
Security News
Feross on TBPN: How North Korea Hijacked Axios
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.
@mcp_hub_org/cli
Advanced tools
A NPX command to install and list Model Context Protocols - now with auto versioning
@mcp_hub_org/cli 是一个用于安装、运行和管理 MCP Hub 平台 MCP Server 的命令行工具。
npm install -g @mcp_hub_org/cli
或者使用npx直接运行:
npx @mcp_hub_org/cli <命令>
npx @mcp_hub_org/cli <命令>
install <服务器> - 安装一个 MCP 服务器
--client <客户端> - 指定 AI 客户端--path <路径> - 指定自定义配置文件路径uninstall <服务器> - 卸载一个 MCP 服务器
--client <客户端> - 指定 AI 客户端--path <路径> - 指定自定义配置文件路径run <服务器> - 运行一个 MCP 服务器
--env <json> - 提供JSON格式的配置list clients - 列出可用的客户端--help - 显示帮助信息cursor - Cursor 编辑器trae - Trae 国内版本trae-global - Trae 国际版本cline - Cline 扩展windsurf - Windsurf 编辑器# 安装服务器到 Cursor(默认路径)
npx -y @mcp_hub_org/cli@latest install sequential-thinking --client cursor
# 安装服务器到 Trae 国际版
npx -y @mcp_hub_org/cli@latest install sequential-thinking --client trae-global
# 安装服务器到自定义路径
npx -y @mcp_hub_org/cli@latest install sequential-thinking --client cursor --path /custom/path/mcp.json
# 卸载服务器
npx -y @mcp_hub_org/cli@latest uninstall sequential-thinking --client cursor
# 从自定义路径卸载服务器
npx -y @mcp_hub_org/cli@latest uninstall sequential-thinking --client cursor --path /custom/path/mcp.json
# 列出可用的客户端
npx -y @mcp_hub_org/cli list clients
# 运行服务器
npx -y @mcp_hub_org/cli run sequential-thinking
# 运行服务器并增加配置
npx -y @mcp_hub_org/cli@latest run Codebase --client cursor --env '{"API_TOKEN":"<填入你的API_TOKEN>"}'
# 显示帮助菜单
npx @mcp_hub_org/cli --help
使用 --path 参数可以将 MCP 服务器安装到自定义位置,这在以下情况下很有用:
# 示例:使用自定义路径
npx @mcp_hub_org/cli install my-server --client cursor --path "/Applications/Cursor.app/Contents/Resources/app/extensions/mcp.json"
FAQs
A NPX command to install and list Model Context Protocols - now with auto versioning
We found that @mcp_hub_org/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.

Security News
OpenSSF has issued a high-severity advisory warning open source developers of an active Slack-based campaign using impersonation to deliver malware.

Research
/Security News
Malicious packages published to npm, PyPI, Go Modules, crates.io, and Packagist impersonate developer tooling to fetch staged malware, steal credentials and wallets, and enable remote access.