Atlas / MCP servers / epistates / turbomcp

turbomcpBLOCK

mcp/epistates/turbomcp

A full featured, enterprise grade rust MCP SDK

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
98
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://crates.io/crates/turbomcp) [](https://docs.rs/turbomcp) [](./LICENSE)

A ground-up Rust SDK for the Model Context Protocol — both halves of the protocol, server and client — with a macro-driven, zero-boilerplate surface and strict spec compliance as a feature.

Status: `4.0.0-alpha.5` — a prerelease for community testing. v4 is a from-scratch rewrite of TurboMCP; the stable line is 3.x. Edition 2024, MSRV 1.88. It interoperates with the official Rust, TypeScript, Python and Go SDKs in both directions, on both revisions, and both halves are scored against the official MCP conformance suite: 231 successful server assertions and 488 distinct successful client scenario/check pairs using pinned client fixture corrections, with zero failures, skips, or warnings. All three advertised revisions (2025-06-18, 2025-11-25, 2026-07-28) are dated and frozen; 2026-07-28 is generated from the released schema/2026-07-28/, not the RC. Found something broken or unergonomic? Please open an issue.

What you get

  • One macro defines a server. #[server] over an impl block turns

#[tool] / #[resource] / #[prompt] methods into a fully-wired MCP server. The macro generates schema derivation code; schema values are initialized once at runtime and cloned for callers, and the advertised capabilities are derived from which markers are present — they can't drift from the implementation.

  • Three protocol revisions, one handler. The same server answers

2025-06-18, 2025-11-25, and 2026-07-28. Your handlers speak version-neutral types; the version-specific wire shapes are conversions, not signature changes — including dropping, per session, the fields a revision predates. Pin the set

Read from source at commit c54ac0128e5cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add turbomcp-interop-ts -- npx -y turbomcp-interop-ts
claude-desktop
{
  "mcpServers": {
    "turbomcp-interop-ts": {
      "command": "npx",
      "args": [
        "-y",
        "turbomcp-interop-ts"
      ]
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
addwriteAdd two integers.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (13 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (15)

HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
crates/turbomcp-auth/src/network.rs:366
"https://169.254.169.254/latest/meta-data/", // cloud metadata
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/turbomcp-auth/src/client/discovery.rs:432
"http://192.0.2.10/token",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/turbomcp-auth/src/client/discovery.rs:455
"https://192.0.2.10/token",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/turbomcp-auth/src/client/discovery.rs:460
"http://127.0.0.1:3456/cb",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/turbomcp-auth/src/client/discovery.rs:461
"http://127.9.9.9/cb",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/turbomcp-auth/src/client/discovery.rs:539
let c = authorization_server_wellknown_candidates("http://127.0.0.1:3456").unwrap();
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benches/regression/performance_regression_detector.rs:226
("json_parsing_typical", 2500.0),     // 2.5μs
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benches/regression/performance_regression_detector.rs:227
("schema_validation_tool_call", 45000.0), // 45μs
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
crates/turbomcp-server/tests/masking.rs:15
const SECRET: &str = "postgres://admin:[email protected]:5432";
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
CHANGELOG.md:4029
- Cloud metadata: 169.254.169.254, 168.63.129.16
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:670
`Mcp-Session-Id` was replayed on every later POST forever, against a server
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2461
- **`RequestContext` unified with bidirectional session state** — `crates/turbomcp-types` / `turbomcp-core`. Server-initiated requests (elicitation, sampling, roots) and inbound request handling now s
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2590
- **MCP 2025-11-25 streamable HTTP transport, full lifecycle** — `crates/turbomcp-server/src/transport/http.rs` now implements the complete spec shape: `POST /` + `POST /mcp` for JSON-RPC requests, `G
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2600
- **SSE primer event for resumability** — `handle_sse` now yields an initial `Event::default().id("<session>-0").data("")` before draining the per-subscriber channel, satisfying the MCP spec's "server
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:2604
- **Comprehensive HTTP spec-compliance integration tests** — New `crates/turbomcp-server/tests/http_transport_spec.rs` covers session-id handshake, `notifications/initialized` → `202`, client JSON-RPC
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c54ac0128e5cfull audit observations/trust-audit/mcp-server/epistates__turbomcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c54ac0128e5cBLOCKD69first audit
06

Questions

What is the turbomcp MCP server?

A full featured, enterprise grade rust MCP SDK

What tools does turbomcp expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is turbomcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does turbomcp need?

No credential environment variables were found in its source, so it appears to need none.

How does turbomcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as turbomcp-interop-ts.

How current is this page?

The grade is for one exact copy of the source (c54ac0128e5c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement