Securing MCP servers in your repositories

Project-level MCP configuration lets every developer’s agent start the same servers. Pin them, authenticate them, and keep secrets out of the file.

Updated 2026-10-06

A .mcp.json, .cursor/mcp.json or .vscode/mcp.json committed to a repository decides which tools every agent in that repository can call. That is convenient, and it is also a supply chain: the configuration runs code on every developer’s machine.

Three rules

  • Pin local servers to an exact version. npx -y some-server runs whatever was published last, including a compromised release.
  • Use TLS and authentication for remote servers. A plain-HTTP or unauthenticated endpoint can be intercepted or impersonated.
  • Keep secrets out of the file. Reference environment variables instead of writing tokens into env blocks or URLs.
{
  "mcpServers": {
    "files": { "command": "npx", "args": ["-y", "some-mcp-server@1.4.2"] },
    "tickets": { "type": "http", "url": "https://mcp.example.com", "headers": { "Authorization": "Bearer ${TICKETS_TOKEN}" } }
  }
}

Check every repository

threadctx checks MCP configuration for unpinned packages, insecure transports and embedded secrets, and redacts any secret it finds in its own output. The org audit lists every server across the organisation in its inventory.

npx threadctx scan
npx threadctx audit --org your-org

Check your repositories now.

Free, local, nothing uploaded.

npx threadctx scan