Atlas / MCP servers / aliyun / ESA

ESASAFE

mcp/aliyun/esa-3
Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
43 18r · 19w · 6d
Transport
stdio
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mcp-server-esa) [](./LICENSE)

MCP server for Alibaba Cloud ESA — deploy to the edge, manage DNS, certificates, and Edge Routines, all from your AI-powered IDE.

English | 中文

Features

  • 🚀 Pages — One-command deploy HTML or static folders (dist/, build/) to the edge
  • ⚡ Edge Routine — Full lifecycle management: create, commit, deploy, route, and tear down
  • 🌐 Site — DNS records, SSL certificates, IPv6, managed transforms, and site configuration
  • 🧩 Modular — Load all 40+ tools or pick only the module you need
  • 🔌 Works everywhere — Cursor, Claude Desktop, Cline, and any MCP-compatible client

Quick Start

Prerequisites

  1. Get your AccessKey ID and Secret from the Alibaba Cloud AccessKey page
  2. Enable the Edge Routine service

Configuration

Add to your MCP client config (e.g., Cursor ~/.cursor/mcp.json, Claude Desktop, Cline):

Pages (recommended) — deploy static sites to the edge in seconds:

{
"mcpServers": {
"esa-pages": {
"command": "npx",
"args": ["-y", "-p", "mcp-server-esa", "mcp-server-esa-pages"],
"env": {
"ALIBABA_CLOUD_ACCESS_KEY_ID": "your AK",
"ALIBABA_CLOUD_ACCESS_KEY_SECRET": "your SK"
}
}
}
}

All-in-one — includes Pages, ER, and Site tools:

{
"mcpServers": {
"esa-mcp-server": {
"command": "npx",
"args": ["-y", "mcp-server-esa"],
"env": {
"ALIBABA_CLOUD_ACCESS_KEY_ID": "your AK",
"ALIBABA_CLOUD_ACCESS_KEY_SECRET": "your SK",
"ALIBABA_CLOUD_SECURITY_TOKEN": "optional, required when using STS Token"
}
}
}
}

Modular — load only what you need:

Read from source at commit 4e96798bbca4OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server-esa --env ALIBABA_CLOUD_ACCESS_KEY_ID=${ALIBABA_CLOUD_ACCESS_KEY_ID} --env ALIBABA_CLOUD_ACCESS_KEY_SECRET=${ALIBABA_CLOUD_ACCESS_KEY_SECRET} --env ALIBABA_CLOUD_SECURITY_TOKEN=${ALIBABA_CLOUD_SECURITY_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server-esa": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ALIBABA_CLOUD_ACCESS_KEY_ID": "${ALIBABA_CLOUD_ACCESS_KEY_ID}",
        "ALIBABA_CLOUD_ACCESS_KEY_SECRET": "${ALIBABA_CLOUD_ACCESS_KEY_SECRET}",
        "ALIBABA_CLOUD_SECURITY_TOKEN": "${ALIBABA_CLOUD_SECURITY_TOKEN}"
      }
    }
  }
}
03

Exposed tools (43)

18 read · 19 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
apply_certificatewriteApplies for a free SSL certificate.
create_sitewriteAdds a website. Make sure that you have an available plan before you add a website. Make sure that your website domain name has an ICP filing if the location you want to specify covers the Chinese mainland.
create_site_a_or_aaaa_recordwriteCreates a DNS record for a specific website. Only A/AAAA records are supported.
create_site_cname_recordwriteCreates a DNS record for a specific website. Only supports records with type=CNAME and sourceType=Domain.
create_site_mx_recordwriteCreates a DNS record for a specific website. Only MX records are supported.
create_site_ns_recordwriteCreates a DNS record for a specific website. Only NS records are supported.
create_site_txt_recordwriteCreates a DNS record for a specific website. Only TXT records are supported.
delete_certificatedestructiveDeletes a certificate for a website.
delete_recorddestructiveDeletes a DNS record of a website based on the specified RecordId.
deployment_deletedestructiveDelete a specified code version associated with an Edge Routine (ER).
er_record_createwriteCreate a new record associated with an Edge Routine (ER)
er_record_deletedestructiveDelete a specified record associated with an Edge Routine (ER).
er_record_listreadList all records associated with a specific Edge Routine (ER).
folder_deploywriteDeploy a local folder of static files (HTML/CSS/JS/images etc.) to ESA Function & Pages and return a default access URL. The folder will be packaged as assets and uploaded.
get_certificatereadRetrieve the certificate, private key, and certificate information
get_certificate_quotareadQuery certificate quota and usage.
get_ipv6readQueries the IPv6 configuration of a website.
get_managed_transformreadQuery Managed Transform Configuration.
get_recordreadQueries the configuration of a single DNS record, such as the record value, priority, and origin authentication setting (exclusive to CNAME records).
get_site_pausereadQueries the ESA proxy configuration of a website.
html_deploywriteQuickly deploy an HTML page to ESA Edge Routine (ER) and return a default access URL to the user.
list_certificatesreadLists certificates of a website.
list_recordsreadQueries a list of Domain Name System (DNS) records of a website, including the record value, priority, and authentication configurations. Supports filtering by specifying parameters such as RecordName and RecordMatchType.
list_sitesread用于查询当前用户下的站点列表 ,包括站点的名称、状态、配置等信息。
route_createwriteCreate a new route associated with an Edge Routine (ER).
route_deletedestructiveDelete a specified route associated with an Edge Routine (ER).
route_getreadGet details of a specific route associated with an Edge Routine (ER).
route_updatewriteModify the configuration of an existing Edge Routine route.
routine_code_commitwriteSave a code version for future modifications or release within an Edge Routine (ER).
routine_code_deploywriteDeploy a selected code version to the staging or production environment. If version is not exist, should call routine_code_commit first
routine_createwriteCreate a new Edge Routine (ER) in your Alibaba Cloud account.
routine_deletedestructiveDelete an existing Edge Routine (ER) from your Alibaba Cloud account.
routine_getreadGet a the details of a Edge Routine (ER).
routine_listreadList all Edge Routines (ERs) in your Alibaba Cloud account.
routine_route_listreadList all routes associated with a specific Edge Routine (ER).
set_certificatewriteConfigures whether to enable certificates and update certificate information for a website.
site_active_listreadList all active sites
site_matchreadIdentify which site in the account matches the provided input criteria.
site_record_listreadList DNS records associated with a specific site.
site_route_listreadList all routes associated with a specific site.
update_ipv6writeModifies the IPv6 configuration of a website.
update_managed_transformwriteModifies the configuration of managed transforms for your website.
update_site_pausewriteModifies the ESA proxy configuration of a website.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_certificate, delete_record, deployment_delete, er_record_delete, route_delete, routine_delete
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/er/commit.ts:2
import api from '../../utils/service.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/er/commit.ts:7
import { uploadCodeToOSS } from '../../utils/helpers.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/er/deploy.ts:2
import api from '../../utils/service.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/er/deployments.ts:2
import api from '../../utils/service.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/er/index.ts:36
import { ToolHandlers } from '../../utils/types';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@alicloud/esa20240910, @alicloud/openapi-client, @alicloud/tea-util, @modelcontextprotocol/sdk, adm-zip, form-data, haikunator, node-fetch
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
image/readme/1744114625974.png
image/readme/1744114625974.png
Why it matters. 1005916 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
image/readme/1744168230082.gif
image/readme/1744168230082.gif
Why it matters. 6905159 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
image/readme/1744168440370.gif
image/readme/1744168440370.gif
Why it matters. 17462684 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
image/readme/1744168966418.gif
image/readme/1744168966418.gif
Why it matters. 20967727 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4e96798bbca4full audit observations/trust-audit/mcp-server/aliyun__esa-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084e96798bbca4SAFEB89first audit
06

Questions

What tools does ESA expose?

43 in total: 18 read-only, 19 that write, and 6 that can delete or overwrite (delete_certificate, delete_record, deployment_delete, er_record_delete, route_delete). Every one is listed on this page with its risk.

Is ESA safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ESA need?

It reads ALIBABA_CLOUD_ACCESS_KEY_ID, ALIBABA_CLOUD_ACCESS_KEY_SECRET and ALIBABA_CLOUD_SECURITY_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ESA run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-server-esa at 1.1.0.

How current is this page?

The grade is for one exact copy of the source (4e96798bbca4), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement