CuratedMCP
CuratedMCP Agent · v2.0 production ready

Install MCP servers once. Use them in every AI client.

Stop reinstalling and reconfiguring the same MCP servers every time you switch AI clients.

Install and audit 70+ MCP servers once — GitHub, Slack, Linear, Stripe, Firecrawl and more. Use them across Claude Code, Cursor, Windsurf, Copilot, and Gemini, with local protection against risky tools and actions. One npx curatedmcp install, no cloud account required.

Or browse the 70-server catalog — every server risk-classified before it's listed.

No account, no signupLocal privacy shield + firewallWorks across every AI clientOpen source · MIT

Works across the AI clients your team already runs

Claude CodeCursorWindsurfGitHub CopilotGemini

What happens after you install

One command. Every client. Audited and firewalled before it runs.

curatedmcp — install once
$ npx curatedmcp add github
Resolving github from curated catalog…
Security review passed · Read-write · verified publisher
Synced to 5 connected AI clients
Local action firewall armed
Done in 3.2s
Available in Cursor
Available in Claude Code
Available in Copilot
Available in Windsurf + Gemini
Security review completedAudit
Dangerous actions blocked locallyAudit
Ready to share with your team

Switch clients tomorrow — it's already there. No re-setup.

How CuratedMCP upgrades your AI workflow

Five things you do every week — before and after installing the agent.

Install an MCP tool

Manually edit hidden JSON config files for each AI client.

Run one command. Active across every client instantly.

Switch AI clients

Re-authenticate, copy env vars, reconfigure your stack.

Your tools follow you from Cursor to Claude Code to Gemini.

Verify server safety

Cross your fingers, read raw GitHub source, hope no key leaks.

Risk-classified and screened locally before installation.

Control permissions

Third-party MCP servers get blind, unrestricted access.

Local firewall blocks dangerous file or network actions.

Share a stack with your team

Slack a JSON snippet and pray nobody mis-pastes it.

One config URL — every reload reflects the latest allowlist.

Individual dev or engineering org?

Same mission — governed MCP — two entry points depending on where you are.

For individual developers

The CuratedMCP Agent

A free, open-source CLI that installs in 30 seconds. Audit your AI clients for risky MCP servers, run a unified hub across every IDE, and add a local action firewall — all without a cloud account.

  • Free forever · MIT licensed
  • Runs locally — nothing leaves your machine
  • Works with Claude, Cursor, Windsurf, Copilot, Gemini
  • Try it in-browser with zero install

For engineering organisations

The Control Plane

A team-level governance dashboard. Approve which MCP servers your engineers can install, push one allowlist across every AI client they run, and see every tool call in a tamper-proof audit log.

  • Curated server allowlist — per team, per role
  • Per-tool-call audit log with blocked-call events
  • One config URL syncs every developer instantly
  • SSO + RBAC — shipping with design partners

Four commands. Everything you need.

One CLI that runs locally — no signup, no cloud dependency. Audit risks in 30 seconds, then run it as your MCP hub, add a firewall, and sync your team's governance policy.

$npx curatedmcp audit

# free · runs offline · nothing leaves your machine

Audit
curatedmcp audit

Scan every AI client on this machine. Flags credential leaks, unverified servers, risky tool permissions.

Run
curatedmcp run

One MCP hub. Add it to Claude, Cursor, Windsurf, Copilot or Gemini once — every server you add appears in all of them.

Guard
curatedmcp guard

Local-first action firewall. Intercepts every MCP tool call before it executes. Block, alert, or require approval.

Govern
curatedmcp sync

Connect to your team's control plane. Pull the org allowlist and report your local audit upstream.

Why this matters now

MCP adoption just crossed the “it's everywhere” threshold. Every AI-forward eng org is hitting these three problems simultaneously.

Shadow MCP is the new shadow IT

Engineers install MCP servers across Claude Code, Cursor, and Copilot without IT visibility. One risky server — unverified publisher, credential in env, unrestricted filesystem — gives an AI agent keys to production. The Agent audits what's installed today. The Control Plane prevents it tomorrow.

Multi-IDE sprawl, one policy

Your team uses Claude Code, Cursor, Windsurf, and Copilot simultaneously. Each has its own MCP config. The Control Plane pushes one allowlist to all of them via a single team config URL — remove a server here and every developer's next reload reflects it instantly.

Supply chain risk, classified before you install

MCP is the new npm — and the same supply-chain attacks are coming. Every server in the CuratedMCP catalog is human-reviewed, risk-classified (Read-only / Read-write / Executes commands / Network egress), and credential-handling audited before it can be added to any team's allowlist.

From zero visibility to full control

Four steps — the first one takes 30 seconds and costs nothing.

  1. 01

    Scan your current stack

    Run `npx curatedmcp audit` — it scans Claude Desktop, Cursor, Claude Code, and Windsurf configs in under 30 seconds and flags risky servers by severity. Free, offline, no account.

    Free · no signup
  2. 02

    Build your approved allowlist

    Browse the 70+ human-reviewed servers in the catalog. Filter by risk level (Read-only / Read-write / Executes commands). Add what your team actually needs. One team config URL — developers paste it once.

    Team plan
  3. 03

    Enforce across every AI client

    The agent's `guard` command wraps any MCP server in a local firewall. Block unapproved tool calls before they execute. Policy is defined once and synced to every developer running `curatedmcp sync`.

    Agent + Team plan
  4. 04

    Audit what your AI agents actually did

    Every tool call logged — who called it, which IDE, what arguments (hashed locally, never exfiltrated). Filter by server, by user, by blocked vs. allowed. Export to CSV. Prove compliance.

    Team plan

The Control Plane

One admin dashboard for every MCP across every AI client

Built for Heads of Platform Engineering and AppSec leads rolling out Claude Code, Cursor, or Copilot at 50–500 engineers. Set policy once, enforced everywhere.

Team allowlist — one URL

Live

Approve which MCP servers your engineers can use. One team config URL distributes the allowlist. Remove a server and every developer's next sync reflects it.

Per-tool-call audit log

Live

Every MCP tool invocation captured — server, tool name, caller, IDE, timestamp. Blocked calls logged separately. Filter and export to CSV or SIEM.

Risk-classified catalog

Live

70+ human-reviewed servers, each rated by risk level (Read-only / Read-write / Executes commands / Network egress). Filter the whole catalog to Read-only in one click.

SSO · RBAC · self-hosted

Q3 2026

Okta / Azure AD / Google Workspace. Owner / Admin / Member roles. Run the control plane in our cloud or fully on-prem. Shipping with our first design partners.

Design partner program — limited seats

60-day pilot · $7,500 flat · founding-customer pricing

We scan your dev fleet, set up the allowlist and audit policy, and stand up the control plane for your org. SSO + per-tool-call audit included for design partners.

Apply for pilot

Start in the next 30 seconds.

Try the agent free in your browser, or tour the live control plane demo — no account, no credit card.

Ready to roll it out across your org? See the 60-day pilot →