
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@mcp_hub_fun/cli
Advanced tools
@mcp_hub_fun/cli 是一个用于安装、运行和管理 MCP Hub 平台 MCP Server 的命令行工具。
npm install -g @mcp_hub_fun/cli
或者使用npx直接运行:
npx @mcp_hub_fun/cli <命令>
npx @mcp_hub_fun/cli <命令>
install <服务器> - 安装一个 MCP 服务器
--client <客户端> - 指定 AI 客户端--path <路径> - 指定自定义配置文件路径uninstall <服务器> - 卸载一个 MCP 服务器
--client <客户端> - 指定 AI 客户端--path <路径> - 指定自定义配置文件路径run <服务器> - 运行一个 MCP 服务器
--env <json> - 提供JSON格式的配置list clients - 列出可用的客户端--help - 显示帮助信息cursor - Cursor 编辑器trae - Trae 国内版本trae-global - Trae 国际版本cline - Cline 扩展windsurf - Windsurf 编辑器# 安装服务器到 Cursor(默认路径)
npx -y @mcp_hub_fun/cli@latest install sequential-thinking --client cursor
# 安装服务器到 Trae 国际版
npx -y @mcp_hub_fun/cli@latest install sequential-thinking --client trae-global
# 安装服务器到自定义路径
npx -y @mcp_hub_fun/cli@latest install sequential-thinking --client cursor --path /custom/path/mcp.json
# 卸载服务器
npx -y @mcp_hub_fun/cli@latest uninstall sequential-thinking --client cursor
# 从自定义路径卸载服务器
npx -y @mcp_hub_fun/cli@latest uninstall sequential-thinking --client cursor --path /custom/path/mcp.json
# 列出可用的客户端
npx -y @mcp_hub_fun/cli list clients
# 运行服务器
npx -y @mcp_hub_fun/cli run sequential-thinking
# 运行服务器并增加配置
npx -y @mcp_hub_fun/cli@latest run Codebase --client cursor --env '{"API_TOKEN":"<填入你的API_TOKEN>"}'
# 显示帮助菜单
npx @mcp_hub_fun/cli --help
使用 --path 参数可以将 MCP 服务器安装到自定义位置,这在以下情况下很有用:
# 示例:使用自定义路径
npx @mcp_hub_fun/cli install my-server --client cursor --path "/Applications/Cursor.app/Contents/Resources/app/extensions/mcp.json"
FAQs
A NPX command to install and list Model Context Protocols
We found that @mcp_hub_fun/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.