{"_id":"@getmcpm/cli","_rev":"69-6d5157034e1647444ebf1d2d1aed5ca7","name":"@getmcpm/cli","dist-tags":{"latest":"0.43.0"},"versions":{"0.1.0":{"name":"@getmcpm/cli","version":"0.1.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.1.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"8995e1c9143910b94425122dfefaa4334ecb8503","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.1.0.tgz","fileCount":68,"integrity":"sha512-5YQ6vVun8pR2v3Z2TlCcRMt7vh6nx+scEtzDE9Eb/sYcszT9AwiMmTopT51gmFquttYpVt/kSW/sDt0lcFPqDg==","signatures":[{"sig":"MEUCIF+8OLlrUGYKY3+Az7ZEHJVje5QceuotUmWwrdwPE1JZAiEA9A2affRbi6Fm6MAKsjkKcHb0caseBVC8q3aDok2Ch6w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":297989},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"m1ngshum","email":"wwwdycg@gmail.com"},"_resolved":"/tmp/3ad137e0d66c8ef16c00bb544636e112/getmcpm-cli-0.1.0.tgz","_integrity":"sha512-5YQ6vVun8pR2v3Z2TlCcRMt7vh6nx+scEtzDE9Eb/sYcszT9AwiMmTopT51gmFquttYpVt/kSW/sDt0lcFPqDg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.9.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.0","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","chalk":"^5.4.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.0_1774806282845_0.14494026928287096","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@getmcpm/cli","version":"0.1.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.1.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"be1a2f37b0b3b372c2fd483de1261d6a000989ce","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.1.1.tgz","fileCount":72,"integrity":"sha512-rxR5Fwvg9Gi0MTZ6RbRX8VavWq2yrp/ONrybWqPWgASpk43Zlr7NJ9FnhtaOO2m9EIqRaZgxawfgA980UODtBA==","signatures":[{"sig":"MEQCIHXfm+aKamjStk7+e5qNlTAmitQvdKCMzL1jUxImI9m3AiBe7QXliVdoTp4Z4HOSg+5FzEwLBDJuB89nJCsOo3H8zQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":342793},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/2ead9de6c228387476cb28ae2c17bf27/getmcpm-cli-0.1.1.tgz","_integrity":"sha512-rxR5Fwvg9Gi0MTZ6RbRX8VavWq2yrp/ONrybWqPWgASpk43Zlr7NJ9FnhtaOO2m9EIqRaZgxawfgA980UODtBA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.9.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.0","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","chalk":"^5.4.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.1_1774841302873_0.9533289818656963","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@getmcpm/cli","version":"0.1.2","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.1.2","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"1595d0dc6912b6ea8308dcd0f7f7b0878bf3e5c3","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.1.2.tgz","fileCount":72,"integrity":"sha512-SsVrXRVf3fJ5ES+pOW4wtNKyHKpqNFBXQoh6brZgRRIoDP0awAGMSUahPnHFykPbQyVigIutBEie9hmEBqJS2w==","signatures":[{"sig":"MEUCIAZ0rQdcq91AupuCIrsF9BgtRYNEpCodsPd9FI9ji6mVAiEA4cQJ5Pzr6g1GltYmj/QRBlb+0/OfD+wOUg9JDSfNKog=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":345651},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.1.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/b891abdce18b19b344be4b0a9ad2b555/getmcpm-cli-0.1.2.tgz","_integrity":"sha512-SsVrXRVf3fJ5ES+pOW4wtNKyHKpqNFBXQoh6brZgRRIoDP0awAGMSUahPnHFykPbQyVigIutBEie9hmEBqJS2w==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.9.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.0","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","chalk":"^5.4.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.2_1774858745235_0.7983543382923448","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@getmcpm/cli","version":"0.1.3","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.1.3","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"002a79d51a823de36a4ec39ef67a1ff81f8d654e","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.1.3.tgz","fileCount":72,"integrity":"sha512-d8Xz3Xd+OQRsZ3BIuRH57vJkpcWbYVG98cy1jcbE2Uh+b4IaL6LP8jMs0164izf9BEXfdQsYVDBWczkVPzz0bQ==","signatures":[{"sig":"MEYCIQCvVgwflR/5fowmolKDVRFCwJMD8K5lOZCbd1MLq1uJ6wIhAPzEDmimo/wppZYkWSoiJPvxgXrn9cI/3WgO+wfQl1JE","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":347359},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.1.3.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/ee32c7cc0d614b71a131e053153faa22/getmcpm-cli-0.1.3.tgz","_integrity":"sha512-d8Xz3Xd+OQRsZ3BIuRH57vJkpcWbYVG98cy1jcbE2Uh+b4IaL6LP8jMs0164izf9BEXfdQsYVDBWczkVPzz0bQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.9.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.0","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","chalk":"^5.4.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.3_1774866941463_0.1839707112884379","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@getmcpm/cli","version":"0.2.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.2.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"b886168545d2b7540d332d9baf8861929499b076","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.2.0.tgz","fileCount":78,"integrity":"sha512-H+2oHK4pkkRtKwtm2WH3XNnalh/Nl7knRnyV2qG6F+sug1vF4V/6CQ3A0CCceytpE6ZXpdBT4E1snwaBRuNcdg==","signatures":[{"sig":"MEQCICSsQVAb4G/VwzbdsWMyaSPG3lb1rTVxGwM58Rz10+zoAiAlu94Uj0tpK+Dtu4FsghSbXAohhtll9ncp94P9BQHTbw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":396276},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.2.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/d3a644afa2293a4eba48756a839ab077/getmcpm-cli-0.2.0.tgz","_integrity":"sha512-H+2oHK4pkkRtKwtm2WH3XNnalh/Nl7knRnyV2qG6F+sug1vF4V/6CQ3A0CCceytpE6ZXpdBT4E1snwaBRuNcdg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","chalk":"^5.4.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.2.0_1775369843131_0.5270700335028748","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@getmcpm/cli","version":"0.2.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.2.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"0869ff77ec8b9f5f83f6fcc7be8f803e54bc2049","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.2.1.tgz","fileCount":78,"integrity":"sha512-Ra+LNuoleJjsWY5BsLiD188/N0+A7YaxnNANe+I6vPMjnJ4FBYTUg5qr2tRzwoigeyrLPqVN96L4FI5BpJOaEA==","signatures":[{"sig":"MEQCIGp8qIWtfq4uUJPOdvRjP06bsCkCYEatlLDb//m7aleoAiAoRuVQRCK67UUE/OQKF+PAkynMx73g6ufH8rwCYtPCwQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":396282},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.2.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/c68832e41b840f33fee7053f06a0b089/getmcpm-cli-0.2.1.tgz","_integrity":"sha512-Ra+LNuoleJjsWY5BsLiD188/N0+A7YaxnNANe+I6vPMjnJ4FBYTUg5qr2tRzwoigeyrLPqVN96L4FI5BpJOaEA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","chalk":"^5.4.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.2.1_1775370674612_0.09019044044800939","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@getmcpm/cli","version":"0.2.2","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.2.2","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"67b9c17ae12ea243f22745ca4804e3872a253125","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.2.2.tgz","fileCount":78,"integrity":"sha512-b2qfv2XibifTVnntdWlYAPVkSdhhw/ZjmeXi1eOk7423LzmX6g/E+ZC6Hinq4C+qd6ZCQRztMQgYb8q0QstVqQ==","signatures":[{"sig":"MEYCIQDLlh0QXcmpidwfiLmWwoqLtROY+5MENKQKIo/NXXULGQIhAJnR6R4wQ3KiMbPEOUafwlAj5k5uKA6eBHavKZuVKsVo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":397452},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.2.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/470860e96210788070239d1b87cc40fd/getmcpm-cli-0.2.2.tgz","_integrity":"sha512-b2qfv2XibifTVnntdWlYAPVkSdhhw/ZjmeXi1eOk7423LzmX6g/E+ZC6Hinq4C+qd6ZCQRztMQgYb8q0QstVqQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","chalk":"^5.4.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.2.2_1775372006074_0.314819781281074","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@getmcpm/cli","version":"0.3.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.3.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"0e443d2ce030ca6d2688416b5805743a24132e79","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.3.0.tgz","fileCount":88,"integrity":"sha512-OSKeCWk7pI0E+lYX8aVqVvHMt5EK9cS4/0sAuFnfkbGMV3w5HfarF+AE8PUkbTYPuZp8xa5emYpCVfrmlgPfeQ==","signatures":[{"sig":"MEQCIAuNDEAg4C5jaWlUGBNSnet5/Rr0pAYMo+YZw/8QeNI4AiBIaJUi64PoeizdDV3BuwmwcHPZh4gJOOmJJsK+U+wDtA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":516993},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.3.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/f55c55b011a842ecae967f2d67a711ca/getmcpm-cli-0.3.0.tgz","_integrity":"sha512-OSKeCWk7pI0E+lYX8aVqVvHMt5EK9cS4/0sAuFnfkbGMV3w5HfarF+AE8PUkbTYPuZp8xa5emYpCVfrmlgPfeQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","yaml":"^2.8.3","chalk":"^5.4.0","semver":"^7.7.4","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.3.0_1775412017049_0.02742228258274393","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@getmcpm/cli","version":"0.3.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.3.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"b87529d09924d7a7a459f5eee8e048da79a3e241","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.3.1.tgz","fileCount":88,"integrity":"sha512-fdQ7xufzPUc7flJdZUFlqAQdBMWFXbWtJe9evyZ5J7L4BqL4Xp6lnjM1WPt+BUx+Z7NNz8U7+tAND6n17tnjzQ==","signatures":[{"sig":"MEQCIC2AqbywouMYk/OrH4jDZu6lWdGqwoio4Zb84hvSWraEAiA02zEYtwTVHRB1a/gaqZsPrvrLP/ffFXRaGxLTWiR/Fw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":518522},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.3.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/eec200195d8559ea23407960d8e7b1b1/getmcpm-cli-0.3.1.tgz","_integrity":"sha512-fdQ7xufzPUc7flJdZUFlqAQdBMWFXbWtJe9evyZ5J7L4BqL4Xp6lnjM1WPt+BUx+Z7NNz8U7+tAND6n17tnjzQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","yaml":"^2.8.3","chalk":"^5.4.0","semver":"^7.7.4","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.3.1_1775464379064_0.09962287268743486","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@getmcpm/cli","version":"0.3.2","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.3.2","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"82772edef35a7ec398857a5f70467adb562713a4","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.3.2.tgz","fileCount":88,"integrity":"sha512-++zX3ZrYiN/lts1qKLjHA0RMyGAqY+peoJ4WvroFp38SsqTJW/YnpCozMsfmaJGbYr9ZJnDoJQYUJzSQync99g==","signatures":[{"sig":"MEYCIQDm/4dKccdedl6f8X2KWlsc0dArvX4EyjSpGKuJRhkVBgIhAOStFAPikT9boQNWTzWWNWzLEUdTz3+pto23Y2xK8HfX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":519035},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.3.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/b74ae2283ab4e90b6a48433754bec635/getmcpm-cli-0.3.2.tgz","_integrity":"sha512-++zX3ZrYiN/lts1qKLjHA0RMyGAqY+peoJ4WvroFp38SsqTJW/YnpCozMsfmaJGbYr9ZJnDoJQYUJzSQync99g==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.3.0","zod":"^3.25.0","yaml":"^2.8.3","chalk":"^5.4.0","semver":"^7.7.4","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.3.2","@modelcontextprotocol/sdk":"^1.28.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.4.0","vitest":"^3.0.0","typescript":"^5.9.0","@types/node":"^22.0.0","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.3.2_1775471170081_0.2966901391872738","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@getmcpm/cli","version":"0.3.3","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.3.3","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"e02c9bc412830917d135ac83e7df0523bd1f0708","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.3.3.tgz","fileCount":88,"integrity":"sha512-TXuf3FQjJEkiMXxx9sXVO5MAMqHum0WRjKjUX5rOQX2WYP+0O3mHBMYpJpFwn2n12u19i0hZkZoUbTBzvt5beg==","signatures":[{"sig":"MEQCIHieOn+0NO+MNI4cAzDxe4Zu7uqThbkJhTwMW8wVNImPAiBQrWykF+A3iJa8IVx/5JIU4g8attALfekRKJNU6nfheA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.3.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":535570},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.3.3.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/86d68f0a7fd6d91ba3b23d2465ea5653/getmcpm-cli-0.3.3.tgz","_integrity":"sha512-TXuf3FQjJEkiMXxx9sXVO5MAMqHum0WRjKjUX5rOQX2WYP+0O3mHBMYpJpFwn2n12u19i0hZkZoUbTBzvt5beg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.4.0","zod":"^3.25.76","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.18","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.3.3_1778523565778_0.7109091484461778","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@getmcpm/cli","version":"0.4.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.4.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"ee2063419da837c3d8939a4914981cfd13e8b35f","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.4.0.tgz","fileCount":92,"integrity":"sha512-zvo23apnqdKu1mYexSxHQApi+0KzFk+5xJYbp5jUIwjqRUmLjNtOETs+MhKdRKs17LqsSKcadRxudgcP/viCZg==","signatures":[{"sig":"MEUCIDGmwoPUPhcs9gR/ds98T7v/uB0M09HorrvhtobnnC0VAiEAiHcrOXBxijJjegfH0Ca1LwXBbg2ZJHKWavSKCi/SskI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":585822},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.4.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/f8c04c509b832e44e0ef1f6fd01f9a9f/getmcpm-cli-0.4.0.tgz","_integrity":"sha512-zvo23apnqdKu1mYexSxHQApi+0KzFk+5xJYbp5jUIwjqRUmLjNtOETs+MhKdRKs17LqsSKcadRxudgcP/viCZg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.11.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ora":"^9.4.0","zod":"^3.25.76","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.0","commander":"^14.0.3","cli-table3":"^0.6.5","@inquirer/prompts":"^8.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.18","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.4.0_1778596698295_0.27319029734623457","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@getmcpm/cli","version":"0.5.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.5.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"178de20243d610bacab5bc7a7fd6dd589f64c4d2","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.5.0.tgz","fileCount":118,"integrity":"sha512-ZdnO7QazSJ43zhHLXWTij/4HfmBrQazmsghplkBzdey37ZKYAk3HtF9mFq2CuxcXAr0Q76PTXGgwdL2pMjJM4w==","signatures":[{"sig":"MEUCIQCbFV3e269ecPwuVec6kmvAigfuTFGaRAspmOhto9N9JQIgXVJa8qkrki538Q8N2gsK4GXChlfHbszNyGZLVPJuw/I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":814407},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.5.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/177487b5d819aa04ad5585de5bbfb342/getmcpm-cli-0.5.0.tgz","_integrity":"sha512-ZdnO7QazSJ43zhHLXWTij/4HfmBrQazmsghplkBzdey37ZKYAk3HtF9mFq2CuxcXAr0Q76PTXGgwdL2pMjJM4w==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.12.1","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.15.0","dependencies":{"ora":"^9.4.0","zod":"^3.25.76","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.0","commander":"^14.0.3","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.4.3","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.18","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.5.0_1779006907247_0.028680010307808645","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@getmcpm/cli","version":"0.6.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.6.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"7fde1d9f9487e4c847b449fbe3394b16df432700","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.6.0.tgz","fileCount":122,"integrity":"sha512-MLtjsYYxXNschU5GuShQmQkr6lbeB03d1PZqtJ+arnSWSKDX4uGJIJ0an2fGol1pInrPgIA9ssA3wnSNvAhUSw==","signatures":[{"sig":"MEUCIBmoImv6bQ+dZIjA92U86f1Y83B9sMy9IlYzJDVWM6Y5AiEA3RLRp7FFo5TNQjnXbg+nUL1SHKjfcojtlkbJ03s6BFg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":866498},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.6.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/e31769883311b1fedd4ca1c584918bf4/getmcpm-cli-0.6.0.tgz","_integrity":"sha512-MLtjsYYxXNschU5GuShQmQkr6lbeB03d1PZqtJ+arnSWSKDX4uGJIJ0an2fGol1pInrPgIA9ssA3wnSNvAhUSw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^3.25.76","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^14.0.3","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.6.0_1780302206230_0.49573946094728294","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@getmcpm/cli","version":"0.7.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.7.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"f3741812776591d66f92dda7e17e079168ed338e","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.7.0.tgz","fileCount":122,"integrity":"sha512-XhddVJNjhDE37h7Rnu110oQFhzc5EMgJIHuMrjbBrQ4Hl0aF/yXwTOZZP/ezm2sq2OhYcr+a19aaSkvGOBzEgg==","signatures":[{"sig":"MEQCIDJSESNT4RJmiptfbwv+tfX/kW8Eu1fY5Y+VjGSXPOyrAiBFkkRx5nh0jdnDZLRyHMcOVeGR5mKdylsVqqStinNc/Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":891795},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.7.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/3293573b591495da35e22791ab0eaa17/getmcpm-cli-0.7.0.tgz","_integrity":"sha512-XhddVJNjhDE37h7Rnu110oQFhzc5EMgJIHuMrjbBrQ4Hl0aF/yXwTOZZP/ezm2sq2OhYcr+a19aaSkvGOBzEgg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^3.25.76","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^14.0.3","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.7.0_1780334765729_0.43560415816187503","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@getmcpm/cli","version":"0.7.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.7.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"898a049ec4f27c588fdb07608a62c4ee25c354f8","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.7.1.tgz","fileCount":122,"integrity":"sha512-5rb04GA48piTBt3UoTglTBjG7o3krfk6HwZsw6hEFQWqkybuX9g8E6lzU0x472Z6QhnwAGEoobjq05JssBvlLQ==","signatures":[{"sig":"MEYCIQC/kuTdcgXOvUQoD1ZAUPatZSOQ4J2x8VcrOL5igolW8QIhAK+J8gYW41w77CWX4I23THjheEhOPO8KGEgFg4dJDKwn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":938842},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.7.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/48fa2d71d9a42cb9f73cfc454de527e6/getmcpm-cli-0.7.1.tgz","_integrity":"sha512-5rb04GA48piTBt3UoTglTBjG7o3krfk6HwZsw6hEFQWqkybuX9g8E6lzU0x472Z6QhnwAGEoobjq05JssBvlLQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^3.25.76","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^14.0.3","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.7.1_1780388650177_0.834322572955633","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@getmcpm/cli","version":"0.8.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.8.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"13376c963069f53ec7d320974dbcca9c323ec45f","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.8.0.tgz","fileCount":122,"integrity":"sha512-xUAmccY4I+4LN5PNVyqfCb6eL+JsfVBR20xk+Lf+HRLVQ5DEz8IsJ49RHWf8W+AJAJt8Fr6Noc3S6V/wTY1r5A==","signatures":[{"sig":"MEQCIC+R0dJ+J0irEQdVWbLIJT0/6mrbL6lDUV6Im2zbeK7KAiAQcjf8MplbCa7dmbUbPIop64ALozX/2ytm8fSIUpy+zQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":992034},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.8.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/9aa27e6c7876463ccf3598457316cc4e/getmcpm-cli-0.8.0.tgz","_integrity":"sha512-xUAmccY4I+4LN5PNVyqfCb6eL+JsfVBR20xk+Lf+HRLVQ5DEz8IsJ49RHWf8W+AJAJt8Fr6Noc3S6V/wTY1r5A==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^3.25.76","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^14.0.3","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.8.0_1780415716254_0.5733029913430057","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"@getmcpm/cli","version":"0.8.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.8.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"24f2c72d6dd6b096224f8c32ea4ec2980c4492bb","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.8.1.tgz","fileCount":122,"integrity":"sha512-TPCM2cU/wXbSydZB2DRgez2PtcI9LUjGnr9mxoJlo7NeJCH/eprBGsZYxi967DwVpYfcNVjlu+k/rDcNdvtU6A==","signatures":[{"sig":"MEQCIEfVscAC92WkLaTM75/ntCmyU1oX/Vi89CjoBq/4/JpVAiA066mf0esMXrGzOeRERMkv4bO7g2c8lAd10KqcwhDvlg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.8.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1057320},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.8.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/c651d66573e07cc772e1d7479bb6e741/getmcpm-cli-0.8.1.tgz","_integrity":"sha512-TPCM2cU/wXbSydZB2DRgez2PtcI9LUjGnr9mxoJlo7NeJCH/eprBGsZYxi967DwVpYfcNVjlu+k/rDcNdvtU6A==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.8.1_1780936424351_0.7383066497898092","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@getmcpm/cli","version":"0.9.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.9.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"4984d33ea5e3c330d5a1d7eb54c8a7272c74eb48","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.9.0.tgz","fileCount":122,"integrity":"sha512-PGZuao6cGoS5rNEBCSEcFGaRcMD3tbDme1fuIqp4jFJFAcJceWEl50or9cjCPhAMhbXtenHxDJ6CSb7ds2Ex0A==","signatures":[{"sig":"MEQCIG0QphXnwBnqgkxnHEtVPKPEOf/+ygyFIuxcVB8f0hMwAiASapaaZ22/kNt5dLPoqgU8NRBYswBC3dPTogLYk0N17g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1100433},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.9.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/aca5efe8dfa49514364be7d1e8060bf7/getmcpm-cli-0.9.0.tgz","_integrity":"sha512-PGZuao6cGoS5rNEBCSEcFGaRcMD3tbDme1fuIqp4jFJFAcJceWEl50or9cjCPhAMhbXtenHxDJ6CSb7ds2Ex0A==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.9.0_1781080704257_0.38370229794467114","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@getmcpm/cli","version":"0.10.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.10.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"708aaa3e9db1cf2285fad073b3debfb673426af9","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.10.0.tgz","fileCount":124,"integrity":"sha512-3KvHG78X/3d0xj0FGQtu7wqyCDbcAnRaJ6SfebHJI3uBXTSXF+CYIZdoW3IctaIGys0OmhssiWjfy6N+LZBYjw==","signatures":[{"sig":"MEUCIDOZuvIZY/1sODNOqnpqtuGbg4Np+STMm35xNbZZ2J3CAiEAyLMTHUvA5KWuORL37tuX/dlwh6QB9/y9zecz+FwqiJE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1272196},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.10.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/f2049988b383bb25bbd57f19f34a3aec/getmcpm-cli-0.10.0.tgz","_integrity":"sha512-3KvHG78X/3d0xj0FGQtu7wqyCDbcAnRaJ6SfebHJI3uBXTSXF+CYIZdoW3IctaIGys0OmhssiWjfy6N+LZBYjw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.10.0_1781422131253_0.9470030638923637","host":"s3://npm-registry-packages-npm-production"}},"0.10.1":{"name":"@getmcpm/cli","version":"0.10.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.10.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"927f526e321ebe926292d5c581e5ac5a9b478dad","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.10.1.tgz","fileCount":124,"integrity":"sha512-3gwiTHngJksXCpBbU/4GktyHQMoDb3x/FTeAOc6yoh9vNqhV0JGCc9LmvpRQ84ALUBWYEiIO0Yn4WVKnyTRIJA==","signatures":[{"sig":"MEUCIQCshOhFN1ycoEHcb9jzt/WselLOTQJ0Wvb2sQeWvgjb6QIgPNTDADYj5Qt3Ex/fjK3BU2YUNMg1ieNkNz9G73kuoF4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.10.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1273658},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.10.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/56cdd147e1d1b2c482c0838b100da254/getmcpm-cli-0.10.1.tgz","_integrity":"sha512-3gwiTHngJksXCpBbU/4GktyHQMoDb3x/FTeAOc6yoh9vNqhV0JGCc9LmvpRQ84ALUBWYEiIO0Yn4WVKnyTRIJA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.10.1_1781434210328_0.123551175323668","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@getmcpm/cli","version":"0.11.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.11.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"a22f721193db8be8b3045f8a49ca20c70ddf60bd","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.11.0.tgz","fileCount":124,"integrity":"sha512-XLwfTi9vJLqlOEJK4tJV2HiR3mLGzTIN6tYAAMz0KQWFrDa9LckuyAyDJlzSudee9hvWhYpcUgh6oiHbGnRzUQ==","signatures":[{"sig":"MEUCIGxe27+j3dVOK+suoH9Fwb+KX+OWCXtSqZgryzGFtJe4AiEA/7dLwoFUy8lLijuNUIC1KJGylQRZPKFmFPvQQxTc4o8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1289392},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.11.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/c0e8c8630ff6a84397db6ad6ab4ff22a/getmcpm-cli-0.11.0.tgz","_integrity":"sha512-XLwfTi9vJLqlOEJK4tJV2HiR3mLGzTIN6tYAAMz0KQWFrDa9LckuyAyDJlzSudee9hvWhYpcUgh6oiHbGnRzUQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.11.0_1781720819572_0.8916943741654022","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@getmcpm/cli","version":"0.12.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.12.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"7e61bacb503df8cf4df7aaaca687948088916ebd","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.12.0.tgz","fileCount":124,"integrity":"sha512-0E2WyKI+Yb9q6ueeJXUxUuJ/CPUTIG6hsXp3O9vO/IwCRz1OqZJgw+2t2+IC0wtMj5NFqZ3uFBB4YSpMWX2pxg==","signatures":[{"sig":"MEQCIBs0KU3g/Cl1/BNVFMGFEqO/RdNDXi12RXYLy67xdpQaAiBRNf6+ohESubtQSS5B0GaB4q37p/EioCyTvG0sLKwGcQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1306305},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.12.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/dc64f6e6bd301d85f513683fd63ed24f/getmcpm-cli-0.12.0.tgz","_integrity":"sha512-0E2WyKI+Yb9q6ueeJXUxUuJ/CPUTIG6hsXp3O9vO/IwCRz1OqZJgw+2t2+IC0wtMj5NFqZ3uFBB4YSpMWX2pxg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.12.0_1781853493021_0.7926147147474005","host":"s3://npm-registry-packages-npm-production"}},"0.12.1":{"name":"@getmcpm/cli","version":"0.12.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.12.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"baf2781a425af5c68583661445183a15c29f1f24","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.12.1.tgz","fileCount":124,"integrity":"sha512-m+SKQgIAEehQihavV2cLjqxE9NFfNsnsl/grmQ5rr9UQAezL7zC2jvKJgZPnMz2D3fKMMqieuGInKC9Pb6z/TA==","signatures":[{"sig":"MEUCIQDCs77PmdHcOynALr5MTwCdCFfjsY5zkmfMBvRfApVUnwIgcNOThHhsbWmbFXo6x19rAhh4V591NK4pvsAR9UQCZEQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.12.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1308802},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.12.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/090f3c381b84a5d6778a2a61d212850e/getmcpm-cli-0.12.1.tgz","_integrity":"sha512-m+SKQgIAEehQihavV2cLjqxE9NFfNsnsl/grmQ5rr9UQAezL7zC2jvKJgZPnMz2D3fKMMqieuGInKC9Pb6z/TA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.12.1_1781855224964_0.022429112016610242","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"@getmcpm/cli","version":"0.13.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.13.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"495639ab7db1f86a527b28ffe249839e54fbd55d","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.13.0.tgz","fileCount":124,"integrity":"sha512-ClZhzcbiCvBW8/w4mA/uYvAyVpeZfMj5uZCWnnOwf69iyGVEyHd5a4KmKa4I2vs8h9+mdo4kjjJp9QJX1GOvDA==","signatures":[{"sig":"MEYCIQD4pTHo+czZ+mEgqXxfbOEJWx8WLdWHcBDXVl2g/JAW6gIhALraiBcEHdf22MYFrqQVCJZ/qa3O4y+cUfiGNmNXXSNV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1322043},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.13.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/90e53dc3688bc9abdbd8946a361b8710/getmcpm-cli-0.13.0.tgz","_integrity":"sha512-ClZhzcbiCvBW8/w4mA/uYvAyVpeZfMj5uZCWnnOwf69iyGVEyHd5a4KmKa4I2vs8h9+mdo4kjjJp9QJX1GOvDA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.13.0_1781886564030_0.7530566914439714","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"@getmcpm/cli","version":"0.14.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.14.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"2f31c6643c3b2b7f4eea5978d3305ab3643d293a","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.14.0.tgz","fileCount":124,"integrity":"sha512-fXPTNEPmMbCMwCoZ3w03olzybDKd3PuaZIu56CpBC1jgQ+hzrWvSyZV/pasfDOq+RmitAlFZlC9UxQGefmkxNQ==","signatures":[{"sig":"MEUCIQDUFbpumJlPI06uwNOeJFhYQyZDfOFluu94rjxKBdFSTgIgOuEQaCa4Cs+ZH03YxOakH2V46Nrzkbgix7LvAV56I9I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.14.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1338058},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.14.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/f47a8155782f32e75671d14699e42f08/getmcpm-cli-0.14.0.tgz","_integrity":"sha512-fXPTNEPmMbCMwCoZ3w03olzybDKd3PuaZIu56CpBC1jgQ+hzrWvSyZV/pasfDOq+RmitAlFZlC9UxQGefmkxNQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.14.0_1781892843224_0.3357048138037886","host":"s3://npm-registry-packages-npm-production"}},"0.15.0":{"name":"@getmcpm/cli","version":"0.15.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.15.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"8d7beba73c3a34616053cd99d97a64fcc40810b6","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.15.0.tgz","fileCount":124,"integrity":"sha512-b0J7R8UkL1XY2z1Cj5I4P+JeOV/xiRe+U/vhlWYuX7QAtgCAdPlx6DVnmyNtoK4MTuFSc4sEt6k43UzNMJ8RKw==","signatures":[{"sig":"MEYCIQDa41WBA+9ZO1IHZTUfhH2OgyC7z8OTTeZsJBUXDP4XTAIhAOkWFmS5TJXMEg8xOvbA9gHk4EWSTah2eQ4YpgU8uPYW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.15.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1366862},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.15.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/79f7d84519af44df5f0a05cbb32e039c/getmcpm-cli-0.15.0.tgz","_integrity":"sha512-b0J7R8UkL1XY2z1Cj5I4P+JeOV/xiRe+U/vhlWYuX7QAtgCAdPlx6DVnmyNtoK4MTuFSc4sEt6k43UzNMJ8RKw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.16.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.15.0_1782121505294_0.23372883583691384","host":"s3://npm-registry-packages-npm-production"}},"0.16.0":{"name":"@getmcpm/cli","version":"0.16.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.16.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"cd45c31fe6fa93afebc2a65e42704e4c7ab6202d","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.16.0.tgz","fileCount":126,"integrity":"sha512-vGtE9Okk+rQu1xsFK4FHT/CjHixdRsOv2VSOKYcvroeVr3GWVrGwp0rQuqrHbnwmrmTgDfUuN/deOlCQAjeLPQ==","signatures":[{"sig":"MEYCIQCk3LDcSTL/l6cRICBDVCv4Qd18jwVN34rPWSIZCIRIjwIhAIPa519qRPYHw2evy+3zm6xnBpsgis17w76Dswtr6Kww","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.16.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1464510},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.16.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/d9aa0e96f60b1e8d1e7a5584ddc1bc4c/getmcpm-cli-0.16.0.tgz","_integrity":"sha512-vGtE9Okk+rQu1xsFK4FHT/CjHixdRsOv2VSOKYcvroeVr3GWVrGwp0rQuqrHbnwmrmTgDfUuN/deOlCQAjeLPQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.13.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.17.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.16.0_1782987790019_0.3846319089892827","host":"s3://npm-registry-packages-npm-production"}},"0.17.0":{"name":"@getmcpm/cli","version":"0.17.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.17.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"ed7f69abc4ebc603c9c6eb4ee6a474954ad79530","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.17.0.tgz","fileCount":126,"integrity":"sha512-5A7ExJ70UGzaE6H2o4CNlJ/CKAKXt44+8aplEX3SzhwscHcKx5sg96St3O+TSv7dTlr6cxfccB4H5iHzz6CF+Q==","signatures":[{"sig":"MEUCIQDeL7NBsjkGMNhofwAhKn95ah0xeY2imJ+B4asKV8G4YgIgTdp2O8jymk0Elg/B6Hq/Gzb0w2EF2PKdo70lMrhgXlE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.17.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1474035},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.17.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/1bb4c19501f439abb6f5aea47f4ee5f3/getmcpm-cli-0.17.0.tgz","_integrity":"sha512-5A7ExJ70UGzaE6H2o4CNlJ/CKAKXt44+8aplEX3SzhwscHcKx5sg96St3O+TSv7dTlr6cxfccB4H5iHzz6CF+Q==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.17.0_1783047617133_0.1305379886047835","host":"s3://npm-registry-packages-npm-production"}},"0.18.0":{"name":"@getmcpm/cli","version":"0.18.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.18.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"14c1a29a4ac0864e92888ae139303a6460fcc997","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.18.0.tgz","fileCount":126,"integrity":"sha512-oDgvBw7PPn2YCP6xgs4snfm5mXwk5kQQkiuw7hUe8jKGzDPtiw2MaKnMqRUlkT4r+3Mw1r9kfy4JrDy/8ePRmA==","signatures":[{"sig":"MEUCIG6l7SkEM+rVEJoAYa4gfHhSM6jIZe4eAPnP3jEcMPShAiEA5nqTJJSaeswm0EcG/0rp4Ieh45qJ9ca9uKRkyc9vlL4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.18.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1476564},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.18.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/7e184dc8bced58ed5cad4c039464fbac/getmcpm-cli-0.18.0.tgz","_integrity":"sha512-oDgvBw7PPn2YCP6xgs4snfm5mXwk5kQQkiuw7hUe8jKGzDPtiw2MaKnMqRUlkT4r+3Mw1r9kfy4JrDy/8ePRmA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.18.0_1783052338776_0.27229517867796216","host":"s3://npm-registry-packages-npm-production"}},"0.19.0":{"name":"@getmcpm/cli","version":"0.19.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.19.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"e7dfa732cace86987add47f454e5f5ca64179d9a","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.19.0.tgz","fileCount":128,"integrity":"sha512-SITGmhfoDBO338BNjCT9xrKsm+G/2B5vQDTVUlW62LM6FxreJIphYzZqDEWFEZChckAkXZpMEFv9OV6yTF0qMw==","signatures":[{"sig":"MEYCIQCNmPQVQh22Vqz7bIaDgRoF7fyvtHgK17wbMmYIqLvz7gIhAPXiDvWF9nkmFyobk8H/r9o6JjkADDGjaOg1w5T2bq6p","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.19.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1528132},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.19.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/75c76725d0477a265010fe9913e32442/getmcpm-cli-0.19.0.tgz","_integrity":"sha512-SITGmhfoDBO338BNjCT9xrKsm+G/2B5vQDTVUlW62LM6FxreJIphYzZqDEWFEZChckAkXZpMEFv9OV6yTF0qMw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.19.0_1783077354450_0.413828798457057","host":"s3://npm-registry-packages-npm-production"}},"0.20.0":{"name":"@getmcpm/cli","version":"0.20.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.20.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"b61b3946bc9811d62550fb08f836349d6d79883e","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.20.0.tgz","fileCount":130,"integrity":"sha512-TGiXNkKbY94ziPYeWYMd4KdkeW3NKUGRhkZ3vwfxgON2m7Evu3lan/hRFsxMwtCd5SFL2/meGSMdor80kxmtmw==","signatures":[{"sig":"MEQCIBTYP8+UDC9QqrUoBHEuMT41tChW1wVdT4bsNb+rv0/oAiAquzz5LRyMcIs/m77XXGDStS5U1HDTfnsb2CWnSRh4Wg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.20.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1556159},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.20.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/49f97409a414da3bf14add7f3c92848e/getmcpm-cli-0.20.0.tgz","_integrity":"sha512-TGiXNkKbY94ziPYeWYMd4KdkeW3NKUGRhkZ3vwfxgON2m7Evu3lan/hRFsxMwtCd5SFL2/meGSMdor80kxmtmw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.20.0_1783995849899_0.40474661298653225","host":"s3://npm-registry-packages-npm-production"}},"0.20.1":{"name":"@getmcpm/cli","version":"0.20.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.20.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"67c9c0f0d014341bfffd53260eb96c409e89418a","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.20.1.tgz","fileCount":130,"integrity":"sha512-uJKnWC9JZU49uBnXckBEYxYkZLwilooalFonFJTCX+s8BBxb0u5qKRo4UXaJwK/+ld6qJDM2EMUy39f5BA/YQg==","signatures":[{"sig":"MEQCIBduOekPtWnZwnw/H7vet/TtkSlJesk/aNMUr/9S4BwJAiBmaFNaTmHE6Qa4+8c7ivlFJ+/YjDZF3JJM6dckfE2iug==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.20.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1559900},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.20.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/29dbeec75acf1fd80f23c7deb883a6d3/getmcpm-cli-0.20.1.tgz","_integrity":"sha512-uJKnWC9JZU49uBnXckBEYxYkZLwilooalFonFJTCX+s8BBxb0u5qKRo4UXaJwK/+ld6qJDM2EMUy39f5BA/YQg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.20.1_1784173566855_0.41029661506092974","host":"s3://npm-registry-packages-npm-production"}},"0.21.0":{"name":"@getmcpm/cli","version":"0.21.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.21.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"0044160ed43fde3dcf2d796ba1b215e9e02f95ea","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.21.0.tgz","fileCount":128,"integrity":"sha512-IxF6mkNhfTSJUg0kZoWt588JvYsec3FGLE8iT82tla3Nx3KPt22Py1nBbRbi+hKRmJhAeGY/XxqwzeXSC0dhrw==","signatures":[{"sig":"MEQCIAqqdst89WZB5si9BFu63o1M1sy4JZVVSldVSF+5yNSWAiBHMmls/E+1t+NXSA7WGpdbDuFIKDDN2nrcwtDbnWk/PQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.21.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1574979},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.21.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/f8fc7bfce4abbb3a07f27b285c90d579/getmcpm-cli-0.21.0.tgz","_integrity":"sha512-IxF6mkNhfTSJUg0kZoWt588JvYsec3FGLE8iT82tla3Nx3KPt22Py1nBbRbi+hKRmJhAeGY/XxqwzeXSC0dhrw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.21.0_1784215442466_0.8994915771170926","host":"s3://npm-registry-packages-npm-production"}},"0.22.0":{"name":"@getmcpm/cli","version":"0.22.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.22.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"8cebcee907d9ecdeadd988e7010c281da110f659","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.22.0.tgz","fileCount":130,"integrity":"sha512-eE6lHHkV5SlxM1hX+VyNBYGixiAhIfsq7pZq3hTHv0+vh+klD/jQSHPos6oYEXZI+P9aXCCm/8gTyQ7CtqBPMw==","signatures":[{"sig":"MEUCIQCrtX27KZ+dswqGvU6028IY/4nOvcBxzkjnnM0Zqe93dAIgMjpS400o0pK06FIyMoo4n3NyE+46WTZKKu3L4Xv6Ewk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.22.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1615327},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.22.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/21fc2536a3f0ee5e6289d847a60759f1/getmcpm-cli-0.22.0.tgz","_integrity":"sha512-eE6lHHkV5SlxM1hX+VyNBYGixiAhIfsq7pZq3hTHv0+vh+klD/jQSHPos6oYEXZI+P9aXCCm/8gTyQ7CtqBPMw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.22.0_1784360491353_0.37284615132476784","host":"s3://npm-registry-packages-npm-production"}},"0.23.0":{"name":"@getmcpm/cli","version":"0.23.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.23.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"a4b9e2b8443aea329c8c2ca5acb9c3e3b46306b0","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.23.0.tgz","fileCount":122,"integrity":"sha512-Kpx0CBzv8a/ckR4TpAUSaCtW8dpsFcAkOTj/J8f6VGFLqEGvXBT62x6RvDPTHEaot41be17o4jX8dGTdfmaSrg==","signatures":[{"sig":"MEYCIQDpPivnsdqVgXq02GjOabDjg9HP93UoLK2oRyZobXZLewIhAMObvPYa+xgJhAjWtkZghUAu+5YWU0YTVh6asH+AN8GX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.23.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1641454},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.23.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/1456b381d974f42e6024d0581dae5f1c/getmcpm-cli-0.23.0.tgz","_integrity":"sha512-Kpx0CBzv8a/ckR4TpAUSaCtW8dpsFcAkOTj/J8f6VGFLqEGvXBT62x6RvDPTHEaot41be17o4jX8dGTdfmaSrg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^4.0.0","@sigstore/verify":"^3.1.1","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.23.0_1784521377397_0.9156340384072426","host":"s3://npm-registry-packages-npm-production"}},"0.24.0":{"name":"@getmcpm/cli","version":"0.24.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.24.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"89be28303815df92a4bac56a04eb069b4a39b689","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.24.0.tgz","fileCount":122,"integrity":"sha512-r/DibshaOraNhEBgYiFoNL7IONTPPQHoj/upeZRXBWvXMbGDh5qjBiaweCJzabKWHjR1lKcpJsO1oVmUEedFGg==","signatures":[{"sig":"MEUCIQDHwXvMuL8iEWQsRKfUXeTXovxYvJ6eKWH4LWrADvc+0wIgK9pPVXi2VZafvk4dD8YTFQ4NBnvVy18zVwoVlAKq164=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.24.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1689036},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.24.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/556c75b16147ba37cac4a39f2dc35317/getmcpm-cli-0.24.0.tgz","_integrity":"sha512-r/DibshaOraNhEBgYiFoNL7IONTPPQHoj/upeZRXBWvXMbGDh5qjBiaweCJzabKWHjR1lKcpJsO1oVmUEedFGg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^4.0.0","@sigstore/verify":"^3.1.1","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.24.0_1784743420546_0.3125424350036117","host":"s3://npm-registry-packages-npm-production"}},"0.25.0":{"name":"@getmcpm/cli","version":"0.25.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.25.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"1e2d65fe4b1f8d861ef5a736dad9b4fc05aa348e","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.25.0.tgz","fileCount":124,"integrity":"sha512-EswnNFyogV56guhiOmL0Fl9ai3BX+OQUug85wI38jiZd4rCwhTORVOKrnJtYRklYHD7Mwb/w6oMnCHyVgl0Hcw==","signatures":[{"sig":"MEQCIGl23TkLeobAk02HUYxkz6T4pNfUN7gcpLqRMRoiOnS/AiAyElR3H1W1ec6XlLUhLrGZTbyh6AcMWl+tqzDCWTGhoA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.25.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1709367},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.25.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/45ce48564f3556e394c91dff26cd6775/getmcpm-cli-0.25.0.tgz","_integrity":"sha512-EswnNFyogV56guhiOmL0Fl9ai3BX+OQUug85wI38jiZd4rCwhTORVOKrnJtYRklYHD7Mwb/w6oMnCHyVgl0Hcw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^4.0.0","@sigstore/verify":"^3.1.1","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.25.0_1784985842697_0.9310425893190639","host":"s3://npm-registry-packages-npm-production"}},"0.26.0":{"name":"@getmcpm/cli","version":"0.26.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.26.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"b74274d18782ddc0c21fff9fc8dc954d51ad2b1b","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.26.0.tgz","fileCount":124,"integrity":"sha512-E1TxAKIqySsJIuvwu53nljJmqH64DHec3MsyVQKbddhDYWil4gLKE5HB7M0M35bf3zpo+ya/vyicsQ/yoBrUdg==","signatures":[{"sig":"MEQCIQDpZiTPY2PvciUSlAb1atkN9l72b1GRp8wq+O7Ep/f0swIfbTAbfMlwgEccJN4Dku73qTYgJsYV6XolJFdHM1bDIQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.26.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1714353},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.26.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/84086bbf5fd9e81476a7319a277257f7/getmcpm-cli-0.26.0.tgz","_integrity":"sha512-E1TxAKIqySsJIuvwu53nljJmqH64DHec3MsyVQKbddhDYWil4gLKE5HB7M0M35bf3zpo+ya/vyicsQ/yoBrUdg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^4.0.0","@sigstore/verify":"^3.1.1","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.26.0_1784991912512_0.8552376676215849","host":"s3://npm-registry-packages-npm-production"}},"0.26.1":{"name":"@getmcpm/cli","version":"0.26.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.26.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"3f8d876b3dfa635593532160df075734488d0708","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.26.1.tgz","fileCount":124,"integrity":"sha512-u0tJixk43sKusAj0bNhv9qxWBwQEL5zRqwZlsJ/vtAgZDrOzbnMtXPAsOIfDIwsACTHwXapeT8es/smQLTccCQ==","signatures":[{"sig":"MEYCIQCPNpwJaHNXc7zKxr8flrQl2a3BYvopuJc0PDvdCjKDmgIhAK5Sug4K2RPTcZmrlEyKeiqtjHiK9MOvDI0rcZNO17CO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.26.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1718802},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.26.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/3d2c828da8713dec12d6e11489de1fd0/getmcpm-cli-0.26.1.tgz","_integrity":"sha512-u0tJixk43sKusAj0bNhv9qxWBwQEL5zRqwZlsJ/vtAgZDrOzbnMtXPAsOIfDIwsACTHwXapeT8es/smQLTccCQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^4.0.0","@sigstore/verify":"^3.1.1","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.26.1_1784993094217_0.5532493268231191","host":"s3://npm-registry-packages-npm-production"}},"0.26.2":{"name":"@getmcpm/cli","version":"0.26.2","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.26.2","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"f2068b2092ad84191e370abaef607c3e8a7bf6e1","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.26.2.tgz","fileCount":124,"integrity":"sha512-giPY5Cv2MO/W/Vo6HOmATb7pIGuAkQuiBZGTDgSVcuw0xwNrWhopPWiGs2N9SLV+aesRbtibYEUS9o0WpnccUg==","signatures":[{"sig":"MEUCIA+ULsyAizpcR5YQp4QZrfzbBK1RioyoWRLI2n+cuFT6AiEAyJcQU1jENbAARek5lple7TwNtP8610EoL9DTaOpheoI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.26.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1718802},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.26.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/2c138cf66bd56d328d24442874aa0d6e/getmcpm-cli-0.26.2.tgz","_integrity":"sha512-giPY5Cv2MO/W/Vo6HOmATb7pIGuAkQuiBZGTDgSVcuw0xwNrWhopPWiGs2N9SLV+aesRbtibYEUS9o0WpnccUg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.0","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.26.2_1784994063409_0.12472029335262036","host":"s3://npm-registry-packages-npm-production"}},"0.26.3":{"name":"@getmcpm/cli","version":"0.26.3","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.26.3","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"446e90a77ea238130ea3cd10f0e5887308437f75","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.26.3.tgz","fileCount":124,"integrity":"sha512-ga+azRPqecLFZ0Y5eUfwQ1Lh6wyJl/ToI/YjiBoloqblqQjLtx75t6crYjmCCrZyzqpdIrrN+xKRMhOOtYtSeA==","signatures":[{"sig":"MEQCIEZufpkMtUjMS4cO1sqz+RNbJzJhKJwm9gH+YooK2Il+AiAxJPYceVpL4GD2j/eiJgch2sGXsHRE7XPbxUwiElAd1A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.26.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1719806},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.26.3.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/318e511e07a5eeac6548251ce750da07/getmcpm-cli-0.26.3.tgz","_integrity":"sha512-ga+azRPqecLFZ0Y5eUfwQ1Lh6wyJl/ToI/YjiBoloqblqQjLtx75t6crYjmCCrZyzqpdIrrN+xKRMhOOtYtSeA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.0","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.26.3_1784996049019_0.005214623050728173","host":"s3://npm-registry-packages-npm-production"}},"0.27.0":{"name":"@getmcpm/cli","version":"0.27.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.27.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"5d56aba57acfb3b4c6b434e5a7c3a0a57813db07","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.27.0.tgz","fileCount":126,"integrity":"sha512-Pxy+JZywXkXJRC87CKfAVOHX5PVstXqwGYsmpn9l6vJ+QKvsQ4GRs5yQiwV9ofxf0wupepx4MRUeufJzBAG3Ow==","signatures":[{"sig":"MEUCIQDNq5NvcerfOcAwz9G/b3Q4XtpHXX6BxnXSXv4E3Lc5UgIgNKsL4vUCjq2zr9w3bW7Ler2edKt23hSe1U2ptoxPVvw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.27.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1722606},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.27.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/e1c0c14d1a9eb14e6cb4d7682d04f8eb/getmcpm-cli-0.27.0.tgz","_integrity":"sha512-Pxy+JZywXkXJRC87CKfAVOHX5PVstXqwGYsmpn9l6vJ+QKvsQ4GRs5yQiwV9ofxf0wupepx4MRUeufJzBAG3Ow==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.0","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.27.0_1785137182587_0.36466140593360064","host":"s3://npm-registry-packages-npm-production"}},"0.28.0":{"name":"@getmcpm/cli","version":"0.28.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.28.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"a5b1e0811c87796adf16f840b3181f66c89f5e42","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.28.0.tgz","fileCount":126,"integrity":"sha512-DCGiGpY8eyt8Zp5QzhMNcVR2Jq4g+sFjUxB+95OnVMucy1DGoEANEB5bMx08mKphEHfpr+B5jbXJ57BN9djgpg==","signatures":[{"sig":"MEYCIQC0OPI76l3Vzdb1iwnmhu079AW48UI6cksXB24ODpx1rAIhAIA5QJAcDJm9/nvC81faqnnuDI/mTQbR4DwCABU+MHbA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.28.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1818255},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.28.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/0bb406e04d2f80cb7fd22e0387611199/getmcpm-cli-0.28.0.tgz","_integrity":"sha512-DCGiGpY8eyt8Zp5QzhMNcVR2Jq4g+sFjUxB+95OnVMucy1DGoEANEB5bMx08mKphEHfpr+B5jbXJ57BN9djgpg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.0","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.28.0_1785923839268_0.8152700713345633","host":"s3://npm-registry-packages-npm-production"}},"0.29.0":{"name":"@getmcpm/cli","version":"0.29.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.29.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"5d1704ba0e2108a24501f907d599dc48bb35ac11","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.29.0.tgz","fileCount":126,"integrity":"sha512-TEsMYEv/uQJO3KasPPwe3o9THZNuA7RdqsWrTsdEf2vUbaPq+BIEKNi2OXKXNIgcIhlKOmkbKnWtQETh9IZD+g==","signatures":[{"sig":"MEQCIADJo/Uz50JCwqxVLoBkqY7wTSii1+g/+Fmilp3LkbkXAiBeC9dQBNmm1aPm29Dsd/5/77rFiMY2ClVu1jmqy3Xnxg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.29.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1856168},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.29.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22.9.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/027ac4ccf082447b8a2082f488e16b49/getmcpm-cli-0.29.0.tgz","_integrity":"sha512-TEsMYEv/uQJO3KasPPwe3o9THZNuA7RdqsWrTsdEf2vUbaPq+BIEKNi2OXKXNIgcIhlKOmkbKnWtQETh9IZD+g==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.16.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.0","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.29.0_1786555674243_0.5419578080853096","host":"s3://npm-registry-packages-npm-production"}},"0.29.1":{"name":"@getmcpm/cli","version":"0.29.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.29.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"af36795e32302641bdd2af97a470ff2f76a9f1a6","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.29.1.tgz","fileCount":126,"integrity":"sha512-dn1gXK0Mt3WVN8QDpgo6Ny9n3xJ4u0QAWSwPyXQWvA8XoAskKli0vyNLQqhXO7M2/IiX01RZPdZ1BY7/QafrVw==","signatures":[{"sig":"MEQCIFS9JAqbqZ0Qi+VrlcJd3xC93kNV2F3YtFMjgVlCALwsAiAjEafVcrOiRu3ycactBDZTxOSaEU3BfIEfSg4OdLsA4w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.29.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1857179},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.29.1.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/26a7ac467a7f55ef504478fabff70373/getmcpm-cli-0.29.1.tgz","_integrity":"sha512-dn1gXK0Mt3WVN8QDpgo6Ny9n3xJ4u0QAWSwPyXQWvA8XoAskKli0vyNLQqhXO7M2/IiX01RZPdZ1BY7/QafrVw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^5.6.2","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.0","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.7.1","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.29.1_1786726522687_0.5264523581309963","host":"s3://npm-registry-packages-npm-production"}},"0.30.0":{"name":"@getmcpm/cli","version":"0.30.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.30.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"0387a69c6e0e80dd5764540669f342bce7373228","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.30.0.tgz","fileCount":126,"integrity":"sha512-IAh7o111UkMbDB3psprsqLhClZ/jaIIftnGWnrUFAJ/aaKCqXDCzPQ1QUTnDVtHyll4YRXSBEnD8f6hp+Q/RFA==","signatures":[{"sig":"MEUCIAI9mgiruuhDQ3l0Fah9z3fH0ALJ7nG2wzzko0g8EvW6AiEA2gvObqVgHA9W2kE2EFjVQy7/HAQkCGHEtRiTZVMyBNU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.30.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1871317},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.30.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/6ab9864d6ce938d77bdde21eb443534a/getmcpm-cli-0.30.0.tgz","_integrity":"sha512-IAh7o111UkMbDB3psprsqLhClZ/jaIIftnGWnrUFAJ/aaKCqXDCzPQ1QUTnDVtHyll4YRXSBEnD8f6hp+Q/RFA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.30.0_1786904057527_0.20095260798592895","host":"s3://npm-registry-packages-npm-production"}},"0.31.0":{"name":"@getmcpm/cli","version":"0.31.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.31.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"71fdf7f4d859a58b9343a50df7d02160c521dbf1","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.31.0.tgz","fileCount":126,"integrity":"sha512-+qwP4FYX4OcqzAUZGj2E321eYqzRRogUBkIW4qbrg2/TjTjXC22e475XPGNBkdoNuhaMYdELU9GhdEF1Ft0eug==","signatures":[{"sig":"MEQCIFffpbFmsC1NBg+XodIYIhueqW3S8Mzaeht6T11fhDJBAiBZnmYEI47KPmCHE0w7SzKhU6Gy84PUVbSxbDThWvLkqQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.31.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1935724},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.31.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/9dab0f442d0baa427321e019a0a8ad8b/getmcpm-cli-0.31.0.tgz","_integrity":"sha512-+qwP4FYX4OcqzAUZGj2E321eYqzRRogUBkIW4qbrg2/TjTjXC22e475XPGNBkdoNuhaMYdELU9GhdEF1Ft0eug==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.1","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.31.0_1787857847139_0.8875332997261305","host":"s3://npm-registry-packages-npm-production"}},"0.32.0":{"name":"@getmcpm/cli","version":"0.32.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.32.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"3c67893be1641486d0759b173d0097471a9dcdbc","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.32.0.tgz","fileCount":126,"integrity":"sha512-u55xUszom+VQerno/MyVvsB9f1kLDn8Eqk+Fysxz0I1BMKGdsoSYEpLxEOurK4w111rSPUbY5RVhUlhAw7Ujbw==","signatures":[{"sig":"MEYCIQCIPKzeXCD1Ikp9QPbdgMMxqYag7Vh4do7g/uGsUIzH5AIhAJeByVLC6BRWr8R57lLYoLCBp+XGYF2AjsCOjIxtWOvd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.32.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1985886},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.32.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/fa9c763996c6a62a773c97245422933f/getmcpm-cli-0.32.0.tgz","_integrity":"sha512-u55xUszom+VQerno/MyVvsB9f1kLDn8Eqk+Fysxz0I1BMKGdsoSYEpLxEOurK4w111rSPUbY5RVhUlhAw7Ujbw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.32.0_1788111944867_0.2718536753881311","host":"s3://npm-registry-packages-npm-production"}},"0.33.0":{"name":"@getmcpm/cli","version":"0.33.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.33.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"4b55d9a802088912a1646b32460abd3a9e31fa85","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.33.0.tgz","fileCount":126,"integrity":"sha512-LeQP0g69erRNEh4a8beOLriWow7RVQECPeJMFG1buPBdJnVLLCF21Uxk076kepUrlEaUuZh3XmxqdFWRr9KmpA==","signatures":[{"sig":"MEUCIFpByJCpa+yZkDmKqA3WriRjJ8r7vpqaq62H/m0DDrYhAiEA/L4SqP3JLZGlJlLBUk9CAEstPImkjhQ4ZhhG4PbDPiM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.33.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1998081},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.33.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/7133d45dd88e963eb2a2a005fcbb9786/getmcpm-cli-0.33.0.tgz","_integrity":"sha512-LeQP0g69erRNEh4a8beOLriWow7RVQECPeJMFG1buPBdJnVLLCF21Uxk076kepUrlEaUuZh3XmxqdFWRr9KmpA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.33.0_1788149530972_0.7218801349641184","host":"s3://npm-registry-packages-npm-production"}},"0.34.0":{"name":"@getmcpm/cli","version":"0.34.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.34.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"a8b94c8d95af588ce85d44746b4834448fd33093","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.34.0.tgz","fileCount":126,"integrity":"sha512-Zj3eTnk/l5abLlcSu7+msKFcptze2hSeuFB2+B4jWq0+dZpS6yCkfWSwPgYyFk+OpkATt0hLhjGfKc78gHkAFA==","signatures":[{"sig":"MEUCIQCNeKf8ggfxfc26Vl0KT5tgZtHJVxpksSUw7PDsfagR8gIgSHP/CKGbWXUSVg6lQ8WkxtGrb1N3v1wbhkQh+GBte/s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.34.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2016104},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.34.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/c21d1af4ba7dae139f03e1bea06b6d67/getmcpm-cli-0.34.0.tgz","_integrity":"sha512-Zj3eTnk/l5abLlcSu7+msKFcptze2hSeuFB2+B4jWq0+dZpS6yCkfWSwPgYyFk+OpkATt0hLhjGfKc78gHkAFA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.34.0_1788164073894_0.8599653004826675","host":"s3://npm-registry-packages-npm-production"}},"0.34.1":{"name":"@getmcpm/cli","version":"0.34.1","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.34.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"e655790bafebd60b1872a498e1eed67ae300dbcd","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.34.1.tgz","fileCount":126,"integrity":"sha512-cbooklVv8vQXvoAKXqSXyy8TqsmTeUgp+49VfwQ2IdWDxXZddCileAO62VI/02Yi5BWYPRyJhImyqLSrrrzt7A==","signatures":[{"sig":"MEYCIQDXoHsaTbcUuU9K6KUbBHuIYX5mWrdBpdGhKzm3DvjutwIhAIeibokkGewvDCl9BoOMSiy5s39v+xielDhyFEEaPisa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.34.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2031963},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.34.1.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/ae2150ebe24445cc61e8b2959734ad49/getmcpm-cli-0.34.1.tgz","_integrity":"sha512-cbooklVv8vQXvoAKXqSXyy8TqsmTeUgp+49VfwQ2IdWDxXZddCileAO62VI/02Yi5BWYPRyJhImyqLSrrrzt7A==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.34.1_1788232872674_0.39756273359733885","host":"s3://npm-registry-packages-npm-production"}},"0.35.0":{"name":"@getmcpm/cli","version":"0.35.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.35.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"344bed640a2ac63fbac2f755e65b669b94f7b352","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.35.0.tgz","fileCount":128,"integrity":"sha512-WCpt5IOa1vl2e1vj2YsraT82O27nLkD2gU1nXiqCMFDgBpO37TQljvls6EVqbSdzzZILopTKOBfes0e5C7YSPw==","signatures":[{"sig":"MEUCIQCGEpe0PFc1MsFeLM+fWTpjpCKDIFf8PgN9ec5zUuROgAIgG43aS/HTv4WWHftrx4aJAjHXRN5vHIzbYB6TiLiO+Zk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.35.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2071639},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.35.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/25578a518eaa5c2c965f6235f61d5192/getmcpm-cli-0.35.0.tgz","_integrity":"sha512-WCpt5IOa1vl2e1vj2YsraT82O27nLkD2gU1nXiqCMFDgBpO37TQljvls6EVqbSdzzZILopTKOBfes0e5C7YSPw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.35.0_1788326362997_0.6133578472243653","host":"s3://npm-registry-packages-npm-production"}},"0.36.0":{"name":"@getmcpm/cli","version":"0.36.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.36.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"aae935f06810700af9b760452202d2f11ae2122e","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.36.0.tgz","fileCount":128,"integrity":"sha512-CRxMia11tx3NQK2soyiRwsXr2bTdYc5dpHrp//nVPU6FpUrqLaxhPEEt6BjRD4/vHLijDLQdKBt+tub29eyOBA==","signatures":[{"sig":"MEUCIGgzBmRJ/Juq3p92L1y2tEtjjdjEtQxa1cK6srNoXWZbAiEAg33i5RxbrN/TRsVywjj2wCsN/rOs1rt8EOYVzbT/l2I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.36.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2089978},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.36.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/c13a575696c8c7af0f27762a65e829c8/getmcpm-cli-0.36.0.tgz","_integrity":"sha512-CRxMia11tx3NQK2soyiRwsXr2bTdYc5dpHrp//nVPU6FpUrqLaxhPEEt6BjRD4/vHLijDLQdKBt+tub29eyOBA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.17.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.19.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.36.0_1788464348805_0.3153871398238297","host":"s3://npm-registry-packages-npm-production"}},"0.37.0":{"name":"@getmcpm/cli","version":"0.37.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.37.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"cf92296d14c93f53713808cc166152fc150689a0","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.37.0.tgz","fileCount":128,"integrity":"sha512-32GyX3pS1tOM/xPWY1voJeH3iuKa/03sJ/jihAjQFdQ2bEQQCxd5JMnhkkPzWs0JhdYKSLCgRVHZqQxsnm5KpQ==","signatures":[{"sig":"MEQCIB6OAyp/TY2C1pNqvT9y79xEo0fmbTgXH0etZyyvPFacAiBDwiOQEij2WuseQkK2iJ9EyucDa8n6ASV9/9tU8kLg7g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.37.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2130930},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.37.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/fdd9d216257c8347862623dd418055ee/getmcpm-cli-0.37.0.tgz","_integrity":"sha512-32GyX3pS1tOM/xPWY1voJeH3iuKa/03sJ/jihAjQFdQ2bEQQCxd5JMnhkkPzWs0JhdYKSLCgRVHZqQxsnm5KpQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.37.0_1788545186015_0.7324642949424507","host":"s3://npm-registry-packages-npm-production"}},"0.38.0":{"name":"@getmcpm/cli","version":"0.38.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.38.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"42c148c634c81ffb0b58e5010981cab845f1d69f","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.38.0.tgz","fileCount":128,"integrity":"sha512-KR9Q4DzITfPCiFC+fsuovGd3JF3TZPkGgiFY7KAFt3hTJZJKBPNkwgxEsluJXqqGsOY0g4p0pIFchYIWhy58iw==","signatures":[{"sig":"MEYCIQD5K+W6eHv8Vb7yjtDdHcVqkGlfulFm+3ze3r5uB8nc4QIhANCY+yguV74mxe9aXCvPaOxh8EEmAvJ2XJK+ek7xbiH+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.38.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2138056},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.38.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/584dcc4e31e0add9f2b846d8eeeca983/getmcpm-cli-0.38.0.tgz","_integrity":"sha512-KR9Q4DzITfPCiFC+fsuovGd3JF3TZPkGgiFY7KAFt3hTJZJKBPNkwgxEsluJXqqGsOY0g4p0pIFchYIWhy58iw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.4.3","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.5.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.38.0_1788752582182_0.2878701228418603","host":"s3://npm-registry-packages-npm-production"}},"0.39.0":{"name":"@getmcpm/cli","version":"0.39.0","keywords":["mcp","model-context-protocol","package-manager","cli","ai","security","claude","cursor","vscode"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.39.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"3c919d7fff017a5ef25de1928e6c1a86f0c9eb15","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.39.0.tgz","fileCount":132,"integrity":"sha512-bkBu7s5fZf3kjDeHuWt4mp1YPVCixZhSW+cw8QlQggRAZ3pbMS7qdmZDr9VH+oislXZGhVTBh/O9izU8d6QtWw==","signatures":[{"sig":"MEUCIQDORrmJP4HDAZHekFfeAQOAaLUS+TPlea6kP+Mgs4Q6mAIgGuce7mJCGMjkUSw/bt4FnlOrwOPgQfyspHa7ao3nW/w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.39.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2167285},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.39.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/97a8e4cd144751736e8eff6b5a82441c/getmcpm-cli-0.39.0.tgz","_integrity":"sha512-bkBu7s5fZf3kjDeHuWt4mp1YPVCixZhSW+cw8QlQggRAZ3pbMS7qdmZDr9VH+oislXZGhVTBh/O9izU8d6QtWw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.5.4","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.0","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.39.0_1788852975565_0.4154768999936169","host":"s3://npm-registry-packages-npm-production"}},"0.39.1":{"name":"@getmcpm/cli","version":"0.39.1","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.39.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"577577c3abcb3517a794590e4127c5c35b17e96a","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.39.1.tgz","fileCount":132,"integrity":"sha512-gc/y6gU6or57NxCsrf/kht+YufaJI4TPgIKEg3djAiCDXFO3SjZEIBe/ytOzpoQ4JHkRKN7DpEPmiIFvwy4xLA==","signatures":[{"sig":"MEYCIQCcE0X/zCNzp9QU0h6+BWuUI7SlLVuU54ftGYhcGxKWuwIhAJOOVNfcoSG52RtrYRE7YPagPb0dHnUZ2cI4qkEfyVIn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.39.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2173519},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.39.1.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/c2336374f3e7d0f9ddc0338202f3edb9/getmcpm-cli-0.39.1.tgz","_integrity":"sha512-gc/y6gU6or57NxCsrf/kht+YufaJI4TPgIKEg3djAiCDXFO3SjZEIBe/ytOzpoQ4JHkRKN7DpEPmiIFvwy4xLA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime, and install them with trust scoring and Sigstore provenance across Claude Desktop, Claude Code, Cursor, VS Code, Win","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.5.4","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.0","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.39.1_1788860823766_0.9478691445154261","host":"s3://npm-registry-packages-npm-production"}},"0.39.2":{"name":"@getmcpm/cli","version":"0.39.2","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.39.2","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"66725cb51089817835e7b5dd7ae1a2d89ae63ec5","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.39.2.tgz","fileCount":132,"integrity":"sha512-HsG1o6LRqiUmPPa9JOQ/hschiM0uYjQQ5K1OKol/34wFHb8RLfWDJmY8oWSUWmE+Bq9d2tlSp3QJ3OtFPnu9KA==","signatures":[{"sig":"MEQCIEo5ionxJVH/gDis7tQnWGKQ9pjBrlYRmterYLrNAN9rAiAfYnZxbNPuN5xqtl9fBrbKzm8W7F2oAkzY8MSC8TyGfQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.39.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2177319},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.39.2.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/f98ca73f39f20bde757832369bf345f5/getmcpm-cli-0.39.2.tgz","_integrity":"sha512-HsG1o6LRqiUmPPa9JOQ/hschiM0uYjQQ5K1OKol/34wFHb8RLfWDJmY8oWSUWmE+Bq9d2tlSp3QJ3OtFPnu9KA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.5.4","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.0","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^4.1.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.39.2_1789147798110_0.36496886179333243","host":"s3://npm-registry-packages-npm-production"}},"0.40.0":{"name":"@getmcpm/cli","version":"0.40.0","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.40.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"4a51fd8034daf14c29105ce6021c1c74c0b42fb0","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.40.0.tgz","fileCount":132,"integrity":"sha512-PF9Cdh/zduHCLDV+q7tstZ24HcMwZ6ySH2v83pAnwDDoB/O06YbZfseNfPRdKE0y48ykzAz8a1/8qW3FTesQsg==","signatures":[{"sig":"MEUCIAy1qrgWwy7wee2R4f0KQzQ24WwFz4U9dBbgCt+62XytAiEAu6Vl/GprDpcVH5zGm2A2ltBhv7GNVyknLAt3Jpseouo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIDNnk8HeqPOMc4ltC4CNP3EXjhaTXE1Tii0UAMMvqd6GAiEAwkIYbps56FEYfn3r39d/4WhQXpOtHRf/w40V51xpfno=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.40.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2212364},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.40.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"tsc --noEmit","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/e17870927fe44d55722ad37ed61bc807/getmcpm-cli-0.40.0.tgz","_integrity":"sha512-PF9Cdh/zduHCLDV+q7tstZ24HcMwZ6ySH2v83pAnwDDoB/O06YbZfseNfPRdKE0y48ykzAz8a1/8qW3FTesQsg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.5.4","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.40.0_1789439349725_0.49750399745417795","host":"s3://npm-registry-packages-npm-production"}},"0.40.1":{"name":"@getmcpm/cli","version":"0.40.1","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.40.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"32d59680deb2eefdb6dc15c731675f21dd036d35","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.40.1.tgz","fileCount":132,"integrity":"sha512-mtdo3o/RfB24tzReUBr+dduCCUtzsvcpZ4PHaz9kZ3V+JlkQyBTyDKT0WlA5qk3ICd5sRWWUIDMbKxWPIO2wrA==","signatures":[{"sig":"MEUCIQCzO798vV4aPxdUN465qmejke/FcouMrjwEy4ojo5DOswIgJDCnG0Ycljy3hU7TSvDw6QydwtQHBHFOaS1HQ6MBxuk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGi+P1sw4MnQ0aEON3RxsFt7/9AmwF1kr2rqev60uuAuAiA0/qADiM4SM2WfWACR1MJ0EvJzZT4n5IHnB70b47Dm6A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.40.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2212732},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.40.1.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/09b36d5926ae46d4ba13bef2010d2e78/getmcpm-cli-0.40.1.tgz","_integrity":"sha512-mtdo3o/RfB24tzReUBr+dduCCUtzsvcpZ4PHaz9kZ3V+JlkQyBTyDKT0WlA5qk3ICd5sRWWUIDMbKxWPIO2wrA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.5.4","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.40.1_1789545909560_0.5654108200455896","host":"s3://npm-registry-packages-npm-production"}},"0.41.0":{"name":"@getmcpm/cli","version":"0.41.0","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.41.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"4ad39383d18c684d8a6e2d0cfce26f904e8d23d7","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.41.0.tgz","fileCount":132,"integrity":"sha512-TEe3D0afM8dkIEW+z/A1diH5ykzppiMvLZBRZHRStzq0j7DQsFJKb3kKn+VOj0bohb+Y1521ny0yYsYpfqQ4SA==","signatures":[{"sig":"MEUCIQDhudV8hlCi2JT5/1xo85M2HVVroEXmrbsgC7tQZ1wGLwIgH0M0WEEbsvT2Z9AHsBAlycQ36csX8Gb9/vWLoSUwDoY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDD7f3VdiOsX8wJxPfm5ReTZtvj/sHLwSgQEcLIpvdptAIgRs68S/g1zTnBr4oywu0dQgreBnixunegglEEGTVbD/w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.41.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2216907},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.41.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/90bf50bb6e539983df55151889dc3cdc/getmcpm-cli-0.41.0.tgz","_integrity":"sha512-TEe3D0afM8dkIEW+z/A1diH5ykzppiMvLZBRZHRStzq0j7DQsFJKb3kKn+VOj0bohb+Y1521ny0yYsYpfqQ4SA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.5.4","yaml":"^2.9.0","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.0","typescript":"^5.9.3","@types/node":"^22.19.19","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.0"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.41.0_1789808520492_0.013115504005144052","host":"s3://npm-registry-packages-npm-production"}},"0.42.0":{"name":"@getmcpm/cli","version":"0.42.0","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.42.0","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"9e094df2fb6e2f436806919996d783f56993d815","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.42.0.tgz","fileCount":132,"integrity":"sha512-+/h3VJYC0WPGvdYlfkt7yNt9sAyhMxpwP0tEOCZGaGx6yZ3hV905D4O4LAJryzxAe5YBHGwSPc0Sa77iGtoKBQ==","signatures":[{"sig":"MEQCIDbTPbDAhX4ifehNtYaGQxVwjA4Xxorum9gcpwCPWygNAiAOwa1tkTvnExghI2s9Ju8VvVnc0j/ipZLtjvNDqb9DNA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIH4INbVqVkN0kfpdb6zLtrtPjyvRid8m24wslZd1HgOtAiEAksPgkdAs3cxLH9l6yohQFHPsSHj5eGwTYSAmZ2LPmO8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.42.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2248108},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.42.0.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/58a4330ddba281511a2c23fa2fc337e5/getmcpm-cli-0.42.0.tgz","_integrity":"sha512-+/h3VJYC0WPGvdYlfkt7yNt9sAyhMxpwP0tEOCZGaGx6yZ3hV905D4O4LAJryzxAe5YBHGwSPc0Sa77iGtoKBQ==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"ora":"^9.4.0","zod":"^4.6.5","yaml":"^2.9.1","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.1","typescript":"^5.9.3","@types/node":"^22.20.3","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.42.0_1789832546427_0.06419278653991278","host":"s3://npm-registry-packages-npm-production"}},"0.42.1":{"name":"@getmcpm/cli","version":"0.42.1","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.42.1","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"d6be4124d9c36db2f44142413712ee019f81669d","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.42.1.tgz","fileCount":132,"integrity":"sha512-zLFixHgiW5xw0qPyHM7xspDjUGPkxszgKKOnPI8qlIH+h1QRMksyOCeX1y3INBbmj5HaMlYu7bAg5jzhnwDtzw==","signatures":[{"sig":"MEUCICgyR+xGSbOqtbiz9ziX1rMYMZIGI/k99u12Jw8jn3SfAiEAzWgo3isfLQga1w7LSmvKqUNvb9iUJXZXLp2Uq8tzWaE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIAVVlBaAQESGaqTTEbUHmG+4hcP0nslBcYfZURu4hjopAiA/PrqdVafjtVtG8ej1DuH5TSTut+ZHNWp02y8EP20hQA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.42.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2250650},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.42.1.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/813ecc2ef49414bf939370d794cb63e5/getmcpm-cli-0.42.1.tgz","_integrity":"sha512-zLFixHgiW5xw0qPyHM7xspDjUGPkxszgKKOnPI8qlIH+h1QRMksyOCeX1y3INBbmj5HaMlYu7bAg5jzhnwDtzw==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"ora":"^9.4.0","zod":"^4.6.5","yaml":"^2.9.1","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.1","fast-check":"^4.10.2","typescript":"^5.9.3","@types/node":"^22.20.3","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.42.1_1790183091962_0.3506775144057228","host":"s3://npm-registry-packages-npm-production"}},"0.42.2":{"name":"@getmcpm/cli","version":"0.42.2","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.42.2","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"ea85684293b0ad6237bf0d697bb15c404d7d8ce9","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.42.2.tgz","fileCount":132,"integrity":"sha512-HruQPEXfRgztw2upEZgMDnGJLKyoA0i+ziHeNdJPBe1hSUP0zY0NaTmCek9RrBAAA6HH85E8zBRv/SlYgsZlrg==","signatures":[{"sig":"MEUCIQCTcOpH7b9fSWe6dz/g+6mP65ey1SWLveH8WQvQ/GznAQIgDmT/p3Q5dRRvAPuMoNDD7jiX2Ca3S5+opVkf6+S7lKs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIDZk7PXv/yji2HNyUuHHYvhTgTcpWBMucCJqYni9a4bsAiEA/bS1wk6K6zoE7xoCq5ku8X4CG7lytmLhXRWnQRtn/3w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.42.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2261814},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.42.2.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/fb88958d951598650f4c1737bf1559ec/getmcpm-cli-0.42.2.tgz","_integrity":"sha512-HruQPEXfRgztw2upEZgMDnGJLKyoA0i+ziHeNdJPBe1hSUP0zY0NaTmCek9RrBAAA6HH85E8zBRv/SlYgsZlrg==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"ora":"^9.4.0","zod":"^4.6.5","yaml":"^2.9.1","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.1","fast-check":"^4.10.2","typescript":"^5.9.3","@types/node":"^22.20.3","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.42.2_1790267539692_0.48667460963758447","host":"s3://npm-registry-packages-npm-production"}},"0.42.3":{"name":"@getmcpm/cli","version":"0.42.3","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.42.3","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"9cde27b32812efafec53ece373baff7f3141c8b1","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.42.3.tgz","fileCount":132,"integrity":"sha512-scbViKK/Jqhga/FC2g+UTIh1qv+6ahYA77AOCvY2l+CkGjRwGM3GP3+DhnFtrMIUEFCdxtStYs2fO0XUlFViFA==","signatures":[{"sig":"MEUCICAI+O3D/ZxKFGLCnJb3wSRQnzkLMDxjC2TsvlDQ604FAiEAt3Z3vdj9qLYpB6gI6bqPWxYexpAxLo0L+BxiuvFCe04=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIA768j5V/JvXLSa62yZB9Ii5kO/o0IccyyvuF4lGwYEEAiAnrFllNhnjonHJXDh2VbBT4jMaH1jtqJZuU5kmFJLHUQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.42.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2266092},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.42.3.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/56a154142e8dd31916c7253cc18841b7/getmcpm-cli-0.42.3.tgz","_integrity":"sha512-scbViKK/Jqhga/FC2g+UTIh1qv+6ahYA77AOCvY2l+CkGjRwGM3GP3+DhnFtrMIUEFCdxtStYs2fO0XUlFViFA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"ora":"^9.4.0","zod":"^4.6.5","yaml":"^2.9.1","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.1","fast-check":"^4.10.2","typescript":"^5.9.3","@types/node":"^22.20.3","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.42.3_1790438406736_0.5673908245651387","host":"s3://npm-registry-packages-npm-production"}},"0.42.4":{"name":"@getmcpm/cli","version":"0.42.4","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.42.4","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"b8c0197aea276d320d5ef2eb0ade1d86ee952904","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.42.4.tgz","fileCount":132,"integrity":"sha512-fzbbi7fGqAyRCVh7n2SieN2hWTeUXpn12s4DHMO4x9+GApSUeVSEMMt7oNuz72oHCyfXUY/VGQqvx/p/PjdIVA==","signatures":[{"sig":"MEUCIA+at2Hl/dUsrbvBT5ZHO2mGPCTabr7CU3e/0iGQYbU2AiEArovlP3pKAVEuCpPjP3UXjuQ9yejIn7ny52zjO4loDTo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDfxxVbO28TmmIA72kN8tYXJQP6LvJRZdstfr1XVifVkwIgCK7cUEVD2JBVS1GKf2vigUdX0F8kUIHe5iJMDJBn/ew=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.42.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2286930},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.42.4.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/37e42ca4f03be35da370f4d3fe3e1eff/getmcpm-cli-0.42.4.tgz","_integrity":"sha512-fzbbi7fGqAyRCVh7n2SieN2hWTeUXpn12s4DHMO4x9+GApSUeVSEMMt7oNuz72oHCyfXUY/VGQqvx/p/PjdIVA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"ora":"^9.4.0","zod":"^4.6.5","yaml":"^2.9.1","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.1","fast-check":"^4.10.2","typescript":"^5.9.3","@types/node":"^22.20.3","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.42.4_1790565919543_0.37522786644349804","host":"s3://npm-registry-packages-npm-production"}},"0.42.5":{"name":"@getmcpm/cli","version":"0.42.5","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"author":"","license":"MIT","_id":"@getmcpm/cli@0.42.5","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"homepage":"https://github.com/getmcpm/cli#readme","bugs":{"url":"https://github.com/getmcpm/cli/issues"},"bin":{"mcpm":"dist/index.js"},"dist":{"shasum":"ace6b1b519f9946e49c580425d2a096a56c32636","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.42.5.tgz","fileCount":132,"integrity":"sha512-ziIiFAmBG7Fqp+4QOlNX8CWZlyX1NiMqdxvCQ+t396flDBx3kwLXgUM0XyvUS6ubr9Zlmhw4Knf/O1VfjjSq2Q==","signatures":[{"sig":"MEQCICyfw75kts7TnSECYxiv/UUMTx0IBHBizeqleyhSt0eaAiBKkF76EKzfcmQtTS/Ak83TkqdTZfxWE7opDSFEnUkwNw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAzNcrfQWOIwlXwDsT9rqJsjiTPYPXZ0Ap78kC/Ldn7UAiEA+L5S7HtkRlSCAlt1oVtfB4tBAFyDAjaC1SHQtz0YgP8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.42.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2295669},"main":"./dist/index.js","type":"module","_from":"file:getmcpm-cli-0.42.5.tgz","types":"./dist/index.d.ts","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ea04afeb-053c-4527-b435-1eee19e1f7be"}},"_resolved":"/tmp/a4d5d8c58a8dd35fb519aca348883ee0/getmcpm-cli-0.42.5.tgz","_integrity":"sha512-ziIiFAmBG7Fqp+4QOlNX8CWZlyX1NiMqdxvCQ+t396flDBx3kwLXgUM0XyvUS6ubr9Zlmhw4Knf/O1VfjjSq2Q==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"_nodeVersion":"24.21.0","dependencies":{"ora":"^9.4.0","zod":"^4.6.5","yaml":"^2.9.1","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.1","fast-check":"^4.10.2","typescript":"^5.9.3","@types/node":"^22.20.3","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.42.5_1790621839700_0.28279886360158946","host":"s3://npm-registry-packages-npm-production"}},"0.43.0":{"_id":"@getmcpm/cli@0.43.0","bin":{"mcpm":"dist/index.js"},"bugs":{"url":"https://github.com/getmcpm/cli/issues"},"dist":{"shasum":"7e37ff73a49b9abb8b576dcee49246a8b465629a","tarball":"https://registry.npmjs.org/@getmcpm/cli/-/cli-0.43.0.tgz","fileCount":132,"integrity":"sha512-zm9T+MEmsvGaSKJyFgsJia6AfatJZFoVbVZgPwbE7ZSMeXu7mcH07BZbc67yI2rvrixQ/Jpt71fqyLc3WBNBqA==","signatures":[{"sig":"MEYCIQCvKUTMF+QKor/Mcbr5ypGcbjEvAMHl6J3IZsgEAyG9HAIhAIwzkcRH6d59pkLN9RCnJzGlJoKuHRvl0TEco07J5jUg","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDaWqIGQSUIDedcmyaZbbqGw+xSiU8MCahCSDxFxd4+gQIgayRgY5dXjW0/Flb1Iy0DcGlTVOz5jeyMLsvlIZeZMHY="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@getmcpm%2fcli@0.43.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2327552},"main":"./dist/index.js","name":"@getmcpm/cli","type":"module","_from":"file:getmcpm-cli-0.43.0.tgz","types":"./dist/index.d.ts","author":"","engines":{"node":"^22.22.2 || ^24.15.0 || >=26.0.0"},"license":"MIT","mcpName":"io.github.getmcpm/cli","scripts":{"dev":"tsup --watch","lint":"pnpm run typecheck","test":"vitest run","build":"tsup","clean":"rm -rf dist coverage","typecheck":"tsc --noEmit && tsc -p tsconfig.tooling.json","test:watch":"vitest","test:coverage":"vitest run --coverage","dogfood:confine":"pnpm build && bash scripts/dogfood-confine.sh","dogfood:release":"bash scripts/dogfood-release.sh"},"version":"0.43.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"ea04afeb-053c-4527-b435-1eee19e1f7be"}},"homepage":"https://github.com/getmcpm/cli#readme","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"_resolved":"/tmp/b6c97382abc7808873b42b25a8fefe96/getmcpm-cli-0.43.0.tgz","_integrity":"sha512-zm9T+MEmsvGaSKJyFgsJia6AfatJZFoVbVZgPwbE7ZSMeXu7mcH07BZbc67yI2rvrixQ/Jpt71fqyLc3WBNBqA==","repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"_npmVersion":"11.19.0","description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","directories":{},"maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"_nodeVersion":"24.21.0","dependencies":{"ora":"^9.4.0","zod":"^4.6.5","yaml":"^2.9.1","chalk":"^6.0.0","semver":"^7.8.1","commander":"^15.0.0","cli-table3":"^0.6.5","proper-lockfile":"^4.1.2","@sigstore/bundle":"^5.0.0","@sigstore/verify":"^4.1.2","@inquirer/prompts":"^8.7.2","@types/proper-lockfile":"^4.1.4","@sigstore/protobuf-specs":"^0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^5.0.1","fast-check":"^4.10.2","typescript":"^5.9.3","@types/node":"^22.20.3","@types/semver":"^7.8.0","@vitest/coverage-v8":"^5.0.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cli_0.43.0_1790745787243_0.4090572033545472"}}},"time":{"created":"2026-03-29T17:44:42.757Z","modified":"2026-09-30T05:23:07.741Z","0.1.0":"2026-03-29T17:44:43.210Z","0.1.1":"2026-03-30T03:28:23.006Z","0.1.2":"2026-03-30T08:19:05.443Z","0.1.3":"2026-03-30T10:35:41.608Z","0.2.0":"2026-04-05T06:17:23.287Z","0.2.1":"2026-04-05T06:31:14.782Z","0.2.2":"2026-04-05T06:53:26.203Z","0.3.0":"2026-04-05T18:00:17.192Z","0.3.1":"2026-04-06T08:32:59.207Z","0.3.2":"2026-04-06T10:26:10.237Z","0.3.3":"2026-05-11T18:19:25.931Z","0.4.0":"2026-05-12T14:38:18.582Z","0.5.0":"2026-05-17T08:35:07.426Z","0.6.0":"2026-06-01T08:23:26.386Z","0.7.0":"2026-06-01T17:26:05.898Z","0.7.1":"2026-06-02T08:24:10.451Z","0.8.0":"2026-06-02T15:55:16.522Z","0.8.1":"2026-06-08T16:33:44.637Z","0.9.0":"2026-06-10T08:38:24.495Z","0.10.0":"2026-06-14T07:28:51.442Z","0.10.1":"2026-06-14T10:50:10.492Z","0.11.0":"2026-06-17T18:26:59.812Z","0.12.0":"2026-06-19T07:18:13.188Z","0.12.1":"2026-06-19T07:47:05.110Z","0.13.0":"2026-06-19T16:29:24.288Z","0.14.0":"2026-06-19T18:14:03.419Z","0.15.0":"2026-06-22T09:45:05.446Z","0.16.0":"2026-07-02T10:23:10.205Z","0.17.0":"2026-07-03T03:00:17.328Z","0.18.0":"2026-07-03T04:18:58.946Z","0.19.0":"2026-07-03T11:15:54.595Z","0.20.0":"2026-07-14T02:24:10.066Z","0.20.1":"2026-07-16T03:46:07.045Z","0.21.0":"2026-07-16T15:24:02.673Z","0.22.0":"2026-07-18T07:41:31.497Z","0.23.0":"2026-07-20T04:22:57.580Z","0.24.0":"2026-07-22T18:03:40.750Z","0.25.0":"2026-07-25T13:24:02.838Z","0.26.0":"2026-07-25T15:05:12.670Z","0.26.1":"2026-07-25T15:24:54.451Z","0.26.2":"2026-07-25T15:41:03.574Z","0.26.3":"2026-07-25T16:14:09.178Z","0.27.0":"2026-07-27T07:26:22.759Z","0.28.0":"2026-08-05T09:57:19.413Z","0.29.0":"2026-08-12T17:27:54.437Z","0.29.1":"2026-08-14T16:55:22.915Z","0.30.0":"2026-08-16T18:14:17.690Z","0.31.0":"2026-08-27T19:10:47.316Z","0.32.0":"2026-08-30T17:45:45.027Z","0.33.0":"2026-08-31T04:12:11.138Z","0.34.0":"2026-08-31T08:14:34.057Z","0.34.1":"2026-09-01T03:21:12.856Z","0.35.0":"2026-09-02T05:19:23.218Z","0.36.0":"2026-09-03T19:39:08.994Z","0.37.0":"2026-09-04T18:06:26.208Z","0.38.0":"2026-09-07T03:43:02.359Z","0.39.0":"2026-09-08T07:36:15.711Z","0.39.1":"2026-09-08T09:47:03.962Z","0.39.2":"2026-09-11T17:29:58.292Z","0.40.0":"2026-09-15T02:29:09.832Z","0.40.1":"2026-09-16T08:05:09.681Z","0.41.0":"2026-09-19T09:02:00.631Z","0.42.0":"2026-09-19T15:42:26.552Z","0.42.1":"2026-09-23T17:04:52.072Z","0.42.2":"2026-09-24T16:32:19.799Z","0.42.3":"2026-09-26T16:00:06.872Z","0.42.4":"2026-09-28T03:25:19.659Z","0.42.5":"2026-09-28T18:57:19.877Z","0.43.0":"2026-09-30T05:23:07.359Z"},"bugs":{"url":"https://github.com/getmcpm/cli/issues"},"license":"MIT","homepage":"https://github.com/getmcpm/cli#readme","keywords":["mcp","model-context-protocol","mcp-security","mcp-server","package-manager","cli","security","prompt-injection","tool-poisoning","llm-security","ai-agents","supply-chain-security","sigstore","claude","claude-code","cursor","vscode","windsurf","gemini-cli"],"repository":{"url":"git+https://github.com/getmcpm/cli.git","type":"git"},"description":"MCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Gemini CLI.","maintainers":[{"name":"m1ngshum","email":"wwwdycg@gmail.com"}],"readme":"<p align=\"center\">\n  <picture>\n    <source media=\"(prefers-color-scheme: dark)\" srcset=\"./assets/banner-dark.svg\">\n    <source media=\"(prefers-color-scheme: light)\" srcset=\"./assets/banner-light.svg\">\n    <img alt=\"mcpm — MCP security guard and package manager for Model Context Protocol servers\" src=\"./assets/banner-light.svg\" width=\"680\">\n  </picture>\n</p>\n\n# mcpm — MCP security guard and package manager\n\n**Block prompt injection, tool poisoning, rug-pulls and credential theft in Model Context Protocol (MCP) servers -- at runtime, on your machine.** Your AI agent trusts every MCP server it talks to; mcpm scores each install, verifies its supply chain with Sigstore, pins every tool definition, and inspects every tool call through a local relay -- with an opt-in OS sandbox on macOS. No cloud, no account, no LLM in the enforcement path.\n\n**Everything runs on your machine.** No account, no mcpm backend, no telemetry -- the guard is a local stdio relay, and trust scores are computed locally with no model and no remote verdict (the 40-point static-scan bucket is deterministic regex/structural checks you can read yourself; the rest is a local health check, registry metadata, and an external scanner only if you name one). Commands that resolve, audit or re-verify a server do reach the public MCP registry and npm -- nothing reaches an mcpm server.\n\n[![npm version](https://img.shields.io/npm/v/@getmcpm/cli)](https://www.npmjs.com/package/@getmcpm/cli)\n[![license](https://img.shields.io/github/license/getmcpm/cli)](./LICENSE)\n[![tests](https://img.shields.io/github/actions/workflow/status/getmcpm/cli/ci.yml?label=tests)](https://github.com/getmcpm/cli/actions)\n[![Known Vulnerabilities](https://snyk.io/advisor/npm-package/@getmcpm/cli/badge.svg)](https://snyk.io/advisor/npm-package/@getmcpm/cli)\n\n---\n\nThe risky part of an MCP server doesn't show up at install -- it shows up while your agent is running: prompt injection hidden in a tool's output, a server that quietly rewrites its tools after you approved them, a sampling request that smuggles instructions into your model. Being listed in a registry is not a safety signal -- in 2026 a proof-of-concept poisoned server was [accepted by 9 of 11 public registries and marketplaces](https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/). So mcpm scores every install for hardcoded secrets, prompt injection, and typosquatting -- then runs a live guard between your AI client and each server, pinning tool definitions against rug-pulls and blocking injection before it reaches the model.\n\n**You don't have to take our word for any of that.** Guards are easy to claim and hard to check, so the measuring stick is public: [**mcp-guardbench**](https://github.com/getmcpm/mcp-guardbench) is a guard-agnostic benchmark -- versioned attack and benign cases, an open schema, and a runner that scores *any* MCP guard through its own published CLI. mcpm is scored the same way as everyone else, by shelling out to `mcpm guard inspect`, never by importing its own engine.\n\nThe corpus isn't mcpm's own test fixtures anymore. As of [corpus v5](https://github.com/getmcpm/mcp-guardbench#corpus-v5---the-first-live-in-the-wild-campaign-case-deadbugz) (57 cases: 33 attack, 20 benign, 4 warn-and-forward) it includes seven cases rebuilt from real, publicly disclosed CVEs in third-party MCP servers, plus three cases reproducing Deadbugz, an active in-the-wild MCP supply-chain campaign -- the third contributed externally by [@vguillaume8](https://github.com/vguillaume8) (see below). The published top row: `@getmcpm/cli@0.42.5` scores 86.5% recall / 0.0% false-positive rate / 100% precision; every mcpm row is measured through that exact version's published CLI. That is a baseline, not a boast -- mcpm's misses are published on the same page as its wins, including all three Deadbugz-derived cases (below).\n\n**How this differs.** [Microsoft APM](https://github.com/microsoft/apm) is the closest analog -- an npm-style installer and lockfile for MCP servers (and skills/prompts/plugins) across 9+ clients -- but its own docs say it [produces no signed attestation](https://github.com/microsoft/apm/blob/main/docs/src/content/docs/enterprise/governance-guide.md) for its install/audit gates, list Sigstore verification as [out of scope until v0.2](https://github.com/microsoft/apm/blob/main/docs/src/content/docs/specs/openapm-v0.1.md), and give its policy schema [no fields for runtime permissions or agent sandboxing](https://github.com/microsoft/apm/blob/main/docs/src/content/docs/enterprise/apm-policy.md). Smithery, [acquired by Arcade.dev](https://www.arcade.dev/blog/smithery-joins-arcade/) (2026-08-05), is a hosted-execution lane, not a local CLI. OSS runtime proxies like [McpVanguard](https://pypi.org/project/mcp-vanguard/) and [MCP Firewall](https://github.com/evalops/mcp-firewall) inspect and enforce policy at runtime, and MCP Firewall also offers containment -- but neither adds install-time trust scoring or Sigstore-verified supply-chain checks. (mcp-guardbench carries a McpVanguard row, but its own README says that row is not comparable to the mcpm rows and should not be quoted as a head-to-head: it drives one offline harness layer rather than McpVanguard's real proxy deployment, and abstains on roughly half the corpus.) What mcpm combines is a trust score, offline Sigstore provenance verification, and a runtime relay with pin/drift plus OS confinement in a single local, account-free tool.\n\n<p align=\"center\">\n  <img src=\"./assets/demo.gif\" alt=\"mcpm demo\" width=\"680\">\n</p>\n\n## Quick start\n\nInstall with the package manager you already use:\n\n| Method | Command |\n|---|---|\n| **npm** (global) | `npm install -g @getmcpm/cli` |\n| **npx** (no install) | `npx @getmcpm/cli <command>` |\n| **pnpm** | `pnpm add -g @getmcpm/cli` |\n| **mise** | `mise use -g npm:@getmcpm/cli` |\n\n**Requires Node `^22.22.2 || ^24.15.0 || >=26.0.0`** — that is **22.22.2+, 24.15.0+ or\n26+**, the intersection of what every runtime dependency itself supports. Everything\nelse is excluded, 23.x and 25.x included. npm warns `EBADENGINE` and fails outright\nunder `--engine-strict`; pnpm installs silently and exits 0 unless you set\n`engine-strict=true`, so there an unsupported Node surfaces as a runtime error rather\nthan an install one.\n\nThe binary is `mcpm`. **Heads up:** the `mcpm` Homebrew formula is a *different,\nunrelated* project ([mcpm.sh](https://mcpm.sh)) — install this mcpm via\nnpm/npx/pnpm/mise above (all resolve the scoped `@getmcpm/cli` package, so there's\nno name collision). A dedicated Homebrew tap is deferred; see\n[`docs/DISTRIBUTION.md`](docs/DISTRIBUTION.md).\n\n```bash\nmcpm search filesystem\nmcpm info io.github.domdomegg/filesystem-mcp\nmcpm install io.github.domdomegg/filesystem-mcp\n```\n\n## Features\n\n### Search the MCP registry\n\nQuery the official MCP Registry and see results with trust indicators.\n\n```\n$ mcpm search filesystem\n\n  Name                                    Description                   Version  Transport  Status\n  io.github.domdomegg/filesystem-mcp       File system access via MCP    1.4.0    stdio      active\n  io.github.Digital-Defiance/mcp-filesystem Read-only filesystem server  0.9.2    stdio      active\n  ...\n```\n\nSearch shows registry lifecycle status, not a trust score -- it is a fast discovery list and does not run the scanner per result. Computed trust lives in `mcpm why`, `info`, `install`, and `audit`.\n\n### Install with trust assessment\n\nEvery install runs a metadata-based trust assessment before writing config.\n\n```\n$ mcpm install io.github.domdomegg/filesystem-mcp\n\n  ███████████████░░░░░ 57/80 CAUTION\n    ├─ Health check: not yet run\n    ├─ Tool descriptions: score 32/40\n    ├─ Package: publisher verification passed\n    └─ External scan: not available (set MCPM_EXTERNAL_SCANNER for deeper analysis)\n\n  Install to Claude Desktop? (Y/n)\n```\n\n### Audit installed servers\n\nScan everything you have installed. Get a trust report.\n\n```\n$ mcpm audit\n\n┌─────────────────────────────────────────────┬─────────────────────────┬─────────────────┬──────────┐\n│ Server                                      │ Score                   │ Level           │ Findings │\n├─────────────────────────────────────────────┼─────────────────────────┼─────────────────┼──────────┤\n│ servers-filesystem                          │ ████████░░ 62/80        │ clean · not run │ 0        │\n├─────────────────────────────────────────────┼─────────────────────────┼─────────────────┼──────────┤\n│ servers-github                              │ ████████░░ 60/80        │ caution         │ 1        │\n├─────────────────────────────────────────────┼─────────────────────────┼─────────────────┼──────────┤\n│ servers-fetch                               │ ███████░░░ 52/80        │ caution         │ 2        │\n├─────────────────────────────────────────────┼─────────────────────────┼─────────────────┼──────────┤\n│ some-sketchy-server                         │ ██░░░░░░░░ 16/80        │ risky           │ 5        │\n└─────────────────────────────────────────────┴─────────────────────────┴─────────────────┴──────────┘\n4 servers scanned, 0 safe, 1 clean · not run, 2 caution, 1 risky\n```\n\n`audit` never executes a server, so the 30-point health-check bucket scores a flat 15 and\n**62/80 is the ceiling** — no server can be rated `safe` here. A server that cleared every\ncheck that actually ran reads `clean · not run` instead. `servers-github` scores 60 because\nan `npx -y` launcher draws one `low` install-script finding, which is also why it reads\n`caution` rather than `clean · not run`: that label requires the scan to have found\n*nothing*, not merely a top-band score.\n\n`audit` also does not apply the **release-age cooldown** finding that `why`, `install`,\n`up` and `lock` do (`src/scanner/cooldown.ts` is an install-gate signal — it exists to\narm `install --min-release-age` / `policy.minReleaseAgeHours`, and re-penalising an\n*already-installed* server for being young is not a decision `audit` is making). For a\nrelease under 24 h old that is a `medium`, so `mcpm audit` can read **5 points higher**\nthan `mcpm why` for the same server at the same moment. Neither number is wrong; they\nanswer different questions.\n\n### Cross-IDE support\n\nOne tool for all your AI clients. mcpm reads and writes the correct config format for each.\n\n```\n$ mcpm list\n\n  Client            Server Name                  Status     Command/URL\n  Claude Desktop    servers-filesystem           active     npx -y servers-filesystem\n  Claude Desktop    servers-github               active     npx -y servers-github\n  Cursor            servers-fetch                disabled   npx -y servers-fetch\n```\n\n### Doctor: check your MCP setup health\n\nFind misconfigurations, missing runtimes, broken servers, and plaintext secrets pasted into client config.\n\n```\n$ mcpm doctor\n\nmcpm doctor\n\n  ✓ Claude Desktop — config found, 3 servers\n  ✗ Claude Code — config not found\n  ✓ Cursor — config found, 1 server\n  ✗ VS Code — config not found\n  ✗ Windsurf — config not found\n  ✗ Gemini CLI — config not found\n\nRuntimes:\n  ✓ npx available\n  ✓ uvx available\n  ✓ docker available\n\nCross-client (advisory):\n  ⚠ servers-filesystem — in claude-desktop; missing in cursor\n  ⚠ servers-github — in claude-desktop; missing in cursor\n  Run `mcpm sync --check` for the full matrix (advisory, not a failure).\n\nPlaintext secrets (advisory):\n  ⚠ claude-desktop · servers-github · env 'GITHUB_TOKEN' — GitHub token\n  Move env secrets to the encrypted store: `mcpm secrets set <server> <KEY>` or re-install with `--secrets keychain`.\n\nNo critical issues found.\n```\n\nThe plaintext-secret scan reports the key name and label only — never the value — and skips values already stored as `mcpm:keychain:` placeholders. It's advisory (never fails `doctor`).\n\n### Stack files: docker-compose for MCP\n\nDeclare your project's MCP servers in `mcpm.yaml`, lock versions with trust snapshots, and let every team member replicate the setup with one command.\n\n```bash\nmcpm export > mcpm.yaml          # dump current setup\nmcpm lock                        # resolve versions + trust snapshot\nmcpm up                          # install everything from mcpm.yaml\nmcpm diff                        # compare installed vs declared state\n```\n\nStack files include a trust policy. If a server's trust score drops below the threshold, `mcpm up` blocks it.\n\n```yaml\nversion: \"1\"\npolicy:\n  minTrustScore: 60\n  blockOnScoreDrop: true\nservers:\n  io.github.domdomegg/filesystem-mcp:\n    version: \"^1.0.0\"\n  io.github.modelcontextprotocol/servers-github:\n    version: \"1.2.3\"\n    env:\n      GITHUB_TOKEN: { required: true, secret: true }\n```\n\n### Scaffold a stack file\n\nStart a new project's MCP setup in one command. `mcpm init` writes a starter `mcpm.yaml` you fill in with servers from `mcpm search`.\n\n```\n$ mcpm init\n\n  Created mcpm.yaml.\n\n  Next steps:\n    mcpm search <query>   find MCP servers in the registry\n    edit mcpm.yaml        add them under `servers:`\n    mcpm lock             resolve and lock versions\n    mcpm up               install from the stack file\n```\n\nIt refuses to clobber an existing `mcpm.yaml` (pass `--force` to overwrite). mcpm deliberately doesn't ship curated packs — blessing specific community servers is a trust decision a security tool shouldn't bake in.\n\n## Trust score\n\nThe trust score is a 0-100 assessment based on publicly available metadata. It is **not** a source code audit.\n\nWhat it checks:\n\n| Component | Points | What it measures |\n|---|---|---|\n| Health check | 0-30 | Can the server start and respond to `list_tools`? |\n| Static scan | 0-40 | Regex-based detection of hardcoded secrets, prompt injection patterns in tool descriptions, typosquatting in package names, suspicious argument schemas |\n| External scanner | 0-20 | Results from a third-party scanner you have installed, opt-in via `MCPM_EXTERNAL_SCANNER` (off by default) |\n| Registry metadata | 0-10 | Verified publisher, publish date, download count (capped to 0 when critical findings present) |\n\nLevels are a **ratio** of the points available, not absolute: **safe** at 80% of `maxPossible` or better, **caution** at 50-79%, **risky** below 50%. With no external scanner (`maxPossible` 80) that puts safe at 64 points, not 80.\n\n`mcpm audit` shows **`clean · not run`** where the server cleared every check that actually ran and the only unmeasured component is the health check — audit never executes servers, so that bucket scores a flat 15/30 and would otherwise drag every flawless server into **caution**. It is a statement about what mcpm did (found nothing, ran nothing), deliberately weaker than **safe**, which is reserved for servers whose health check really ran.\n\nWithout an external scanner, the maximum possible score is 80/100 and the bucket is dropped from the total rather than counted as a failure. The static scan catches common patterns but cannot detect all vulnerabilities. Treat the score as a signal, not a guarantee.\n\n**External scanning is opt-in and mcpm never downloads a scanner.** Set `MCPM_EXTERNAL_SCANNER` to the path or name of a scanner you have already installed. mcpm probes it with `<scanner> --version` and, if that exits 0, scans each server with `<scanner> --json <server-name>`, expecting `{\"findings\": [...]}` on stdout. A scanner whose output cannot be read is treated as **absent** rather than as a clean pass, so the bucket leaves the total instead of silently earning 20/20 — otherwise any binary that exits 0 would raise trust scores.\n\nPackage runners (`npx`, `uvx`, `pipx`, `docker`, shells, …) are refused, including via symlink or a runner's `-cli.js` entrypoint. Be clear about what that is worth: it is a **footgun guard**, not a security boundary. Anyone who can set this variable can usually set `PATH` or drop a file too. What it buys is that a pasted `npx …` recipe — or a future mcpm default drifting back toward one — cannot quietly re-create the fetch-and-execute vector this seam was rebuilt to remove.\n\nNo scanner is recommended here because none evaluated so far fits: `snyk/agent-scan` (the actively maintained successor to Invariant Labs' mcp-scan) does accept a bare registry coordinate as input, but it converts that coordinate into an `npx`/`uvx`/`docker run` invocation and starts the server to inspect it live — conflicting with mcpm's install-then-verify design at the two call sites (install, lock) where this runs before you've committed to installing — and it requires a Snyk account and `SNYK_TOKEN`, with no offline mode. See `src/scanner/tier2.ts`'s header comment for the full evaluation.\n\nThose 20 points **inform the score but cannot clear a safety floor.** The MCP server surface (`mcpm_install`, `mcpm_up`, `mcpm_setup`) enforces a hard trust floor of 25 that no caller-supplied value may lower — and since `MCPM_EXTERNAL_SCANNER` names an arbitrary executable, a two-line script printing `{\"findings\": []}` is caller-supplied input too. So the floor is compared against mcpm's own evidence only: health check + static scan + registry metadata, out of 80. The exclusion is one-directional — a scanner reporting a critical finding still drags a server *down* through the floor (via the registry-metadata cap), it just can't push one up through it. Your own `--min-trust` threshold, a stack file's `policy.minTrustScore`, and `mcpm audit --fix` are unaffected: there the same person picks both the threshold and the scanner. `audit --fix` is also the one score gate that *deletes* rather than refuses, so subtracting the bucket there would remove more servers, not fewer.\n\n## Commands\n\n| Command | Description |\n|---|---|\n| `mcpm search <query>` | Search the MCP registry for servers |\n| `mcpm install <name>` | Install an MCP server from the registry |\n| `mcpm info <name>` | Show full details for an MCP server |\n| `mcpm list` | List all installed MCP servers across detected AI clients |\n| `mcpm remove <name>` | Remove an MCP server from client config(s) |\n| `mcpm audit` | Scan all installed servers and produce a trust report (`--json`, `--sarif` for GitHub code-scanning) |\n| `mcpm update` | Check for newer versions and update installed servers |\n| `mcpm outdated` | Show version drift for installed servers (use `mcpm audit` for current security findings) |\n| `mcpm secrets` | Manage MCP server credentials (AES-GCM encrypted at rest; key held in the OS keychain — macOS Keychain / libsecret / Windows DPAPI — so a copied store can't be decrypted off-machine, with a machine-derived-key fallback where no keychain is available). `mcpm secrets migrate` upgrades older entries |\n| `mcpm publish scaffold` | Create a .mcpm-publish.yaml manifest interactively |\n| `mcpm publish check` | Dry-run: show trust score and what would be submitted (`--json` emits the exact request body) |\n| `mcpm publish` | Submit to the official MCP registry (requires `GITHUB_TOKEN`/`MCPM_TOKEN`, or `--github-oidc` in GitHub Actions with `id-token: write`) |\n| `mcpm doctor` | Check MCP setup health and report issues (`--json` structured model, `--report` redacted paste-for-bug-reports snapshot) |\n| `mcpm init` | Scaffold a starter `mcpm.yaml` stack file in the current directory |\n| `mcpm disable <name>` | Disable an MCP server without removing it from config |\n| `mcpm enable <name>` | Re-enable a previously disabled MCP server |\n| `mcpm import` | Import existing MCP servers from client config files |\n| `mcpm alias` | Create short aliases for long MCP server names |\n| `mcpm export` | Export installed servers as an mcpm.yaml stack file |\n| `mcpm lock` | Resolve versions and create mcpm-lock.yaml with trust snapshots (+ npm provenance identity, WARNs on drift) |\n| `mcpm up` | Install all servers from mcpm.yaml with trust verification |\n| `mcpm verify` | Repo-only CI gate: verify lockfile integrity + re-verify Sigstore provenance vs npm's published record (`--json`) |\n| `mcpm diff` | Compare installed servers against mcpm.yaml and lock file |\n| `mcpm sync` | Show cross-client config drift across all detected clients (`--check` gates CI with exit 2, `--json`) |\n| `mcpm completions <shell>` | Generate shell completion scripts (bash, zsh, fish) |\n| `mcpm why <name>` | Explain a server's trust score (breakdown of all components) |\n| `mcpm serve` | Start mcpm as an MCP server (stdio transport) |\n| `mcpm guard enable` | Wrap detected client configs with the inspection relay |\n| `mcpm guard disable` | Restore original client configs |\n| `mcpm guard status` | Show what's wrapped and the per-server pin state |\n| `mcpm guard demo` | Run the synthetic prompt-injection scenario (visible block) |\n| `mcpm guard accept-drift <server>` | Re-pin a tool's schema after a legitimate upgrade |\n| `mcpm guard mute <signature-id>` | Disable a signature with optional `--for <duration>` |\n| `mcpm guard unmute <signature-id>` | Re-enable a muted signature |\n| `mcpm guard pause` | Pause all guard inspection (debugging escape hatch) |\n| `mcpm guard cleanup` | Prune pin entries for uninstalled servers |\n| `mcpm guard inspect [file]` | Run the signature catalog over MCP JSON-RPC frame(s), offline — no relay, no server |\n| `mcpm guard list-signatures` | Show the shipped OWASP MCP Top 10 signature catalog |\n| `mcpm guard doctor-confine` | Report sandbox-backend availability and which servers are enrolled in confinement (`--json`) |\n| `mcpm guard reset-integrity` | Regenerate the pins.json or guard-policy.yaml integrity sidecar |\n\nRun `mcpm <command> --help` for options and flags.\n\n## CI: verify your lockfile\n\n`mcpm verify` is a repo-only, **client-free** gate: it checks your committed\n`mcpm-lock.yaml` against npm's **published** `dist.integrity` record and exits\nnon-zero on integrity drift, an unverifiable record, a format mismatch, or a\nsuspicious missing baseline. Because it needs no AI clients installed, it runs on a\nhosted CI runner (where `mcpm up` cannot).\n\nIt also checks that the lock **covers** what `mcpm.yaml` declares. The other gates\nread only the lock, so they pass over a lock that is missing servers — the coverage\ncheck is what stops a truncated lock from verifying green while enforcing less than\nyou asked for. A lock holding no servers at all never passes unless an `mcpm.yaml`\nbeside it confirms nothing was declared. Correspondingly, `mcpm lock` is\nall-or-nothing: if any server fails to resolve it reports every failure and writes\n**nothing**, leaving the previous lock intact.\n\nIt **also re-verifies Sigstore provenance** for every npm server whose lock recorded\na cryptographically `verified` baseline: it re-runs the offline crypto verification\nagainst npm's current record and fails closed if the attestation regressed — the\nsigner identity changed, it no longer verifies, or it can't be re-checked. This is\nevidence-gated, so a lock with no `verified` baselines (the common case) is\nunaffected. `mcpm up --frozen` runs the same integrity + provenance freeze before\ninstalling.\n\n`mcpm lock` also records each npm server's **published provenance identity** (the\nsource repo + immutable GitHub repo/owner ids behind the build) and WARNs when it\ndrifts across versions — a repo/owner change or a signed→unsigned drop, the shape\nof a hijacked-publish (Postmark) attack.\n\n`mcpm lock` and `mcpm why` additionally **cryptographically verify** the provenance\n**offline** — the attestation's Sigstore bundle is checked against a vendored trust\nroot (no network at verify time), and the attested subject digest is bound to the\npackage's `dist.integrity`, so a valid attestation for a *different* tarball can't\npass. When it holds, the record reads `verified`; otherwise `attested` — an\n*unverified* registry record — or `unsigned` (neutral). Report-only, and honest\nabout scope: `verified` means the **build identity** is cryptographically attested\nby the CI's OIDC token — **not** that the code is safe (a same-repo CI compromise\nmints a valid attestation).\n\n```yaml\n# .github/workflows/mcpm.yml\njobs:\n  verify:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: getmcpm/cli/.github/actions/mcpm-verify@v0.43.0   # or: run: npx @getmcpm/cli verify\n```\n\nThe Action writes a job step summary from `--json`; the same verb works as a\npre-commit hook. See [`.github/actions/mcpm-verify`](.github/actions/mcpm-verify).\n\n**Code scanning:** `mcpm audit --sarif` emits a SARIF 2.1.0 report (one rule per\nfinding type, findings anchored file-level to `mcpm.yaml`) that GitHub ingests as\ncode-scanning alerts:\n\n```yaml\n      - run: npx @getmcpm/cli audit --sarif > mcpm.sarif\n        continue-on-error: true   # audit exits 1 when a server is risky\n      - uses: github/codeql-action/upload-sarif@v3\n        if: always()              # upload even if the audit flagged a risk\n        with:\n          sarif_file: mcpm.sarif\n```\n\n`mcpm audit` exits `1` when a server is risky and `2` when the invocation itself\ncannot be satisfied — an impossible `--min-trust`, or a flag combination mcpm\nrefuses (`--sarif` is report-only and cannot be combined with `--fix`). A script\nthat treats every non-zero exit as \"a server is risky\" will misread the second.\n\n> Honesty boundary: a failure means npm's *published record* diverged from your\n> lock — not that mcpm caught malicious bytes; npx/uvx fetch the artifact\n> independently at server launch.\n\n## Runtime defense (mcpm-guard)\n\nInstall-time trust scoring catches most poisoned servers before they ship. But what about **rug-pulls** — a server that changes its tool definitions after you've already approved them? Or **prompt-injection in tool responses** — adversarial text embedded in a Slack message, web page, or calendar invite that the agent reads through your trusted MCP server?\n\n`mcpm guard` adds a runtime inspection layer. It wraps every installed MCP server with a stdio relay, scans tool descriptions / responses / arguments for OWASP MCP Top 10 attack patterns, pins each tool's schema at install time, and blocks calls when the live response drifts from the pin (rug-pull defense).\n\n### What happens on every tool call\n\nThe guard sits inline on the stdio channel between your AI client and each MCP server, so it sees **both halves of every tool call** and inspects them as they pass:\n\n- **The request your agent sends** — the tool name and arguments, checked for sensitive-path exfil and injection smuggled into call parameters.\n- **The response the server returns** — checked for instruction injection hidden in the tool's output (the Slack message, web page, or calendar invite your agent is about to read).\n- **The tool's own definition** — `tools/list` descriptions, schemas, and annotations, checked against the schema pinned at approval time, so a server can't quietly rewrite a tool you already trusted.\n\nWhen a frame trips a signature, drift check, or policy rule, the guard **drops it and hands your agent a JSON-RPC error in its place** — carrying the signature id and a `remediation` string — so the poisoned content never reaches your model. Clean calls pass straight through (p99 ~0.065 ms on small frames). Server-initiated `sampling` / `elicitation` requests are inspected the same way, with the error routed back to the server rather than to your agent.\n\n### Quick start\n\n```bash\nnpm install -g @getmcpm/cli@latest\n\nmcpm guard enable           # wrap detected client configs (Claude Desktop / Claude Code / Cursor / VS Code / Windsurf / Gemini CLI)\n# → restart your IDE so it re-spawns the wrapped server processes\nmcpm guard demo             # synthetic prompt-injection scenario — see a live block in your terminal\nmcpm guard status           # what's protected, what's still in first-session-pin mode\n```\n\nThe `demo` command boots an in-process synthetic malicious server that returns a canned prompt-injection payload; the relay blocks it. Total time from `npm install` to a screenshot-worthy block: ~5 minutes (most of which is the IDE restart).\n\n### What it catches\n\nCategories are the [OWASP MCP Top 10 (beta)](https://github.com/OWASP/www-project-mcp-top-10) ids mcpm pins in `src/guard/owasp.ts`; see `docs/owasp-mcp-mapping.md` for the pinned spec commit and the reasoning behind each assignment. \"unclassified\" means the signature was evaluated and does not map cleanly to a category at that commit — never that it is unreviewed.\n\n| Category | Attack class | Action |\n|---|---|---|\n| MCP03 Tool Poisoning | Tool-description injection (poisoning) | block |\n| MCP03 Tool Poisoning | Instruction-shaped text in tool annotations (title or a custom annotation field) | block |\n| MCP03 Tool Poisoning | Schema / annotation drift since install (rug-pull) | block |\n| MCP03 Tool Poisoning | Description-only drift (cosmetic tier) | warn |\n| MCP03 Tool Poisoning | Instruction injection in tool responses | block |\n| MCP03 Tool Poisoning | Exfil-named parameter in a tool's input schema (`_system_prompt_`, …) | block (list-time) |\n| MCP03 Tool Poisoning | Any invisible (`Default_Ignorable_Code_Point`) or control character in tool metadata — zero-width, bidi, combining grapheme joiner, fillers, variation selectors, Unicode TAG block — except a single VS15/VS16 after an emoji, keycaps, ZWJ emoji sequences and the three RGI subdivision flags | warn |\n| MCP03 Tool Poisoning | Payload concealed in U+E0000–U+E007F on any carrier (\"ASCII smuggling\") | decoded and re-scanned — the recovered signature decides; a bare presence floor warns |\n| MCP03 Tool Poisoning | One `tools/list` advertises two tool names that are visually indistinguishable after normalization | warn |\n| MCP03 Tool Poisoning | A run of two or more variation selectors outside tool metadata (\"emoji smuggling\"; presence floor, no decode) | warn |\n| MCP03 Tool Poisoning | A tool name carries an invisible or blank-width character (no carve-outs), or mixes Latin with another script | warn |\n| MCP06 Intent Flow Subversion | Injection in `initialize` instructions (line-jumping) | block |\n| MCP06 Intent Flow Subversion | Instruction injection in resource / prompt content | warn (forward) |\n| MCP06 Intent Flow Subversion | Server solicits a wallet seed phrase / private key / card CVV / SSN / PIN | block (to the server) |\n| MCP06 Intent Flow Subversion | Injection in a server-initiated `sampling` prompt | block (to the server) |\n| MCP05 Command Injection & Execution | Shell-metacharacter / command-substitution syntax in an identifier- or path-shaped `tools/call` argument (CVE-2025-53818, CVE-2026-25546 shape) | block |\n| MCP05 Command Injection & Execution | Query-language control syntax in a table/column/database-name-shaped argument (CVE-2026-33980 shape) | block |\n| MCP05 Command Injection & Execution | An embedded `--`-prefixed CLI flag token in a namespace- or opaque-identifier-shaped argument (CVE-2026-39884 shape) | block |\n| MCP01 Token Mismanagement & Secret Exposure | High-confidence secret returned in a tool response | warn (secret redacted in the log) |\n| MCP01 Token Mismanagement & Secret Exposure | Generic bearer token disclosed in a tool response | warn (secret redacted in the log) |\n| MCP02 Privilege Escalation via Scope Creep | Server's advertised capabilities changed across the `initialize` handshake | warn (once) |\n| unclassified | Sensitive-path exfil in tool arguments | warn (promote to block via policy) |\n| unclassified | HTML/script in a tool response calling the `electron.mcp` privileged IPC bridge (CVE-2025-68669, CVE-2026-22793 shape) | warn |\n\nDetection is regex + structural; NFKC + stripping every Unicode default-ignorable codepoint (and folding blank-width fillers to a space) defeats the common Unicode evasions, and a separate hidden-character *presence* check flags evasion carriers before they're normalized away. [\"ASCII smuggling\"](https://arxiv.org/abs/2607.05744) -- hiding a payload in the Unicode TAG block (U+E0000-U+E007F), which renders as nothing but is readable by a model -- gets two dedicated passes, because that stripping ERASES a fully encoded payload rather than revealing it. The guard decodes TAG runs back to ASCII and re-runs the carrier's own signatures, so a concealed payload is judged by what it says: a TAG-encoded wallet-seed solicitation is blocked by the credential-phishing signature, not merely noted as suspicious. Beneath that sits a presence floor for payloads that are concealed but match nothing. Emoji subdivision flags are built from the same codepoints, so the three a client actually renders (England, Scotland, Wales) are carved out by whole-sequence validation; another well-formed subdivision flag still warns. Base64 / base64url payloads inside server responses are also decoded and re-scanned, so an injection or credential hidden behind an encoding can't slip past the regex floor (base64-decoded hits warn, never hard-block; TAG-decoded hits keep their native severity, since concealment on that plane is not something benign content does). See `mcpm guard list-signatures` for the current shipped set.\n\n\n### Confinement (opt-in enforcement)\n\nEverything above is *detection* — the relay reasons about the JSON-RPC bytes and warns or blocks. But a server that decides to read `~/.ssh` or write a `~/Library/LaunchAgents` persistence hook never expresses that through inspectable traffic. `mcpm guard enable --confine` complements detection with *enforcement*: it wraps each relayed stdio server in an OS sandbox that physically denies reads of a secret-file denylist and writes outside caches/scratch, so the server can't exfil credentials or persist regardless of the JSON-RPC it emits. `mcpm guard doctor-confine` reports backend availability and which servers are enrolled. **macOS only** for now (Seatbelt/`sandbox-exec`); on other platforms it warns and runs unconfined rather than giving a false sense of protection. See `docs/GUARD.md` for the tier details and caveats.\n\n### Day-1 commands\n\n```bash\nmcpm guard enable [--client <name>] [--server <name>] [--dry-run]    # wrap detected configs\nmcpm guard disable [--client <name>] [--server <name>]               # unwrap\nmcpm guard status                                                    # what's wrapped + pin state\nmcpm guard demo                                                      # synthetic attack-block demo\nmcpm guard list-signatures [--json]                                  # show shipped signatures\nmcpm guard inspect frames.ndjson                                     # verdicts for captured traffic, offline\nmcpm guard enable --confine                                          # also OS-sandbox wrapped stdio servers (macOS)\nmcpm guard doctor-confine [--json]                                   # confine backend availability + enrolled servers\n```\n\n### Inspect frames without a server\n\n`mcpm guard inspect` runs the same signature catalog the relay uses over MCP JSON-RPC frames you already have — a captured response, a suspicious `tools/list`, a payload from a writeup — with no wrapped server, no relay, and no network:\n\n```bash\n# one frame, human-readable\nmcpm guard inspect suspicious-response.json\n\n# a capture, machine-readable — one verdict line per input frame, in input order\ncat frames.ndjson | mcpm guard inspect --json\n```\n\nExit status makes it a CI gate over recorded traffic: `0` all clear, `1` something warns (or a frame wouldn't parse or couldn't be inspected), `2` something would be blocked.\n\nVerdicts are the signature catalog's default actions, including the warn-only carrier clamp — so an injection in a `resources/read` body reports `warn` here exactly as it would inline. Your local policy overrides (mutes, `log_only`) are deliberately *not* applied: this answers \"what do the signatures see\", not \"what would my config do\".\n\nIt is also the seam [mcp-guardbench](https://github.com/getmcpm/mcp-guardbench) uses to score mcpm's guard — through this published binary, never by importing the engine, so mcpm is measured on exactly the same footing as any other guard. [**mcp-guardbench**](https://github.com/getmcpm/mcp-guardbench) is the reference consumer: a guard-agnostic corpus + runner that scores any MCP guard this way.\n\n### When a block fires\n\nThe relay returns a JSON-RPC error response to your IDE with the signature id + a `remediation` string telling you exactly which command to run. Two typical cases:\n\n```bash\n# False positive on a legitimate signature\nmcpm guard mute owasp-mcp-2-instruction-injection-in-response --for 5m\n\n# Schema drift on a legitimate server upgrade\nmcpm guard accept-drift slack-mcp --tool send_message --new-hash sha256:abc... --yes\n```\n\n### Audit the log\n\nEvery block / warn is appended to `~/.mcpm/guard-events.jsonl`. Inspect with `jq`:\n\n```bash\n# Last hour's blocks\ntail -n 1000 ~/.mcpm/guard-events.jsonl | jq 'select(.action == \"block\")'\n\n# Group by signature id\njq -s 'group_by(.findings[0].signature_id) | map({sig: .[0].findings[0].signature_id, n: length})' \\\n   < ~/.mcpm/guard-events.jsonl\n\n# Top-N most-blocked servers\njq -s 'group_by(.server_name) | map({server: .[0].server_name, n: length}) | sort_by(-.n) | .[:10]' \\\n   < ~/.mcpm/guard-events.jsonl\n```\n\n### When you're debugging and need to turn it off briefly\n\n```bash\nmcpm guard pause --for 10m     # disables all inspection for 10 minutes\nmcpm guard pause --off         # cancel an active pause\n```\n\n### Why this exists\n\nIndependent 2026 evidence for each thing the guard does, so you can check the premise rather than trust the pitch:\n\n- **[NSA AI Security Center, \"MCP: Security Design Considerations\"](https://media.defense.gov/2026/Jun/02/2003943289/-1/-1/0/CSI_MCP_SECURITY.PDF)** — recommends filtering outbound proxies, data-loss prevention, sandboxing, and local MCP scanning. That is the guard relay, the credential-egress detectors, `--confine`, and `mcpm audit`, in one government document.\n- **[OX Security, \"Mother of All AI Supply Chains\"](https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/)** (2026-04-15) — 10 assigned critical/high CVEs from the config-to-process-spawn design, and a proof-of-concept poisoned server accepted by 9 of 11 public registries and marketplaces. Registry listing is not a safety signal.\n- **Microsoft's tool-poisoning warning** (2026-06-30, [reported here](https://thehackernews.com/2026/06/microsoft-warns-poisoned-mcp-tool.html)) — poisoned tool descriptions steer an agent about as effectively as rewriting its system prompt; the recommended mitigation is code-review-style diffing of description changes. Schema pinning plus drift detection covers the detection half: mcpm tells you a description changed since you approved it, and blocks on schema or annotation drift. It does not render a before/after diff of the text.\n- **[SmartLoader](https://www.straiker.ai/blog/smartloader-clones-oura-ring-mcp-to-deploy-supply-chain-attack)** (disclosed Feb 2026) — a trojanized Oura Ring MCP server, backed by fake GitHub accounts with manufactured social proof, seeded into legitimate registries to drop an infostealer. Stars and listings are forgeable, which is why `mcpm lock`, `why` and `verify` check build provenance instead (it is reported and gated there, not folded into the trust score). Note the honest limit: provenance attests *who built a package*, not that the code is safe — an attacker publishing their own trojanized package from their own CI gets valid provenance. It raises the cost of impersonating someone else; it would not by itself have stopped SmartLoader.\n- **[Deadbugz](https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign)** (Pillar Security, disclosed 2026-08-12) — an active MCP supply-chain campaign: 23 pull requests to unrelated AI/MCP/dev-tool projects from one GitHub account, distributing a server that stays benign for its first three tool calls before its `tools/list` and `prompts/get` responses flip to solicit SSH keys, AWS credentials, shell history, and Kubernetes config. mcpm's session-based schema-drift check blocks the `tools/list` flip in a real session (it compares against the session's own first-seen definitions, not only an on-disk pin) — but [mcp-guardbench's](https://github.com/getmcpm/mcp-guardbench#corpus-v5---the-first-live-in-the-wild-campaign-case-deadbugz) three single-frame, context-free reproductions of that wording -- including a third, externally contributed variant against a real mongodb-mcp-server tool surface -- are published misses at `@getmcpm/cli@0.42.5` (the phrasing doesn't match today's regex signatures), and mcpm's own tests record that the `prompts/get` channel this campaign also poisons has no drift protection at all (`src/guard/__tests__/deadbugz.test.ts`).\n- **[Grafana MCP, CVE-2026-19516](https://www.pillar.security/blog/valid-but-never-issued-session-spoofing-and-ssrf-in-grafana-mcp)** (Pillar Security, 2026-09-02; [Grafana advisory](https://grafana.com/security/security-advisories/cve-2026-19516/), CVSS 9.1, fixed in v1.1.0) — session spoofing plus SSRF in `mcp-grafana` before v1.1.0 let an unauthenticated caller mint a session in the expected format and act with the server's own Grafana credentials, then point the server's `grafana_api_request` tool at internal and cloud-metadata services through the caller-supplied `X-Grafana-URL` request header. The CVE number covers the SSRF half; the auth gap was a companion finding in the same research, and the bearer-token auth v1.1.0 added for it is optional. Honest limit: this is a remote HTTP/SSE server, and mcpm's guard relay is stdio-only — it fails closed (refuses to wrap) on HTTP/SSE transports rather than covering them.\n- **[Context7, CVE-2026-75130](https://nvd.nist.gov/vuln/detail/CVE-2026-75130)** (published 2026-08-18; the assigner scores it 6.4 medium under CVSS 4.0 and 9.0 critical under CVSS 3.1) — a prompt-injection flaw in Upstash's widely used documentation server (~50k GitHub stars, 8M+ npm downloads): its Custom AI Instructions feature could inject unsanitized text into a connected coding agent's context on a routine library-documentation request, enabling credential exfiltration and destructive file deletion. Already fixed — the reporter's [write-up](https://noma.security/blog/contextcrush-context7-the-mcp-server-vulnerability/) records private disclosure on 2026-02-18 and a fix deployed to Context7's production service on 2026-02-23, months before the CVE was published. That is the part worth noting here: the fix was to how the service *serves* those instructions, so no version pin or lockfile entry on the installed package would have moved.\n- **[The official registry's own moderation policy](https://modelcontextprotocol.io/registry/moderation-policy)** — consumers \"should assume minimal-to-no moderation\", with security scanning explicitly delegated to package registries and downstream subregistries. mcpm is one of those downstream layers.\n\n### Read more\n\n- `docs/GUARD.md` — full command reference\n- `docs/SIGNATURES.md` — signature catalog + how to contribute new ones\n- `docs/POLICY.md` — `~/.mcpm/guard-policy.yaml` reference\n- `docs/owasp-mcp-mapping.md` — every mcpm mechanism mapped to an OWASP MCP Top 10 (beta) category, with an honest gap list for what's not covered\n- `docs/VISION.md` — where the project is going (thesis, horizons, doctrine)\n\n## Agent mode\n\nmcpm can run as an MCP server itself, letting AI agents search, install, and audit MCP servers programmatically.\n\n```json\n{\n  \"mcpServers\": {\n    \"mcpm\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@getmcpm/cli\", \"serve\"]\n    }\n  }\n}\n```\n\nThis exposes 9 tools: `mcpm_search`, `mcpm_install`, `mcpm_info`, `mcpm_list`, `mcpm_remove`, `mcpm_audit`, `mcpm_doctor`, `mcpm_setup`, and `mcpm_up`.\n\nThe `mcpm_setup` tool takes a natural language description like \"filesystem and GitHub\" and handles everything: search, trust scoring, install. One tool call to assemble a working MCP toolchain.\n\n**Try it** -- add the config above to your MCP client, restart, then ask your agent:\n\n> You have mcpm tools available (from @getmcpm/cli, the MCP package manager, not the Minecraft one). Use them to find MCP servers for filesystem access and GitHub. Check their trust scores and install anything above 60.\n\n## Supported clients\n\n| Client | Config path (macOS) |\n|---|---|\n| Claude Desktop | `~/Library/Application Support/Claude/claude_desktop_config.json` |\n| Claude Code | `~/.claude.json` (user-global `mcpServers`) |\n| Cursor | `~/.cursor/mcp.json` |\n| VS Code | `~/Library/Application Support/Code/User/mcp.json` |\n| Windsurf | `~/.codeium/windsurf/mcp_config.json` |\n| Gemini CLI | `~/.gemini/settings.json` (user-global `mcpServers`) |\n\nLinux and Windows paths are also supported. See `mcpm doctor` to verify which clients are detected on your system.\n\n## How it works\n\nmcpm is a local-first CLI. There is no mcpm backend or account system.\n\n```mermaid\nflowchart TD\nsubgraph user[\"User / Terminal\"]\n    CLI[\"mcpm CLI<br/>Commander entry point\"]\nend\n\nsubgraph commands[\"Commands (src/commands/)\"]\n    SEARCH[\"search\"]\n    INSTALL[\"install\"]\n    AUDIT[\"audit\"]\n    GUARD[\"guard<br/>enable/disable/status\"]\nend\n\nsubgraph registry[\"Registry API<br/>(Only Remote)\"]\n    REGAPI[\"https://registry.<br/>modelcontextprotocol.io<br/>v0.1\"]\nend\n\nsubgraph scanning[\"Local Scanning & Trust<br/>(src/scanner/)\"]\n    HEALTH[\"Health Check<br/>(0-30): spawn +<br/>verify response\"]\n    TIER1[\"Tier 1: Static Patterns<br/>(0-40): secrets, injection,<br/>typosquatting, exfil\"]\n    TIER2[\"Tier 2: External Scan<br/>(0-20): opt-in via<br/>MCPM_EXTERNAL_SCANNER\"]\n    META[\"Registry Metadata<br/>(0-10): publisher,<br/>age, downloads\"]\n    SCORE[\"Trust Score<br/>(max 80; 100 with<br/>external scan)\"]\nend\n\nsubgraph config[\"Config Management<br/>(src/config/adapters/)\"]\n    DETECT[\"Detect AI clients<br/>Claude Desktop / Claude Code / Cursor<br/>VS Code / Windsurf / Gemini CLI\"]\n    ATOMIC[\"Atomic writes<br/>0o600 + symlink-safe<br/>.tmp/.bak\"]\nend\n\nsubgraph guard_runtime[\"Guard Runtime<br/>(src/guard/)\"]\n    WRAP[\"Config entry wrap<br/>via run --inner\"]\n    RELAY[\"Stdio MITM Relay<br/>per-server\"]\n    PATTERNS[\"Pattern Engine<br/>OWASP MCP Top 10\"]\n    PINS[\"Schema Pins<br/>+ Drift Detection\"]\n    FAILCLOSED[\"Fail-closed on<br/>pins.json error\"]\n    EVENTS[\"Event Log<br/>guard-events.jsonl\"]\nend\n\nsubgraph local_state[\"Local State<br/>(~/.mcpm/)\"]\n    SERVERS[\"servers.json\"]\n    ALIASES[\"aliases.json\"]\n    SECRETS[\"secrets.enc.json\"]\n    PINS_STORE[\"pins.json\"]\n    POLICY[\"guard-policy.yaml\"]\nend\n\nsubgraph clients[\"Native AI Clients\"]\n    CD[\"Claude Desktop\"]\n    CC[\"Claude Code\"]\n    CURSOR[\"Cursor\"]\n    VSCODE[\"VS Code\"]\n    WINDSURF[\"Windsurf\"]\n    GEMINI[\"Gemini CLI\"]\nend\n\nCLI --> commands\ncommands -->|searchServers| REGAPI\ncommands -->|scan| HEALTH\ncommands -->|scan| TIER1\ncommands -->|if available| TIER2\ncommands -->|registry meta| META\nHEALTH --> SCORE\nTIER1 --> SCORE\nTIER2 --> SCORE\nMETA --> SCORE\ncommands -->|detect| DETECT\ncommands -->|merge & write| ATOMIC\nDETECT -->|config paths| clients\nATOMIC -->|config| clients\nGUARD -->|wrap| WRAP\nWRAP -->|modifies config<br/>to invoke| clients\nWRAP -->|setup| RELAY\nRELAY -->|parse frames<br/>inspect msg| PATTERNS\nPATTERNS -->|check pins| PINS\nPINS -->|read| PINS_STORE\nPATTERNS -->|read policy| POLICY\nPINS -->|fail-closed| FAILCLOSED\nRELAY -->|record| EVENTS\ncommands -->|store| SERVERS\ncommands -->|aliases| ALIASES\ncommands -->|secrets| SECRETS\n```\n\n1. **Search and install** query the [official MCP Registry API](https://registry.modelcontextprotocol.io) (v0.1) maintained by the Model Context Protocol project.\n2. **Trust assessment** runs locally using built-in scanners (regex-based pattern detection), and can additionally shell out to a third-party scanner you have installed and named via `MCPM_EXTERNAL_SCANNER`.\n3. **Config management** reads and writes the native config file for each AI client. All writes use atomic file operations with restricted permissions (0o600 files, 0o700 directories).\n4. **Local state** lives in `~/.mcpm/` — `servers.json` (installed server registry), `aliases.json`, `secrets.enc.json` (the encrypted credential store), and the guard files (`pins.json`, `guard-policy.yaml`, `guard-confine.yaml`, `guard-unguarded.json`, `guard-events.jsonl`). There is no registry cache: every registry read is a live fetch.\n\nNo telemetry. No analytics. No account required.\n\n## Contributing\n\nContributions are welcome.\n\n```bash\ngit clone https://github.com/getmcpm/cli.git\ncd cli\npnpm install\npnpm test\npnpm build\n```\n\nBefore submitting a PR:\n\n- Run `pnpm test` and ensure all tests pass\n- Run `pnpm lint` to check types\n- Keep commits focused -- one change per commit\n- Follow [conventional commit](https://www.conventionalcommits.org/) format\n\nThis project is MIT licensed. See [LICENSE](./LICENSE).\n\n## Security\n\nIf you discover a security vulnerability, please use [GitHub's private vulnerability reporting](https://github.com/getmcpm/cli/security/advisories/new) instead of opening a public issue. We will respond within 48 hours.\n\nFor trust assessment issues (false positives/negatives in the scanner), regular GitHub issues are fine.\n\n## License\n\n[MIT](./LICENSE)\n","readmeFilename":"README.md"}