Atlas / MCP servers / fiberplane / Lite

LiteCAUTION

mcp/fiberplane/lite

Lightweight, composable MCP framework for TypeScript

Verdict
CAUTION
Grade
B
Trust score
80 /100
Exposed tools
92 89r · 3w · 0d
Transport
streamable-http
License
MIT
Stars
119
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Hello and welcome! This folder has been automatically generated by @changesets/cli, a build tool that works with multi-package repos, or single-package repos to help you version and publish your code. You can find the full documentation for it in our repository

We have a quick list of common questions to get you started engaging with this project in our documentation

Read from source at commit 374270907a21OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add starter-mcp-supabase --env ELEVENLABS_API_KEY=${ELEVENLABS_API_KEY} -- npx -y starter-mcp-supabase
claude-desktop
{
  "mcpServers": {
    "starter-mcp-supabase": {
      "command": "npx",
      "args": [
        "-y",
        "starter-mcp-supabase"
      ],
      "env": {
        "ELEVENLABS_API_KEY": "${ELEVENLABS_API_KEY}"
      }
    }
  }
}
03

Exposed tools (92)

89 read · 3 write · 0 destructive.

ToolRiskDescription
WidgetreadInteractive widget for items
addwrite
add_itemwrite
analyzereadAnalyze text with specific parameters
annotatedMessageread
audiencereadTarget audience level
auth-testread
calculateread
calculateSumread
cancel-elicitationread
codereadCode to review
collectFormDataread
complex-auth-testread
concatread
conceptreadThe concept to explain
confirmActionread
consistency-testread
contentreadContent to analyze
craft_wonky_promptread
decline-elicitationread
deleteDatabaseread
direct-auth-testread
direct-no-auth-testread
doubleread
doubleNumberread
dynamic-toolread
dynamicGreetread
echoread
empty-schema-elicitationread
enableDynamicToolread
error-response-elicitationread
error-response-samplingread
errorToolread
experimental-featureread
fetchWebPageread
fileSearchread
focusreadAnalysis focus
full-elicitationread
full-samplingread
generateIdread
getConfigread
getDataread
getTinyImageread
getWeatherread
greetread
greetingreadGenerate a greeting message
image-samplingread
includeExamplesreadInclude practical examples
invalid-response-elicitationread
invalid-response-samplingread
invalidOutputread
languagereadProgramming language
lengthreadSummary length
listFilesread
list_itemsread
longRunningOperationread
middleware-testread
multiplyread
myToolread
no-auth-testread
no-elicitationread
no-middleware-auth-testread
no-samplingread
optional-fields-elicitationread
pingread
queryDataread
sampling-with-preferencesread
searchread
sequential-elicitationsread
sequential-samplingread
setConfigread
severityreadReview severity
simpleEchoread
slow-toolread
strictnessreadReview strictness level
stylereadDocumentation style
sumread
summarizewriteCreate a summary prompt
testread
test-capabilitiesread
test-toolread
textreadText to summarize
text_to_speechread
timeout-elicitationread
timeout-samplingread
tool-with-metadataread
tool-without-metadataread
topicreadResearch topic
unvalidatedread
validatedreadPrompt with runtime validation
with-elicitationread
with-samplingread
04

Trust audit

CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (22)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
templates/starter-mcp-supabase/supabase/functions/mcp-server/index.ts:73
curl -i --location --request POST 'http://127.0.0.1:54321/functions/v1/mcp-server/mcp' \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
templates/starter-mcp-supabase/supabase/functions/mcp-server/index.ts:80
curl 'http://127.0.0.1:54321/functions/v1/mcp-server/health'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/tests/integration/auth-info.test.ts:396
token: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.test",
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/auth-clerk/.dev.vars.example
.dev.vars.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
README.md
README.md
Why it matters. link not followed
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
examples/cloudflare-worker-kv/worker-configuration.d.ts:2266
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
examples/cloudflare-worker-kv/worker-configuration.d.ts:7064
exec(query: string): Promise<D1ExecResult>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/tests/integration/auth-info.test.ts:2
import type { AuthInfo } from "../../src/auth.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/tests/integration/auth-info.test.ts:3
import { McpServer, StreamableHttpTransport } from "../../src/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/tests/integration/auth-info.test.ts:4
import type { MCPServerContext } from "../../src/types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/tests/integration/capabilities-e2e.test.ts:10
} from "../../src/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/tests/integration/client-request-adapter.ts:4
import { InMemoryClientRequestAdapter } from "../../src/index.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
templates/starter-mcp-supabase/README.md:61
curl 'http://127.0.0.1:54321/functions/v1/mcp-server/health'
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
examples/cloudflare-worker-kv/worker-configuration.d.ts:210
atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
examples/cloudflare-worker-kv/worker-configuration.d.ts:298
declare function atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
examples/composing-servers/src/transform-server.ts:66
const decoded = atob(args.value);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/auth-clerk/package.json
@clerk/backend, @clerk/mcp-tools, @valibot/to-json-schema, hono, valibot, wrangler
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/cloudflare-worker-kv/package.json
@valibot/to-json-schema, hono, valibot, wrangler
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/composing-servers/package.json
hono, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/fastify-basic/package.json
fastify, zod, @types/node, tsx, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/sampling/package.json
arktype, hono, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 374270907a21full audit observations/trust-audit/mcp-server/fiberplane__lite.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07374270907a21CAUTIONB80first audit
06

Questions

What is the Lite MCP server?

Lightweight, composable MCP framework for TypeScript

What tools does Lite expose?

92 in total: 89 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Lite safe to connect to an agent?

With care. The audit graded it B (80/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Lite need?

It reads ELEVENLABS_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Lite run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as starter-mcp-supabase.

How current is this page?

The grade is for one exact copy of the source (374270907a21), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement