FunnelBLOCK
Finally, a proxy that does what grep does for logs - filters out the noise. Stop carrying 70k tokens of tools you'll never use. It's like tree-shaking, but for MCP. 🚀
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Core infrastructure package for MCP Funnel. Provides transport implementations, secret management, logging, authentication utilities, and resilient connection management.
Installation
yarn add @mcp-funnel/core
Features
- Multiple Transport Implementations: stdio, SSE, HTTP, and WebSocket client transports for MCP communication
- Secret Management: Secure secret provider system with dotenv, process env, and inline providers
- Structured Logging: Pino-based logging with automatic credential redaction
- Connection Resilience: Exponential backoff and automatic reconnection management
- Authentication Utilities: Interfaces and types for implementing OAuth and bearer token auth
- Environment Resolution: Secure variable interpolation with ${VAR} patterns and circular reference detection
Key Components
Transports
Client transport implementations for the Model Context Protocol:
- StdioClientTransport: Communicates with child processes via stdin/stdout using newline-delimited JSON-RPC
- SSEClientTransport: Server-Sent Events transport with OAuth authentication support
- StreamableHttpClientTransport: HTTP-based streaming transport
- WebSocketClientTransport: WebSocket-based bidirectional transport
- BaseClientTransport: Abstract base class with shared transport functionality
All transports implement the MCP SDK Transport interface for seamless integration.
Secret Management
Secure secret provider system with fine-grained control:
- SecretManager: Orchestrates multiple secret providers with precedence rules
- Providers:
DotEnvProvider: Loads secrets from .env filesProcessEnvProvider: Filters process environment variables by prefixInlineProvider: Defines secrets directly in configuration- SecretProviderRegistry: Manages provider registration and discovery
- Security Features:
- Environment variable filtering to prevent credential lea
d4b577033725OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add web --env API_KEY=${API_KEY} --env AUTH_ENDPOINT=${AUTH_ENDPOINT} --env CLIENT_SECRET=${CLIENT_SECRET} --env DISABLE_INBOUND_AUTH=${DISABLE_INBOUND_AUTH} -- npx -y @mcp-funnel/[email protected]{
"mcpServers": {
"web": {
"command": "npx",
"args": [
"-y",
"@mcp-funnel/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"AUTH_ENDPOINT": "${AUTH_ENDPOINT}",
"CLIENT_SECRET": "${CLIENT_SECRET}",
"DISABLE_INBOUND_AUTH": "${DISABLE_INBOUND_AUTH}"
}
}
}
}Exposed tools (57)
50 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
big_tool | read | Test |
bridge_tool_request | write | Execute any discovered tool dynamically. First use get_tool_schema to understand the required arguments structure. |
create_issue | write | Create a GitHub issue |
create_pr | write | Create a PR |
create_pull_request | write | Create a pull request |
debug_info | read | Debug tool |
discover_tools_by_words | read | Search for tools by keywords in their descriptions. Returns matching tools that can be dynamically enabled to reduce context usage. |
echo | read | Echo back the message |
echo_tool | read | Echoes input |
env-server | read | Server with complex environment setup |
example | read | Example tool for testing |
exposed_tool | read | A tool that should be exposed |
filesystem-server | read | MCP server for filesystem operations |
fs-001 | read | MCP server for filesystem operations |
getResults | read | Query test results. Returns summary only by default. Specify testFile or testName (supports globs) to get detailed results showing all test statuses. Returns failed tests only when no filters specified. |
getSessionStatus | write | Get current status of a test session including run state and summary statistics. |
get_teams | read | Get teams |
get_tool_schema | read | Get the input schema for a specific tool. Use the returned schema to understand what arguments are required for bridge_tool_request. |
github-mcp-server | read | GitHub MCP Server |
hidden_tool | read | A tool that should be hidden |
hybrid-server | read | Server with both package and remote options |
js-debugger_debuggerCommand | read | Control execution flow for an existing debugger session. |
js-debugger_getScopeVariables | read | Inspect variables within a paused call frame scope. |
js-debugger_queryOutput | read | Retrieve buffered stdout, stderr, console, and exception output. |
js-debugger_startDebugSession | read | Spawn a Node.js target and attach a debugger session. |
large_tool | read | Returns large data |
list_files | read | List files in a directory |
list_issues | read | List GitHub issues |
lookup | read | Get detailed information about an NPM package |
mcp-funnel-server | read | MCP proxy server |
multi-package-server | read | Server with multiple package options |
normal_tool | read | Matches exposeTools |
npm-server | read | Server from NPM package |
oci-server | read | Server from OCI container |
official-server | read | Server from official registry |
other-server | read | Other server |
other_tool | read | Not in exposeTools |
private_tool | read | A private tool that should be hidden |
public_tool | read | A public tool that should be discoverable |
pypi-server | read | Server from PyPI package |
queryConsole | read | Search and filter console output from test session. |
read_file | read | Read contents of a file |
remote-server | read | Server accessed remotely |
search | read | Search for NPM packages |
secret_tool | read | A secret tool that should be hidden |
startSession | write | Start a vitest test session. Returns sessionId and summary stats. |
super_tool | read | Always visible |
test-cmd | read | Test |
test-server | read | Test server |
test__tool1 | read | [test] Tool 1 |
test__tool2 | read | [test] Tool 2 |
test_tool | read | A test tool |
tool | read | A simple tool |
tool1 | read | Tool 1 |
tool2 | read | Tool 2 |
unknown-server | read | Server with unknown type |
write_file | write | Write contents to a file |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
<!-- Fill in the the checklist above and check the ones you verified (you MUST verify all or give justification -->
packages/mcp/docs
* console.log(secrets.API_KEY); // Value from the last provider that resolved it
token: 'test-access-token-123',
token: 'test-refresh-token-123',
token: 'expired-refresh-token',
SSH_PRIVATE_KEY: '-----BEGIN RSA PRIVATE KEY-----...',
.mcp-funnel.example.json
.prettierignore
.yarnrc.yml
CLAUDE.md
README.md
packages/mcp/README.md
import { AuthenticationError } from '../../errors/authentication-error.js';import { AuthenticationError, OAuth2ErrorCode } from '../../errors/authentication-error.js';import { AuthenticationError } from '../../errors/authentication-error.js';import { AUTH_DEFAULT_EXPIRY_SECONDS } from '../../utils/index.js';import { AuthenticationError, OAuth2ErrorCode } from '../../errors/authentication-error.js';@modelcontextprotocol/sdk, zod, @eslint/js, @hono/zod-validator, @types/micromatch, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
zod
@modelcontextprotocol/sdk, zod, @types/node, esbuild, tsx, typescript, vitest
@modelcontextprotocol/sdk, chalk, emittery, execa, get-port, source-map, undici, ws
@modelcontextprotocol/sdk, @types/node, esbuild, tsx, vitest
- **Attack surface**: Each server has access to more credentials than necessary
- Both servers read from the same `.env` file
Gates applied: no_behavioural_pass.
d4b577033725full audit observations/trust-audit/mcp-server/chris-schra__funnel.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d4b577033725 | BLOCK | D | 66 | first audit |
Questions
What is the Funnel MCP server?
Finally, a proxy that does what grep does for logs - filters out the noise. Stop carrying 70k tokens of tools you'll never use. It's like tree-shaking, but for MCP. 🚀
What tools does Funnel expose?
57 in total: 50 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Funnel safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Funnel need?
It reads API_KEY, AUTH_ENDPOINT, CLIENT_SECRET, DISABLE_INBOUND_AUTH, INLINE_SECRET, MCP_FUNNEL_AUTH_TOKEN, MCP_TOKEN_STORAGE, OAUTH_BASE_URL, OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET, OAUTH_ISSUER and OAUTH_TOKEN_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Funnel run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mcp-funnel/web at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (d4b577033725), read on 2026-10-07. The repository is watched and re-audited when it changes.