1C TemplatesCAUTION
MCP-сервер с семантическим поиском по шаблонам кода 1С (BSL). 2200+ шаблонов, CRUD веб-UI с Monaco Editor, ChromaDB + embeddings.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP-сервер с семантическим поиском по шаблонам кода 1С (BSL). 2262+ шаблонов из сообщества, CRUD веб-интерфейс с Monaco Editor, ChromaDB + embeddings для поиска по смыслу.
Возможности
- Семантический поиск - гибридный (vector + full-text) поиск шаблонов кода на русском языке
- 6 MCP-инструментов - поиск, просмотр, создание, редактирование, удаление шаблонов
- Веб-интерфейс - полный CRUD с Monaco Editor и подсветкой BSL-синтаксиса
- 2262+ шаблонов - предустановленная база шаблонов кода 1С в
seed_templates.jsonl - Гибкие embeddings - OpenAI-совместимый API или локальная модель SentenceTransformer
- Docker - готовый docker-compose для быстрого запуска
Установка из готового образа (рекомендуется)
Для обычного использования - без клонирования репозитория и без сборки. Готовый образ публикуется на Docker Hub: `desko77/1c-templates-mcp`.
Скачайте папку deploy/ (три файла: docker-compose.yml, .env.example, README.md) и запустите:
cd deploy docker compose up -d # CPU-режим docker compose --profile gpu up -d # GPU-режим (NVIDIA)
Подробная инструкция по настройке и обновлению - в deploy/README.md.
Быстрый старт (сборка из исходников)
Подходит для разработки и контрибуций. Собирает образ локально из текущего состояния репозитория.
git clone https://github.com/Desko77/1c-templates-mcp.git cd 1c-templates-mcp # CPU (универсально, без требований к GPU) docker compose --profile cpu up -d # ИЛИ GPU (NVIDIA, значительно быстрее индексация + поиск) docker compose --profile gpu up -d
Сервер доступен:
- Веб-интерфейс:
http://localhost:8004 - MCP endpoint:
http://localhost:8004/mcp(POST, Streamable HTTP)
Разница между профилями:
- `cpu` — контейнер
template_search_mcp, без GPU-проброса. Первая индексация RoSBERTa на CPU ~5-10 мин. Работает везде. - `gpu`
24ef76d883b2OBSERVED · 2026-10-09Exposed tools (6)
3 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_template | write | Add a new template to the database. |
delete_template | destructive | Delete a template by ID. |
get_template | read | Get full template with code by ID. |
list_templates | read | List templates (id, name, description, tags) without code — paginated. |
templatesearch | read | Searches the 1C code template database using hybrid semantic + full-text search. |
update_template | write | Update an existing template. |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (5 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
&& rm -rf /var/lib/apt/lists/*
&& rm -rf /app/bsl_console/.git
shutil.rmtree(MODEL_CACHE_PATH)
shutil.rmtree(item)
logging.info(f"Web UI: http://0.0.0.0:{config.HTTP_PORT}/")delete_template
chromadb, fastmcp, fastapi, starlette, uvicorn, sentence-transformers, torch, numpy
seed_templates.jsonl
Gates applied: no_behavioural_pass, no_license.
24ef76d883b2full audit observations/trust-audit/mcp-server/desko77__1c-templates.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 24ef76d883b2 | CAUTION | B | 85 | first audit |
Questions
What is the 1C Templates MCP server?
MCP-сервер с семантическим поиском по шаблонам кода 1С (BSL). 2200+ шаблонов, CRUD веб-UI с Monaco Editor, ChromaDB + embeddings.
What tools does 1C Templates expose?
6 in total: 3 read-only, 2 that write, and 1 that can delete or overwrite (delete_template). Every one is listed on this page with its risk.
Is 1C Templates safe to connect to an agent?
With care. The audit graded it B (85/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does 1C Templates need?
It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does 1C Templates run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (24ef76d883b2), read on 2026-10-09. The repository is watched and re-audited when it changes.