MCP servers are installed via npx -y @scope/package — which silently downloads the latest version every time your AI tool starts, with no integrity check. mcp-lock fixes this by recording exact tarball hashes on first run and detecting any changes on every run after that — the same guarantee npm ci gives you for Node.js projects.
Partial audit · 2/5 dimensions · Audit v1-github · today · imported from glama ai
Sonraí na n-uirlisí ag teacht go luath. Tá 0 uirlisí ar fáil ag an bhfreastalaí seo.
MCP servers are installed via npx -y @scope/package — which silently downloads the latest version every time your AI tool starts, with no integrity check. mcp-lock fixes this by recording exact tarball hashes on first run and detecting any changes on every run after that — the same guarantee npm ci gives you for Node.js projects.
Yes, mcp-lock is completely free to use with no usage limits on the free tier.
mcp-lock is listed under the AI & Machine Learning category in the AgentForge MCP registry.
mcp-lock has a current uptime of 99.9% with an average response time of 0ms.
To connect mcp-lock, click the "Connect Agent" button on this page to get the configuration snippet. Add it to your MCP client (Claude Desktop, Cursor, or any MCP-compatible tool). Your AI agent will then have access to all of mcp-lock's tools via the Model Context Protocol.