mcpgawkdocs ← Site

Install & downloads

Five surfaces. The CLI is the engine; everything else is a way of reaching it.

1 · The CLI — PyPI

The engine. Everything else on this page depends on it being installed.

uv tool install --force mcpgawk      # recommended: isolated, always on PATH
pipx install --force mcpgawk         # same idea, if you already use pipx
python3 -m pip install --user --upgrade mcpgawk   # anywhere Python 3.10+ is; fix PATH yourself

pypi.org/project/mcpgawk · Apache-2.0 · free forever, no account.

Which one? uv tool install if you have uv: it isolates the package and puts the binary somewhere already on your PATH, which is the single most common install problem. Plain pip install into a system Python is the most likely to end in command not found.

2 · VS Code — Marketplace

The fleet, in the sidebar. It shells out to the CLI on your machine and renders what comes back; it is a view, not a second engine.

code --install-extension gawk-dev.mcpgawk

Extension ID gawk-dev.mcpgawk. Requires the CLI above.

3 · VSCodium, Cursor, Windsurf and friends — Open VSX

The same extension, published to the registry those editors use instead of the Microsoft one.

codium --install-extension gawk-dev.mcpgawk

open-vsx.org/extension/gawk-dev/mcpgawk.

Open VSX download counts include registry mirroring and are not a usage number. We do not quote them as traction, and neither should you.

4 · CI — the GitHub Action

Gate a merge on what an MCP server actually is, in the pipeline rather than on a laptop.

- uses: gawk-dev/mcpgawk/action@main
  with:
    fail-on-flagged: true

Exit codes are the contract: 0 clean, 1 findings, 4 incomplete. Fail the build on 4 as well as 1 — a run that could not finish is not a pass.

5 · As an MCP server — so your agent can ask

Installing the CLI also installs mcpgawk-mcp, which exposes two read-only tools (scan_mcp_fleet, scan_mcp_server) so an agent can check this machine's scanner before trusting a server.

claude mcp add mcpgawk -- mcpgawk-mcp

The same server is reachable through the one binary as mcpgawk mcp, so a client that can only name a package can run it as uvx mcpgawk mcp.

It is read-only and refuses nothing by itself. Call-time refusal is the guard hook (Quickstart step 3), and it refuses to launch stdio servers unless the caller asks.

Check where your copy came from

From 0.1.73, every file on PyPI carries a signed record of where it was built: our public repository's release workflow, through PyPI trusted publishing. No API token can publish mcpgawk, so a stolen one cannot ship a fake release. You can check the record yourself:

uvx pypi-attestations verify pypi --repository https://github.com/gawk-dev/mcpgawk \
    pypi:mcpgawk-0.1.73-py3-none-any.whl

OK means the file PyPI serves was built by that repository. A file signed by any other repository fails, and so does any release before 0.1.73, which predates the signing. Swap in the version you installed (mcpgawk --version).

Keeping it current

mcpgawk --version
uv tool install --force mcpgawk     # or: pipx install --force mcpgawk

The extension and the CLI are released in lockstep on the same version number. A mismatch is worth reporting.