mcpm
@mcpm/cli is a command-line tool for managing MCP servers for Claude App: discovering MCP packages, installing/removing them, enabling/disabling servers, listing configured servers, and optionally running MCPM itself as an MCP server.
Score Breakdown
⚙ Agent Friendliness
🔒 Security
Security posture cannot be fully assessed from the provided README. TLS/authentication details for any network interactions are not documented. CLI tools often touch local filesystem paths and Claude App configuration; ensure secrets (if any) are not logged and review how credentials or tokens are handled in the underlying MCP/server integration.
⚡ Reliability
Best When
You want a local workflow/CLI to configure MCP servers for Claude App and optionally expose MCPM as an MCP server.
Avoid When
You need a stable, documented HTTP/REST API for programmatic access from other services rather than using a CLI or MCP transport.
Use Cases
- • Add and manage multiple MCP servers in Claude App
- • Search and discover MCP packages from a registry/community
- • Install MCP packages and configure them automatically
- • Temporarily disable MCP servers by moving them to local storage
- • Run MCPM as an MCP server to manage MCP servers via MCP tooling
Not For
- • Providing a hosted API for third-party integrations (it’s primarily a CLI/local tool)
- • High-assurance enterprise credential management without reviewing security model
- • User-facing SaaS billing/usage metering
Interface
Authentication
No explicit authentication mechanism is documented in the provided README. The tool appears to manage local configuration and integrate with Claude App/CLI workflows.
Pricing
No pricing information is provided in the supplied materials; appears to be a standard open-source CLI distributed via npm.
Agent Metadata
Known Gotchas
- ⚠ This is primarily a CLI; agent orchestration may need to execute commands and parse output
- ⚠ Behavior for interactive prompts may require TTY handling or flags like -y/--json
- ⚠ No details provided on safe retries or idempotency semantics for operations like install/add/remove
Alternatives
Full Evaluation Report
Comprehensive deep-dive: security analysis, reliability audit, agent experience review, cost modeling, competitive positioning, and improvement roadmap for mcpm.
AI-powered analysis · PDF + markdown · Delivered within 30 minutes
Package Brief
Quick verdict, integration guide, cost projections, gotchas with workarounds, and alternatives comparison.
Delivered within 10 minutes
Score Monitoring
Get alerted when this package's AF, security, or reliability scores change significantly. Stay ahead of regressions.
Continuous monitoring
Scores are editorial opinions as of 2026-03-30.