README.md:380-385 describes ~/.mcp.json as "global servers available in every session." There is no such location.
MCP user scope lives in ~/.claude.json. A file at ~/.mcp.json is only picked up incidentally, as a project-scope .mcp.json discovered by walking up the directory tree from the working directory — which happens to work for repos under $HOME and nowhere else.
Two consequences:
- Because it resolves as project scope, it's gated by the project-server approval flow — and this repo's
settings.json sets enableAllProjectMcpServers: false. The README's two recommendations work against each other.
- For anyone who keeps repos outside
$HOME, the servers silently don't load at all.
Verified
macOS, CLI 2.1.238, with ~/.mcp.json present and populated from mcp-template.json:
$ cd ~/Developer/claude-code-config && claude mcp get exa
exa:
Scope: Project config (shared via .mcp.json)
Status: ⏸ Pending approval (run `claude` to approve)
Type: http
$ cd /private/tmp/scratch && claude mcp get exa
No MCP server named "exa".
The Scope: Project config line and the pending-approval status are both the symptom: it was never registered as a user-scope server.
Suggested fix
Drop ~/.mcp.json from the README and from /trailofbits:config, and use the CLI, which writes real user scope:
claude mcp add --transport http exa --scope user 'https://mcp.exa.ai/mcp' --header "x-api-key: $EXA_API_KEY"
claude mcp add context7 --scope user -- npx -y @upstash/context7-mcp
That leaves mcp-template.json without a purpose — either remove it, or relabel it as an example project-scoped .mcp.json rather than something to copy into $HOME.
Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238). One of five separate findings from the same pass.
README.md:380-385describes~/.mcp.jsonas "global servers available in every session." There is no such location.MCP user scope lives in
~/.claude.json. A file at~/.mcp.jsonis only picked up incidentally, as a project-scope.mcp.jsondiscovered by walking up the directory tree from the working directory — which happens to work for repos under$HOMEand nowhere else.Two consequences:
settings.jsonsetsenableAllProjectMcpServers: false. The README's two recommendations work against each other.$HOME, the servers silently don't load at all.Verified
macOS, CLI 2.1.238, with
~/.mcp.jsonpresent and populated frommcp-template.json:The
Scope: Project configline and the pending-approval status are both the symptom: it was never registered as a user-scope server.Suggested fix
Drop
~/.mcp.jsonfrom the README and from/trailofbits:config, and use the CLI, which writes real user scope:That leaves
mcp-template.jsonwithout a purpose — either remove it, or relabel it as an example project-scoped.mcp.jsonrather than something to copy into$HOME.Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238). One of five separate findings from the same pass.