Mcp-ClientSAFE
Typescript mcp client library.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A TypeScript implementation of a Model Context Protocol (MCP) client for LLM agents.
Installation
npm install mcp-client
Features
- Full implementation of the MCP specification
- Support for both stdio and HTTP+SSE transports
- Built-in MCP server process management
- Integration with Claude's native tool calling
- Type-safe API
- Event-based architecture
- Promise-based async/await API
- Support for all MCP operations:
- Resources
- Tools
- Prompts
- Sampling
Usage
Using with MCP Servers
The most common way to use MCP Client is with standard MCP servers via npx. Create a configuration file (mcp-config.json):
{
"mcpServers": {
"memory": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-memory"
]
},
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"/path/to/allowed/directory"
]
},
"brave-search": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-brave-search"
],
"env": {
"BRAVE_API_KEY": "your-api-key"
}
}
}
}Then use the MCPConnectionManager to connect to your servers:
import { MCPConnectionManager } from 'mcp-client';
const manager = new MCPConnectionManager();
await manager.initialize('./mcp-config.json');
// Get clients for specific servers
const memoryClient = manager.getClient('memory');
const fsClient = manager.getClient('filesystem');
// Use tools from the servers
const memoryTools = await memoryClient?.listTools();
const fsTools = await fsClient?.listTools();
// Clean up when done
await manager.cleanup();Integration with Claude
The client is designed to work seamlessly with Claude's native tool calling:
import { Anthropic } from '@anthropic-ai/sdk';
import { MCPConnectionManager } from 'mcp-client';
// Initialize 9ea7d05de014OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-client --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-client": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
calculator | read | Performs basic arithmetic calculations |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
@anthropic-ai/sdk, dotenv, @types/node, typescript
uuid, events, @types/node, @types/uuid, typescript, @types/jest, jest, ts-jest
Gates applied: no_behavioural_pass, no_license.
9ea7d05de014full audit observations/trust-audit/mcp-server/edanyal__mcp-client.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 9ea7d05de014 | SAFE | B | 89 | first audit |
Questions
What is the Mcp-Client MCP server?
Typescript mcp client library.
What tools does Mcp-Client expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcp-Client safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mcp-Client need?
It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (9ea7d05de014), read on 2026-10-08. The repository is watched and re-audited when it changes.