mcptrustchecker / setup / cline
Setup guide

Set up mcptrustchecker in Cline

communitystdiounknown

Security scanner for MCP (Model Context Protocol) servers — reads the real published npm/PyPI source, not just metadata, to catch tool poisoning, prompt injection, toxic flows & supply-chain risk. Offline, deterministic A–F Trust Score, SARIF + CI gates.


01Configuration
{ "mcpServers": { "mcptrustchecker": { "command": "npx", "args": [ "-y", "mcptrustchecker" ] } } }

Add this to cline_mcp_settings.json. Generated from the captured install method (npx); the mcpServers shape is shared across Claude Desktop, Cursor, Windsurf, Cline, and VS Code.


02Steps
  1. Make sure Cline is installed and up to date.
  2. Open cline_mcp_settings.json and add the block above (merge into any existing mcpServers).
  3. Provide any required API keys/credentials as environment variables.
  4. Restart Cline and confirm mcptrustchecker’s tools appear.

03Other runtimes

04Provenance
config_sourcegenerated from captured install method
last_checked2026-07-24 13:20Z
sourcesGitHub repo search [p4]

Next step

Want agents that act within guardrails? Apex is the live governed-agent product — paced, capped, and fully-logged actions with approvals before anything runs.

Explore Apex →

See also: server page · is it safe? · alternatives