Atlas / MCP servers / desko77 / 1C Templates

1C TemplatesCAUTION

mcp/desko77/1c-templates

MCP-сервер с семантическим поиском по шаблонам кода 1С (BSL). 2200+ шаблонов, CRUD веб-UI с Monaco Editor, ChromaDB + embeddings.

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
6 3r · 2w · 1d
Transport
streamable-http
License
—
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP-сервер с семантическим поиском по шаблонам кода 1С (BSL). 2262+ шаблонов из сообщества, CRUD веб-интерфейс с Monaco Editor, ChromaDB + embeddings для поиска по смыслу.

Возможности

  • Семантический поиск - гибридный (vector + full-text) поиск шаблонов кода на русском языке
  • 6 MCP-инструментов - поиск, просмотр, создание, редактирование, удаление шаблонов
  • Веб-интерфейс - полный CRUD с Monaco Editor и подсветкой BSL-синтаксиса
  • 2262+ шаблонов - предустановленная база шаблонов кода 1С в seed_templates.jsonl
  • Гибкие embeddings - OpenAI-совместимый API или локальная модель SentenceTransformer
  • Docker - готовый docker-compose для быстрого запуска

Установка из готового образа (рекомендуется)

Для обычного использования - без клонирования репозитория и без сборки. Готовый образ публикуется на Docker Hub: `desko77/1c-templates-mcp`.

Скачайте папку deploy/ (три файла: docker-compose.yml, .env.example, README.md) и запустите:

cd deploy
docker compose up -d              # CPU-режим
docker compose --profile gpu up -d  # GPU-режим (NVIDIA)

Подробная инструкция по настройке и обновлению - в deploy/README.md.

Быстрый старт (сборка из исходников)

Подходит для разработки и контрибуций. Собирает образ локально из текущего состояния репозитория.

git clone https://github.com/Desko77/1c-templates-mcp.git
cd 1c-templates-mcp

# CPU (универсально, без требований к GPU)
docker compose --profile cpu up -d

# ИЛИ GPU (NVIDIA, значительно быстрее индексация + поиск)
docker compose --profile gpu up -d

Сервер доступен:

  • Веб-интерфейс: http://localhost:8004
  • MCP endpoint: http://localhost:8004/mcp (POST, Streamable HTTP)

Разница между профилями:

  • `cpu` — контейнер template_search_mcp, без GPU-проброса. Первая индексация RoSBERTa на CPU ~5-10 мин. Работает везде.
  • `gpu`
Read from source at commit 24ef76d883b2OBSERVED · 2026-10-09
02

Exposed tools (6)

3 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_templatewriteAdd a new template to the database.
delete_templatedestructiveDelete a template by ID.
get_templatereadGet full template with code by ID.
list_templatesreadList templates (id, name, description, tags) without code — paginated.
templatesearchreadSearches the 1C code template database using hybrid semantic + full-text search.
update_templatewriteUpdate an existing template.
03

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (5 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:5
&& rm -rf /var/lib/apt/lists/*
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:14
&& rm -rf /app/bsl_console/.git
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
app/search.py:66
shutil.rmtree(MODEL_CACHE_PATH)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
app/search.py:271
shutil.rmtree(item)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/main.py:324
logging.info(f"Web UI: http://0.0.0.0:{config.HTTP_PORT}/")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_template
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
chromadb, fastmcp, fastapi, starlette, uvicorn, sentence-transformers, torch, numpy
Why it matters. 12 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
seed_templates.jsonl
seed_templates.jsonl
Why it matters. 3462170 bytes not read

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-09 · audit v0.4.1 · source sha 24ef76d883b2full audit observations/trust-audit/mcp-server/desko77__1c-templates.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0924ef76d883b2CAUTIONB85first audit
05

Questions

What is the 1C Templates MCP server?

MCP-сервер с семантическим поиском по шаблонам кода 1С (BSL). 2200+ шаблонов, CRUD веб-UI с Monaco Editor, ChromaDB + embeddings.

What tools does 1C Templates expose?

6 in total: 3 read-only, 2 that write, and 1 that can delete or overwrite (delete_template). Every one is listed on this page with its risk.

Is 1C Templates safe to connect to an agent?

With care. The audit graded it B (85/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does 1C Templates need?

It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does 1C Templates run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (24ef76d883b2), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement