Atlas / MCP servers / edanyal / Mcp-Client

Mcp-ClientSAFE

mcp/edanyal/mcp-client

Typescript mcp client library.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
—
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A TypeScript implementation of a Model Context Protocol (MCP) client for LLM agents.

Installation

npm install mcp-client

Features

  • Full implementation of the MCP specification
  • Support for both stdio and HTTP+SSE transports
  • Built-in MCP server process management
  • Integration with Claude's native tool calling
  • Type-safe API
  • Event-based architecture
  • Promise-based async/await API
  • Support for all MCP operations:
  • Resources
  • Tools
  • Prompts
  • Sampling

Usage

Using with MCP Servers

The most common way to use MCP Client is with standard MCP servers via npx. Create a configuration file (mcp-config.json):

{
"mcpServers": {
"memory": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-memory"
]
},
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/path/to/allowed/directory"
]
},
"brave-search": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-brave-search"
],
"env": {
"BRAVE_API_KEY": "your-api-key"
}
}
}
}

Then use the MCPConnectionManager to connect to your servers:

import { MCPConnectionManager } from 'mcp-client';

const manager = new MCPConnectionManager();
await manager.initialize('./mcp-config.json');

// Get clients for specific servers
const memoryClient = manager.getClient('memory');
const fsClient = manager.getClient('filesystem');

// Use tools from the servers
const memoryTools = await memoryClient?.listTools();
const fsTools = await fsClient?.listTools();

// Clean up when done
await manager.cleanup();

Integration with Claude

The client is designed to work seamlessly with Claude's native tool calling:

import { Anthropic } from '@anthropic-ai/sdk';
import { MCPConnectionManager } from 'mcp-client';

// Initialize 
Read from source at commit 9ea7d05de014OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-client --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-client": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
calculatorreadPerforms basic arithmetic calculations
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/memory-app/package.json
@anthropic-ai/sdk, dotenv, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
uuid, events, @types/node, @types/uuid, typescript, @types/jest, jest, ts-jest
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 9ea7d05de014full audit observations/trust-audit/mcp-server/edanyal__mcp-client.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-089ea7d05de014SAFEB89first audit
06

Questions

What is the Mcp-Client MCP server?

Typescript mcp client library.

What tools does Mcp-Client expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mcp-Client safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Mcp-Client need?

It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (9ea7d05de014), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement