers straight from registry.modelcontextprotocol.io
- Multi-Client Support — Claude Desktop/Code, Cursor, VS Code, Cline, Windsurf, Codex, Roo Code. see Detail
- Cross-Platform — macOS, Windows, Linux
- Smart Detection — Auto-detect Python, Node.js, uv environments
- GUI for OpenAI Codex CLI — based on Codexia
🚀 Quick Start
Installation
macOS (Homebrew)
brew install mcplinker
Arch Linux (AUR)
yay -S mcp-linker-bin
Windows / Linux / macOS (Direct Download) Download the: 📥latest Releases
[!Note] If you have subscribed, please relaunch the app after logging in for the first time.
Getting Started
- Browse MCP servers in the built-in marketplace
- Click "Get" to show configuration
0c750ea6ad21OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-linker -- npx -y [email protected]
{
"mcpServers": {
"mcp-linker": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (19)
16 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
airtable | write | Read/write records, manage bases and tables |
asana | read | Interact with your Asana workspace to keep projects on track |
atlassian | read | Manage your Jira tickets and Confluence docs |
clickup | read | Task management, project tracking |
cloudflare | read | Build applications, analyze traffic, monitor performance, and manage security settings |
figma | read | Access designs, export assets (Requires Figma Desktop with Dev Mode MCP Server) |
intercom | read | Access real-time customer conversations, tickets, and user data |
invideo | read | Build video creation capabilities into your applications |
linear | read | Integrate with Linear |
notion | write | Read docs, update pages, manage tasks |
parallel-search | write | Opt in by clicking Add. User-provided search objectives, search queries, and requested URLs are sent to Parallel. |
paypal | read | Integrate PayPal commerce capabilities, payment processing, transaction management |
plaid | read | Analyze, troubleshoot, and optimize Plaid integrations. Banking data, financial account linking |
sentry | read | Monitor errors, debug production issues |
socket | read | Security analysis for dependencies |
square | read | Use an agent to build on Square APIs. Payments, inventory, orders, and more |
stripe | read | Payment processing, subscription management, and financial transactions |
workato | read | Access any application, workflows or data via Workato, made accessible for AI |
zapier | read | Connect to nearly 8,000 apps through Zapier |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
"apt" => ("sudo", vec!["apt", "install", "-y", package_name]),icon.icns
url: "http://127.0.0.1:3845/sse"
streamable-http
.prettierignore
import { LabeledInput } from "../../shared/LabeledInput";import { LabeledInput } from "../../shared/LabeledInput";import { LabeledInput } from "../../shared/LabeledInput";const readme = atob(data.content.replace(/\n/g, ""));
const decodedConfig = atob(config);
return atob(config);
const binary = atob(base64);
sudo apt update
sudo apt install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
sudo apt-get update
sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
@hookform/resolvers, @radix-ui/react-accordion, @radix-ui/react-alert-dialog, @radix-ui/react-checkbox, @radix-ui/react-collapsible, @radix-ui/react-context-menu, @radix-ui/react-dialog, @radix-ui/rea
system use found in code, not declared in the description
Gates applied: no_behavioural_pass.
0c750ea6ad21full audit observations/trust-audit/mcp-server/milisp__store.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0c750ea6ad21 | BLOCK | D | 69 | first audit |
Questions
What is the Store MCP server?
MCP store. Discover, add & syncs configuration manager across clients like Claude code, Codex, Cursor💡mcphub
What tools does Store expose?
19 in total: 16 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Store safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Store need?
No credential environment variables were found in its source, so it appears to need none.
How does Store run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-linker at 2.3.0.
How current is this page?
The grade is for one exact copy of the source (0c750ea6ad21), read on 2026-10-08. The repository is watched and re-audited when it changes.