# @mockzilla/mcp

MCP server for Mockzilla (github.com/mockzilla/mockzilla-mcp). Lets Claude, Cursor, and Gemini CLI install the Mockzilla CLI, run local mock servers from OpenAPI specs, and mock individual endpoints, no account needed. Log in from the agent to deploy host

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.2.26
- **Author:** io.github.mockzilla
- **License:** MIT
- **npm:** @mockzilla/mcp
- **Source:** https://github.com/mockzilla/mockzilla-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 6 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-17T21:18:48.113Z
- **Version scanned:** 0.2.25
- **CVEs:** none found by OSV at scan time

## Tools

Tool surface: no readable artifact — tool surface unknown.

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@mockzilla/mcp\"\n      ],\n      \"env\": {\n        \"MOCKZILLA_TOKEN\": \"<YOUR_MOCKZILLA_TOKEN>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `MOCKZILLA_TOKEN` — Mockzilla Token (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Moderate blast radius — holds an api key; runs on your machine.
- Floor 18, ceiling 18 (tier: moderate)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40mockzilla%2Fmcp
- Install plan: https://forgeregistry.com/api/v1/packages/%40mockzilla%2Fmcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40mockzilla%2Fmcp
- HTML page: https://forgeregistry.com/registry/%40mockzilla%2Fmcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
