Atlas / MCP servers / cyanheads / Mcp Ts Template

Mcp Ts TemplateBLOCK

mcp/cyanheads/mcp-ts-template

Agent-native TypeScript framework for building MCP servers.

Verdict
BLOCK
Grade
F
Trust score
39 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
152
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

@cyanheads/mcp-ts-core Agent-native TypeScript framework for building MCP servers. Runtime infrastructure for your server, and the agent skills to build, test, and ship it.

[](./CHANGELOG.md) [](./LICENSE) [](https://modelcontextprotocol.io/specification/2026-07-28)

[](https://modelcontextprotocol.io/) [](https://www.typescriptlang.org/) [](https://bun.sh/)

Quick start · Capabilities · API reference · Examples

Build AI tools for anything you can describe

Connect an API, a dataset, or a workflow to an AI agent through the Model Context Protocol (MCP). Your project holds the domain code; @cyanheads/mcp-ts-core handles the auth, storage, logging, and transports underneath it.

Agent-native. Every scaffold ships the framework reference and a set of Agent Skills: workflows for designing tools, writing tests, reviewing security, and cutting releases. You decide what the server does; your agent follows the skills to build it.

The framework stays a dependency. Infrastructure fixes arrive as package upgrades. Run the maintenance skill and your agent bumps core, syncs the latest skills, and adopts what changed.

Quick start

Servers run on Bun, Node.js 24+, or Cloudflare Workers.

bunx @cyanheads/mcp-ts-core init my-mcp-server
cd my-mcp-server
bun install

The

Read from source at commit 807e5c69aa7bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-ts-core -- npx -y @cyanheads/[email protected]
claude-code (npm)
claude mcp add mcp-ts-core -- npx -y @cyanheads/[email protected]
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
data-explorer-uireadInteractive HTML app for the data explorer tool. Renders a sortable, filterable table with row selection.
echo-app-uireadInteractive HTML app for the echo app tool. Displayed as a sandboxed iframe by MCP Apps-capable hosts.
echo-resourcereadEcho the message component of the URI back as JSON with a timestamp.
template-echo-resourcereadEcho a message from the URI. Replace this with your first real resource.
04

Trust audit

BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (8 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/utils/parsing/yamlParser.ts:105
return yaml.load(stringToParse, { schema: yaml.YAML11_SCHEMA }) as T;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/services/mirror/sqlite/handle.ts:35
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/services/mirror/sqlite/handle.ts:73
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/utils/network/fetchWithTimeout.ts:314
const PRIVATE_HOSTNAMES = new Set(['localhost', 'metadata.google.internal', 'metadata.internal']);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
framework-skills/design-mcp-server/SKILL.md:439
| **Server credential** | The server's own upstream key is missing, or the upstream rejects it (401/403) | `ConfigurationError` — translated in the service, since the automatic status mapping yields `
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
framework-skills/release-and-publish/SKILL.md:218
Prereq: a GitHub PAT with `read:org` + `read:user` scopes stored in Keychain under the service name `mcp-publisher-github-pat`:
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
framework-skills/orchestrations/SKILL.md:55
2. **No `git stash`, no `git reset --hard`, no `git restore .`, no `git clean -f`, no `git checkout -- .`.** These bypass safety and risk silent data loss. Read-only git (`status`, `diff`, `log`, `sho
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/utils/security/sanitization.ts:1077
* logger.info('Request', sanitizeInputForLogging({ user: 'alice', token: 'secret' }));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/testing/apps/host-pages.ts:64
hostOrigin = `http://127.0.0.1:${(host.address() as AddressInfo).port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/testing/apps/host-pages.ts:65
sandboxOrigin = `http://127.0.0.1:${(sandbox.address() as AddressInfo).port}`;
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/testing/fuzz.ts:377
'',
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.jsonc
.markdownlint.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/mcp-server/resources/definitions/data-explorer-ui.app-resource.ts:14
import { UI_RESOURCE_URI } from '../../tools/definitions/template-data-explorer.app-tool.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/index.ts:14
import packageJson from '../../package.json' with { type: 'json' };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/canvas/providers/duckdb/DuckdbProvider.ts:32
import { canvasNotFound } from '../../core/CanvasRegistry.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/canvas/providers/duckdb/DuckdbProvider.ts:33
import type { IDataCanvasProvider } from '../../core/IDataCanvasProvider.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/canvas/providers/duckdb/DuckdbProvider.ts:34
import { sniffSchema } from '../../core/schemaSniffer.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:80
Point your MCP client at `http://127.0.0.1:3010/mcp` (Streamable HTTP), or have the client launch it over stdio with `bun /absolute/path/to/dist/index.js`.
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@hono/node-server, @modelcontextprotocol/server, @opentelemetry/api, hono, jose, pino, zod, @cloudflare/vitest-pool-workers
Why it matters. 54 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
templates/package.json
@cyanheads/mcp-ts-core, pino-pretty, @socketsecurity/bun-security-scanner, depcheck, fast-check, ignore, tsc-alias, typescript
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:199
- **DataCanvas:** An optional DuckDB workspace where agents run SQL across staged API results and export CSV, Parquet, or JSON. Agents share a workspace by passing its canvas token. Enable it with `CA
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
changelog/0.11.x/0.11.2.md:50
- **`notifications/cancelled` aborts the handler over HTTP** ([#311](https://github.com/cyanheads/mcp-ts-core/issues/311)). The notification arrives on its own POST with its own `Server`, so the SDK's
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
changelog/0.11.x/0.11.5.md:27
- **`ctx.elicit` completes over stateful Streamable HTTP.** Server-initiated requests now carry a session-unique wire ID registered on the `SessionStore`, so a response arriving on a later POST reache
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
changelog/0.12.x/0.12.9.md:27
- **A cancelled single-request POST's SSE stream closes immediately** ([#401](https://github.com/cyanheads/mcp-ts-core/issues/401)) — `notifications/cancelled` for an in-flight request now closes that
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 807e5c69aa7bfull audit observations/trust-audit/mcp-server/cyanheads__mcp-ts-template.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07807e5c69aa7bBLOCKF39first audit
06

Questions

What is the Mcp Ts Template MCP server?

Agent-native TypeScript framework for building MCP servers.

What tools does Mcp Ts Template expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mcp Ts Template safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (39/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Mcp Ts Template need?

It reads ELEVEN_KEY and OPENAI_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcp Ts Template run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as {{PACKAGE_NAME}} at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (807e5c69aa7b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement