mcp-pin Public logTeamsGitHub

Install

Pin what your apps approved.

One command protects every app on this machine, or pick the way that fits. Free and MIT licensed. The proxy runs locally and makes no network calls.

Every app on this machine

Finds the MCP servers in Claude Desktop, Claude Code, Cursor, VS Code, Gemini CLI, Devin Desktop, Windsurf, Cline and Codex, shows you the plan, backs up each file, and protects every local server. Undo with unwrap.

npx -y mcp-pin@0.2.1 wrap

Claude Code plugin

Adds the mcp-pin lookup tools, a skill for checking servers before you trust them, and a note at session start listing servers that run without mcp-pin.

claude plugin marketplace add GautamTalksDev/mcp-pin
claude plugin install mcp-pin@mcp-pin

Ask mcp-pin from your AI app

The lookup server answers "has this server changed?" and "is anything waiting for my review?". Read-only, and it never passes third-party text to the model.


Protect one server

Paste the command you would normally run for an MCP server. You get that server behind mcp-pin, for each app.








An independent open-source project by Gautam Khosla, not affiliated with Anthropic or the Model Context Protocol project. mcp-pin.gautamkhosla.com