# mcp-lock

> Use this tool when you need to ensure the integrity and consistency of MCP server installations, solving problems of silent updates and potential security risks. It records exact tarball hashes and detects changes, providing a guarantee similar to npm ci for Node.js projects. By using mcp-lock, you can trust the inputs of your MCP server installations and receive outputs of verified integrity checks.

Canonical page: https://skillsregistry.net/skills/mcpguards-mcp-lock  
JSON: https://api.skillsregistry.net/v1/skills/mcpguards-mcp-lock

## Description

MCP servers are installed via npx -y @scope/package — which silently downloads
the latest version every time your AI tool starts, with no integrity check.

mcp-lock fixes this by recording exact tarball hashes on first run and detecting
any changes on every run after that — the same guarantee npm ci gives you for
Node.js projects.

## Trust

- **Trust score (0–1):** 0.97
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-09-19

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/fq7ey2avym)
- **Repository:** <https://github.com/mcpguards/mcp-lock>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "mcpguards-mcp-lock"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/mcpguards-mcp-lock` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/mcpguards-mcp-lock/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
