Atlas / MCP servers / chris-schra / Funnel

FunnelBLOCK

mcp/chris-schra/funnel

Finally, a proxy that does what grep does for logs - filters out the noise. Stop carrying 70k tokens of tools you'll never use. It's like tree-shaking, but for MCP. 🚀

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
57 50r · 7w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
157
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Core infrastructure package for MCP Funnel. Provides transport implementations, secret management, logging, authentication utilities, and resilient connection management.

Installation

yarn add @mcp-funnel/core

Features

  • Multiple Transport Implementations: stdio, SSE, HTTP, and WebSocket client transports for MCP communication
  • Secret Management: Secure secret provider system with dotenv, process env, and inline providers
  • Structured Logging: Pino-based logging with automatic credential redaction
  • Connection Resilience: Exponential backoff and automatic reconnection management
  • Authentication Utilities: Interfaces and types for implementing OAuth and bearer token auth
  • Environment Resolution: Secure variable interpolation with ${VAR} patterns and circular reference detection

Key Components

Transports

Client transport implementations for the Model Context Protocol:

  • StdioClientTransport: Communicates with child processes via stdin/stdout using newline-delimited JSON-RPC
  • SSEClientTransport: Server-Sent Events transport with OAuth authentication support
  • StreamableHttpClientTransport: HTTP-based streaming transport
  • WebSocketClientTransport: WebSocket-based bidirectional transport
  • BaseClientTransport: Abstract base class with shared transport functionality

All transports implement the MCP SDK Transport interface for seamless integration.

Secret Management

Secure secret provider system with fine-grained control:

  • SecretManager: Orchestrates multiple secret providers with precedence rules
  • Providers:
  • DotEnvProvider: Loads secrets from .env files
  • ProcessEnvProvider: Filters process environment variables by prefix
  • InlineProvider: Defines secrets directly in configuration
  • SecretProviderRegistry: Manages provider registration and discovery
  • Security Features:
  • Environment variable filtering to prevent credential lea
Read from source at commit d4b577033725OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add web --env API_KEY=${API_KEY} --env AUTH_ENDPOINT=${AUTH_ENDPOINT} --env CLIENT_SECRET=${CLIENT_SECRET} --env DISABLE_INBOUND_AUTH=${DISABLE_INBOUND_AUTH} -- npx -y @mcp-funnel/[email protected]
claude-desktop
{
  "mcpServers": {
    "web": {
      "command": "npx",
      "args": [
        "-y",
        "@mcp-funnel/[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "AUTH_ENDPOINT": "${AUTH_ENDPOINT}",
        "CLIENT_SECRET": "${CLIENT_SECRET}",
        "DISABLE_INBOUND_AUTH": "${DISABLE_INBOUND_AUTH}"
      }
    }
  }
}
03

Exposed tools (57)

50 read · 7 write · 0 destructive.

ToolRiskDescription
big_toolreadTest
bridge_tool_requestwriteExecute any discovered tool dynamically. First use get_tool_schema to understand the required arguments structure.
create_issuewriteCreate a GitHub issue
create_prwriteCreate a PR
create_pull_requestwriteCreate a pull request
debug_inforeadDebug tool
discover_tools_by_wordsreadSearch for tools by keywords in their descriptions. Returns matching tools that can be dynamically enabled to reduce context usage.
echoreadEcho back the message
echo_toolreadEchoes input
env-serverreadServer with complex environment setup
examplereadExample tool for testing
exposed_toolreadA tool that should be exposed
filesystem-serverreadMCP server for filesystem operations
fs-001readMCP server for filesystem operations
getResultsreadQuery test results. Returns summary only by default. Specify testFile or testName (supports globs) to get detailed results showing all test statuses. Returns failed tests only when no filters specified.
getSessionStatuswriteGet current status of a test session including run state and summary statistics.
get_teamsreadGet teams
get_tool_schemareadGet the input schema for a specific tool. Use the returned schema to understand what arguments are required for bridge_tool_request.
github-mcp-serverreadGitHub MCP Server
hidden_toolreadA tool that should be hidden
hybrid-serverreadServer with both package and remote options
js-debugger_debuggerCommandreadControl execution flow for an existing debugger session.
js-debugger_getScopeVariablesreadInspect variables within a paused call frame scope.
js-debugger_queryOutputreadRetrieve buffered stdout, stderr, console, and exception output.
js-debugger_startDebugSessionreadSpawn a Node.js target and attach a debugger session.
large_toolreadReturns large data
list_filesreadList files in a directory
list_issuesreadList GitHub issues
lookupreadGet detailed information about an NPM package
mcp-funnel-serverreadMCP proxy server
multi-package-serverreadServer with multiple package options
normal_toolreadMatches exposeTools
npm-serverreadServer from NPM package
oci-serverreadServer from OCI container
official-serverreadServer from official registry
other-serverreadOther server
other_toolreadNot in exposeTools
private_toolreadA private tool that should be hidden
public_toolreadA public tool that should be discoverable
pypi-serverreadServer from PyPI package
queryConsolereadSearch and filter console output from test session.
read_filereadRead contents of a file
remote-serverreadServer accessed remotely
searchreadSearch for NPM packages
secret_toolreadA secret tool that should be hidden
startSessionwriteStart a vitest test session. Returns sessionId and summary stats.
super_toolreadAlways visible
test-cmdreadTest
test-serverreadTest server
test__tool1read[test] Tool 1
test__tool2read[test] Tool 2
test_toolreadA test tool
toolreadA simple tool
tool1readTool 1
tool2readTool 2
unknown-serverreadServer with unknown type
write_filewriteWrite contents to a file
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHPrompt injection · prompt.hidden_comment · CWE-94, CWE-1427
.haino/personas/coordinator.md:91
<!-- Fill in the the checklist above and check the ones you verified (you MUST verify all or give justification -->
Why it matters. directive hidden in a comment the user does not see rendered
Fix. remove the comment
MEDIUMInventory / provenance · inv.symlink · CWE-1104
packages/mcp/docs
packages/mcp/docs
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/core/src/secrets/secret-manager.ts:53
* console.log(secrets.API_KEY); // Value from the last provider that resolved it
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/auth/src/provider/__tests__/memory-oauth-storage.test.ts:99
token: 'test-access-token-123',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/auth/src/provider/__tests__/memory-oauth-storage.test.ts:131
token: 'test-refresh-token-123',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/auth/src/provider/__tests__/memory-oauth-storage.test.ts:223
token: 'expired-refresh-token',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/mcp/test/security/env-security-simple.test.ts:187
SSH_PRIVATE_KEY: '-----BEGIN RSA PRIVATE KEY-----...',
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp-funnel.example.json
.mcp-funnel.example.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.yarnrc.yml
.yarnrc.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
README.md
README.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
packages/mcp/README.md
packages/mcp/README.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/auth/src/__tests__/base-oauth-provider/ensure-valid-token.test.ts:3
import { AuthenticationError } from '../../errors/authentication-error.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/auth/src/__tests__/base-oauth-provider/handle-token-request-error.test.ts:3
import { AuthenticationError, OAuth2ErrorCode } from '../../errors/authentication-error.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/auth/src/__tests__/base-oauth-provider/process-token-response.test.ts:3
import { AuthenticationError } from '../../errors/authentication-error.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/auth/src/__tests__/base-oauth-provider/process-token-response.test.ts:4
import { AUTH_DEFAULT_EXPIRY_SECONDS } from '../../utils/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/auth/src/__tests__/base-oauth-provider/request-token-with-retry.test.ts:3
import { AuthenticationError, OAuth2ErrorCode } from '../../errors/authentication-error.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @eslint/js, @hono/zod-validator, @types/micromatch, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/auth/package.json
zod
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/commands/core/package.json
@modelcontextprotocol/sdk, zod, @types/node, esbuild, tsx, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/commands/js-debugger/package.json
@modelcontextprotocol/sdk, chalk, emittery, execa, get-port, source-map, undici, ws
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/commands/npm-lookup/package.json
@modelcontextprotocol/sdk, @types/node, esbuild, tsx, vitest
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/secret-management.md:48
- **Attack surface**: Each server has access to more credentials than necessary
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/secret-management.md:233
- Both servers read from the same `.env` file
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d4b577033725full audit observations/trust-audit/mcp-server/chris-schra__funnel.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d4b577033725BLOCKD66first audit
06

Questions

What is the Funnel MCP server?

Finally, a proxy that does what grep does for logs - filters out the noise. Stop carrying 70k tokens of tools you'll never use. It's like tree-shaking, but for MCP. 🚀

What tools does Funnel expose?

57 in total: 50 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Funnel safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Funnel need?

It reads API_KEY, AUTH_ENDPOINT, CLIENT_SECRET, DISABLE_INBOUND_AUTH, INLINE_SECRET, MCP_FUNNEL_AUTH_TOKEN, MCP_TOKEN_STORAGE, OAUTH_BASE_URL, OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET, OAUTH_ISSUER and OAUTH_TOKEN_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Funnel run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mcp-funnel/web at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (d4b577033725), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement