curatedmcp
# curatedmcp
[](https://www.npmjs.com/package/curatedmcp)
[](https://www.npmjs.com/package/curatedmcp)
[](LICENSE)
[](https://nodejs.org)
> **The CuratedMCP Agent.** One CLI to **discover, run, audit, and govern** every MCP server your AI tools (Claude, Cursor, Windsurf, Copilot, Gemini) use.
```bash
# 10-second risk scan of your machine β no signup
npx curatedmcp audit
```
**Plug it in once. Add servers anytime. Audit and govern them from one place.**
---
## What you get
| Command | What it does |
| --- | --- |
| `curatedmcp audit` | Scan your MCP configs for risky servers (high/medium/low). Zero auth, instant value. |
| `curatedmcp` *(no args)* | Run as an MCP hub server over stdio for Claude, Cursor, Windsurf, etc. |
| `curatedmcp add <slug>` | Add a server from the CuratedMCP catalog to your stack. |
| `curatedmcp remove <slug>` | Remove a server from your stack. |
| `curatedmcp list` | Show your current stack. |
| `curatedmcp init` | Print the config snippet to drop into your AI client. |
| `curatedmcp guard -- <cmd>` | Run a server behind the local action firewall. |
| `curatedmcp login` | Authenticate the agent to your CuratedMCP account. |
| `curatedmcp sync` | Pull your team's registry config and push audit results. |
---
## 1. Audit (the wedge β start here)
```bash
npx curatedmcp audit
```
Scans every MCP config file on your machine (Claude Desktop, Cursor, Windsurf, Claude Code, β¦),
classifies each server against the CuratedMCP catalog, and flags:
- π΄ **HIGH** β unverified or known-risky servers with credentials
- π‘ **MEDIUM** β verified servers running outside catalog defaults
- π’ **VERIFIED** β known-good catalog servers
No signup, no cloud, no data leaves your machine. Logged in? Add `--sync` to push the result to your dashboard.
---
## 2. Run as the MCP Hub
If you use MCP servers across multiple AI clients, you've felt this pain: configure GitHub MCP in
Claude Desktop, then re-do it in Cursor, then in Windsurf. New agent ships? Re-paste every config.
The agent fixes that. It's one MCP entry that fans out to every server you've added, in every AI client.
```
Claude Cursor Windsurf Copilot Gemini
\ \ | / /
ββββββββββββββββββββββββββββ
β curatedmcp β β one config in each agent
β (the MCP hub) β
ββββββ¬βββββββ¬βββββββ¬ββββββββ
β β β
GitHub Postgres Stripe β `add`'d once, available everywhere
```
### Add it to your AI client
```json
{
"mcpServers": {
"curatedmcp": {
"command": "npx",
"args": ["-y", "curatedmcp"]
}
}
}
```
| Client | Path |
| --------------- | --------------------------------------------------------------------- |
| Claude Desktop | `~/Library/Application Support/Claude/claude_desktop_config.json` (mac) / `%APPDATA%\Claude\claude_desktop_config.json` (win) |
| Cursor | `~/.cursor/mcp.json` |
| Windsurf | `~/.codeium/windsurf/mcp_config.json` |
| Claude Code | `~/.claude/mcp.json` (or `.claude/mcp.json` per-project) |
### Add servers to your stack
```bash
npx curatedmcp add github # prompts for GITHUB_TOKEN
npx curatedmcp add postgres --env DATABASE_URL=postgres://...
npx curatedmcp list
```
### Restart your AI client
Tools appear with a `<slug>__` prefix:
- `github__create_issue`
- `postgres__query`
- `filesystem__read_file`
---
## 3. Guard (local action firewall)
```bash
npx curatedmcp guard -- npx -y @modelcontextprotocol/server-github
```
Wraps an MCP server with a local policy engine that gates every `tools/call` against
`~/.curatedmcp/guard-policy.json`. Default policy allows read, prompts on write, blocks destructive.
```bash
npx curatedmcp guard --dashboard --port 7878 -- npx -y @some/server
# Then open http://localhost:7878 for the live action log
```
---
## 4. Login + sync (for teams)
Once you have a CuratedMCP account, link the CLI to it:
```bash
npx curatedmcp login # paste a registry key from your dashboard
npx curatedmcp sync # pull team registry config + push audit results
npx curatedmcp sync --team acme-eng # pick a specific team if you're in more than one
```
Sync pulls the locked-down server list approved by your team and merges it into your local stack β
so every developer's machine runs the same vetted set of servers.
---
## Config files
`~/.curatedmcp/stack.json` β your stack, plain JSON, hand-editable, version-controllable:
```json
{
"version": 1,
"entries": [
{
"slug": "github",
"name": "GitHub",
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-github"],
"env": { "GITHUB_TOKEN": "ghp_xxxxxxxxxxxx" },
"addedAt": "2026-05-01T10:14:00.000Z"
}
]
}
```
Set `"disabled": true` on an entry to skip it without removing it.
Other files (created on first use):
- `~/.curatedmcp/auth.json` β login token (mode 0600)
- `~/.curatedmcp/guard-policy.json` β firewall policy
- `~/.curatedmcp/launcher.json` β anonymous client UUID
---
## In-agent discovery
The agent itself exposes discovery tools to your AI client, so you can ask:
> "Find me an MCP server for Postgres."
> "What's the best Stripe MCP?"
> "Add the Postgres MCP server to my stack."
The agent uses `search_servers`, `get_server_details`, and `add_to_stack` to do all of that without you leaving the chat.
---
## Privacy
- **All config is local** at `~/.curatedmcp/`. No cloud sync unless you `login`.
- **Anonymous telemetry only** (event names like "search", "add"). Disable with `--no-telemetry` or `CURATOR_TELEMETRY=false`.
- Audit results stay on your machine unless you `login` and run `--sync`.
---
## Compatibility
- Works with Claude Desktop, Claude Code, Cursor, Windsurf, Copilot, Gemini, OpenAI Agents β anything that supports MCP over stdio.
- Node.js β₯ 18.
---
## Migrating from the old packages
The agent replaces three earlier packages, which are now deprecated:
| Old | New |
| --- | --- |
| `@curatedmcp/launcher` | `curatedmcp` *(no args)* / `curatedmcp add` / `curatedmcp list` |
| `@curatedmcp/auditor` *(aka `mcp-audit`)* | `curatedmcp audit` |
| `@curatedmcp/sentinel` *(aka `sentinel`)* | `curatedmcp guard` |
A `launcher` bin alias is kept for back-compat.
---
## Links
- π [curatedmcp.com/launcher](https://curatedmcp.com/launcher)
- π [Marketplace](https://curatedmcp.com/marketplace)
- π [GitHub](https://github.com/oneprofile-dev/mcp-launcher)
- π¬ [Issues](https://github.com/oneprofile-dev/mcp-launcher/issues)
MIT licensed.
TDQS
Scored across 5 tools
Tools are mostly distinct: search_servers finds servers, get_server_details retrieves details, list_categories browses categories, while install_server and add_to_stack both relate to making a server available but via different mechanisms. The overlap between install_server and add_to_stack is clarified by their descriptions, so confusion is unlikely.
All tool names follow a consistent verb_noun pattern with lowercase and underscores: get_server_details, search_servers, install_server, list_categories, add_to_stack. The verbs are clear and the pattern is uniform across the entire set.
With only 5 tools, the server is well-scoped for a curated catalog. Each tool covers a distinct core functionβsearching, browsing, retrieving details, and two installation pathsβwithout unnecessary bloat or sparseness.
The tool surface covers the primary lifecycle of discovering and installing MCP servers: search, filter by category, get details, and install via either manual config or Launcher integration. Minor gaps exist, such as no removal/uninstall tool, but the core workflows are complete.