Privacy

mcpock reads your AI agents' config files and checks their MCP servers on your own Mac. It never sends any of it anywhere.

What mcpock reads

mcpock reads the config files of the AI agents you use (for example ~/.claude.json or ~/.cursor/mcp.json) to find the MCP servers listed in them, and it scans the usual config folders on your Mac for any other file written in a standard MCP format. It only looks at known config paths and the usual config folders: the scan never looks inside Documents, Desktop or Downloads, and it skips symbolic links so it can't be led anywhere else.

What mcpock never does

  • Never edits a config. mcpock only reads config files; it never edits, moves or rewrites any of them. "Open Config…" asks first, with Cancel as the default.
  • Never phones home. No accounts, no analytics. The only network connections mcpock makes are to the remote MCP servers already listed in your own configs, to aka's own local helper on your Mac if you use aka, and to mcpock.com to check for a new version.
  • Update checks you control. mcpock asks before its first automatic check. A check downloads a small list of versions from mcpock.com and sends nothing about your servers or configs. Turn automatic checks off in Settings > About; Check for Updates there always works. Every update is signed, and mcpock refuses one whose signature doesn't match.
  • Never keeps a secret. The status file mcpock writes for agents to read holds environment variable and header names, never their values. API keys in command lines, URLs and error texts are masked everywhere mcpock shows or stores anything.

How mcpock checks a server

To check a local server, mcpock starts the exact command from your config, with its arguments and environment, in its project folder when it has one: the same thing your agent runs. It does the MCP handshake, asks for the tool list, then stops the process and all its child processes. Remote servers get the same few requests over HTTP. Paused servers are never started.

Usage counts

To show how many times an agent called a server, mcpock reads that agent's own history files and databases on your Mac, read-only, and keeps only the agent name, the server name and the day, written to ~/Library/Application Support/mcpock/usage.json. It never keeps a message, an argument or a result. Turn this off in Settings > General > Usage.

The MCP helper (mcpock-mcp)

mcpock ships a small, read-only MCP server, mcpock-mcp, so your agents can ask what needs attention instead of you pasting errors by hand. It only reads the status file mcpock already wrote after its last check; it never starts a server and never changes anything, in mcpock or in any agent's config.

Why mcpock isn't on the Mac App Store

The App Store's sandbox would stop mcpock from starting your MCP servers as separate processes and from reading other apps' config files in your home folder, both of which mcpock has to do to work at all. So it ships as a signed, notarized download instead of an App Store app.

Questions

For more detail, see the full guide or the FAQ. mcpock is made by Kika at akakika; reach out via X @akakikaaa.