Atlas / MCP servers / boguan / Create App

Create AppCAUTION

mcp/boguan/create-app

A CLI tool for quickly scaffolding Model Context Protocol (MCP) server applications with TypeScript support and modern development tooling

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio
License
MIT
Stars
57
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful scaffolding toolkit for creating Model Context Protocol (MCP) applications with modern development practices.

Overview

create-mcp-app is a monorepo project that provides tools and templates for building MCP applications. It uses modern development practices and tools to ensure a smooth development experience. The project is designed to help developers quickly set up and start building MCP applications with best practices and modern tooling.

Features

  • 🚀 Instant project scaffolding for MCP applications
  • 📦 First-class TypeScript support with strict type checking
  • 🔧 Modern development toolchain with ESLint, Prettier, and Husky
  • 🎯 Extensible and customizable templates for both server and client
  • 🏗️ Monorepo architecture with Turborepo for efficient development
  • 📝 Comprehensive documentation and examples
  • 🔍 Built-in testing setup with Jest
  • 🛠️ Development tools and utilities

Project Structure

This project is organized as a monorepo using Turborepo, containing:

create-mcp-app/
├── apps/                          # Application packages
│   ├── create-mcp-server-app/     # Server application template
│   │   ├── src/                   # Source code
│   │   ├── boilerplate/          # Template files
│   │   ├── docs/                 # Documentation
│   │   └── dist/                 # Build output
│   │
│   └── create-mcp-client-app/    # Client application template
│       ├── src/                   # Source code
│       ├── boilerplate/          # Template files
│       ├── docs/                 # Documentation
│       └── dist/                 # Build output
│
├── packages/                      # Shared packages and configurations
├── .vscode/                      # VS Code configuration
└── package.json                  # Root package configuration

Quick Start

To create a new MCP server application (see detailed guide):

npx create-mcp-server-app@latest my-mcp-s
Read from source at commit c4b5d39a494cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add cli --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y @mcp/[email protected]
claude-desktop
{
  "mcpServers": {
    "cli": {
      "command": "npx",
      "args": [
        "-y",
        "@mcp/[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
addwriteAdd two numbers
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (9)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
apps/create-mcp-client-app/boilerplate/base/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/create-mcp-client-app/boilerplate/base/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/create-mcp-server-app/boilerplate/extras/server-type/advanced/server/server.ts:2
import packageJson from "../../package.json" with { type: "json" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/create-mcp-server-app/boilerplate/extras/server-type/high-level/server/server.ts:2
import packageJson from "../../package.json" with { type: "json" };
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/create-mcp-client-app/boilerplate/base/package.json
@anthropic-ai/sdk, @modelcontextprotocol/sdk, chalk, dotenv, zod, zod-to-json-schema, @types/node, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/create-mcp-client-app/package.json
@clack/prompts, commander, execa, fs-extra, sort-package-json, @changesets/changelog-github, @changesets/cli, @types/fs-extra
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/create-mcp-server-app/boilerplate/base/package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/create-mcp-server-app/package.json
@clack/prompts, commander, execa, fs-extra, sort-package-json, @changesets/changelog-github, @changesets/cli, @types/fs-extra
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
tsup, prettier, turbo
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c4b5d39a494cfull audit observations/trust-audit/mcp-server/boguan__create-app.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c4b5d39a494cCAUTIONB83first audit
06

Questions

What is the Create App MCP server?

A CLI tool for quickly scaffolding Model Context Protocol (MCP) server applications with TypeScript support and modern development tooling

What tools does Create App expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Create App safe to connect to an agent?

With care. The audit graded it B (83/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Create App need?

It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Create App run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mcp/cli at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (c4b5d39a494c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement