MCP security guard + package manager. Block prompt injection, tool poisoning and rug-pulls in Model Context Protocol servers at runtime; trust-scored installs with Sigstore provenance for Claude Desktop, Claude Code, Cursor, VS Code, Windsurf and Gemini CLI. Local, deterministic, no LLM in the loop.
Latest release v0.39.1 · 8 Sept 2026
1 file for Claude Code: cli CLAUDE.md — 46,941 tokens loaded in every session.
CLAUDE.md E 46,941 tok These files are getmcpm/cli's own configuration — they tell Claude Code how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.