Mcp Ts TemplateBLOCK
Agent-native TypeScript framework for building MCP servers.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
@cyanheads/mcp-ts-core Agent-native TypeScript framework for building MCP servers. Runtime infrastructure for your server, and the agent skills to build, test, and ship it.
[](./CHANGELOG.md) [](./LICENSE) [](https://modelcontextprotocol.io/specification/2026-07-28)
[](https://modelcontextprotocol.io/) [](https://www.typescriptlang.org/) [](https://bun.sh/)
Quick start · Capabilities · API reference · Examples
Build AI tools for anything you can describe
Connect an API, a dataset, or a workflow to an AI agent through the Model Context Protocol (MCP). Your project holds the domain code; @cyanheads/mcp-ts-core handles the auth, storage, logging, and transports underneath it.
Agent-native. Every scaffold ships the framework reference and a set of Agent Skills: workflows for designing tools, writing tests, reviewing security, and cutting releases. You decide what the server does; your agent follows the skills to build it.
The framework stays a dependency. Infrastructure fixes arrive as package upgrades. Run the maintenance skill and your agent bumps core, syncs the latest skills, and adopts what changed.
Quick start
Servers run on Bun, Node.js 24+, or Cloudflare Workers.
bunx @cyanheads/mcp-ts-core init my-mcp-server cd my-mcp-server bun install
The
807e5c69aa7bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-ts-core -- npx -y @cyanheads/[email protected]
claude mcp add mcp-ts-core -- npx -y @cyanheads/[email protected]
Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
data-explorer-ui | read | Interactive HTML app for the data explorer tool. Renders a sortable, filterable table with row selection. |
echo-app-ui | read | Interactive HTML app for the echo app tool. Displayed as a sandboxed iframe by MCP Apps-capable hosts. |
echo-resource | read | Echo the message component of the URI back as JSON with a timestamp. |
template-echo-resource | read | Echo a message from the URI. Replace this with your first real resource. |
Trust audit
BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
return yaml.load(stringToParse, { schema: yaml.YAML11_SCHEMA }) as T;exec(sql: string): void;
exec(sql: string): void;
const PRIVATE_HOSTNAMES = new Set(['localhost', 'metadata.google.internal', 'metadata.internal']);
| **Server credential** | The server's own upstream key is missing, or the upstream rejects it (401/403) | `ConfigurationError` — translated in the service, since the automatic status mapping yields `
Prereq: a GitHub PAT with `read:org` + `read:user` scopes stored in Keychain under the service name `mcp-publisher-github-pat`:
2. **No `git stash`, no `git reset --hard`, no `git restore .`, no `git clean -f`, no `git checkout -- .`.** These bypass safety and risk silent data loss. Read-only git (`status`, `diff`, `log`, `sho
* logger.info('Request', sanitizeInputForLogging({ user: 'alice', token: 'secret' }));hostOrigin = `http://127.0.0.1:${(host.address() as AddressInfo).port}`;sandboxOrigin = `http://127.0.0.1:${(sandbox.address() as AddressInfo).port}`;'',
.markdownlint.jsonc
.mcpbignore
import { UI_RESOURCE_URI } from '../../tools/definitions/template-data-explorer.app-tool.js';import packageJson from '../../package.json' with { type: 'json' };import { canvasNotFound } from '../../core/CanvasRegistry.js';import type { IDataCanvasProvider } from '../../core/IDataCanvasProvider.js';import { sniffSchema } from '../../core/schemaSniffer.js';Point your MCP client at `http://127.0.0.1:3010/mcp` (Streamable HTTP), or have the client launch it over stdio with `bun /absolute/path/to/dist/index.js`.
@hono/node-server, @modelcontextprotocol/server, @opentelemetry/api, hono, jose, pino, zod, @cloudflare/vitest-pool-workers
@cyanheads/mcp-ts-core, pino-pretty, @socketsecurity/bun-security-scanner, depcheck, fast-check, ignore, tsc-alias, typescript
- **DataCanvas:** An optional DuckDB workspace where agents run SQL across staged API results and export CSV, Parquet, or JSON. Agents share a workspace by passing its canvas token. Enable it with `CA
- **`notifications/cancelled` aborts the handler over HTTP** ([#311](https://github.com/cyanheads/mcp-ts-core/issues/311)). The notification arrives on its own POST with its own `Server`, so the SDK's
- **`ctx.elicit` completes over stateful Streamable HTTP.** Server-initiated requests now carry a session-unique wire ID registered on the `SessionStore`, so a response arriving on a later POST reache
- **A cancelled single-request POST's SSE stream closes immediately** ([#401](https://github.com/cyanheads/mcp-ts-core/issues/401)) — `notifications/cancelled` for an in-flight request now closes that
Gates applied: instruction_override, no_behavioural_pass.
807e5c69aa7bfull audit observations/trust-audit/mcp-server/cyanheads__mcp-ts-template.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 807e5c69aa7b | BLOCK | F | 39 | first audit |
Questions
What is the Mcp Ts Template MCP server?
Agent-native TypeScript framework for building MCP servers.
What tools does Mcp Ts Template expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcp Ts Template safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (39/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Mcp Ts Template need?
It reads ELEVEN_KEY and OPENAI_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mcp Ts Template run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as {{PACKAGE_NAME}} at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (807e5c69aa7b), read on 2026-10-07. The repository is watched and re-audited when it changes.