Plugin name
mcp-pin
Short description
Know when an MCP server's tools change after you approved them: read-only lookup tools against a public log of tool definition changes, a skill for checking servers and explaining blocks, and a session-start note listing local servers that run without mcp-pin.
GitHub repository
GautamTalksDev/mcp-pin
Plugin path inside the repository
plugins/mcp-pin
Ref to review
No response
Commit SHA to review
4af6b8a7fff0b377ff055f5648a01141c8a131b5
Version
0.2.2
License identifier
MIT
Author name
Gautam Khosla
Author URL
https://github.com/GautamTalksDev
Homepage URL
https://mcp-pin.gautamkhosla.com
Keywords
mcp
security
tool-poisoning
rug-pull
supply-chain
Additional notes for reviewers
The plugin starts one local MCP server, npx -y mcp-pin@0.2.2 lookup (npm package with provenance, also in the official MCP Registry as io.github.GautamTalksDev/mcp-pin). Its four tools are read-only and return no third-party text. The only network request is a GET of https://mcp-pin.gautamkhosla.com/api/servers.json. The SessionStart hook runs a Node script that reads local MCP config to list server names, makes no network call and changes nothing. Full disclosure in plugins/mcp-pin/README.md; privacy policy in PRIVACY.md.
This issue was filed with help from an AI assistant (Claude Code) at the maintainer's request.
Submission checklist
Plugin name
mcp-pin
Short description
Know when an MCP server's tools change after you approved them: read-only lookup tools against a public log of tool definition changes, a skill for checking servers and explaining blocks, and a session-start note listing local servers that run without mcp-pin.
GitHub repository
GautamTalksDev/mcp-pin
Plugin path inside the repository
plugins/mcp-pin
Ref to review
No response
Commit SHA to review
4af6b8a7fff0b377ff055f5648a01141c8a131b5
Version
0.2.2
License identifier
MIT
Author name
Gautam Khosla
Author URL
https://github.com/GautamTalksDev
Homepage URL
https://mcp-pin.gautamkhosla.com
Keywords
mcp
security
tool-poisoning
rug-pull
supply-chain
Additional notes for reviewers
The plugin starts one local MCP server,
npx -y mcp-pin@0.2.2 lookup(npm package with provenance, also in the official MCP Registry as io.github.GautamTalksDev/mcp-pin). Its four tools are read-only and return no third-party text. The only network request is a GET of https://mcp-pin.gautamkhosla.com/api/servers.json. The SessionStart hook runs a Node script that reads local MCP config to list server names, makes no network call and changes nothing. Full disclosure in plugins/mcp-pin/README.md; privacy policy in PRIVACY.md.This issue was filed with help from an AI assistant (Claude Code) at the maintainer's request.
Submission checklist