Eliza Plugin MCPSAFE
ElizaOS plugin allowing agents to connect to MCP servers
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://conventionalcommits.org)
This plugin integrates the Model Context Protocol (MCP) with ElizaOS, allowing agents to connect to multiple MCP servers and use their resources, prompts, and tools.
🔍 What is MCP?
The Model Context Protocol (MCP) is an open protocol that enables seamless integration between LLM applications and external data sources and tools. It provides a standardized way to connect LLMs with the context they need.
This plugin allows your ElizaOS agents to access multiple MCP servers simultaneously, each providing different capabilities:
- Resources: Context and data for the agent to reference
- Prompts: Templated messages and workflows
- Tools: Functions for the agent to execute
📦 Installation
Install the plugin in your ElizaOS project:
- npm
npm install @fleek-platform/eliza-plugin-mcp
- pnpm
pnpm install @fleek-platform/eliza-plugin-mcp
- yarn
yarn add @fleek-platform/eliza-plugin-mcp
- bun
bun add @fleek-platform/eliza-plugin-mcp
🚀 Usage
- Add the plugin to your character configuration:
{
"name": "Your Character",
"plugins": ["@fleek-platform/eliza-plugin-mcp"],
"settings": {
"mcp": {
"servers": {
"github": {
"type": "stdio",
"name": "Code Server",
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-github"]
}
}
}
}
}⚙️ Configuration Options
MCP supports two types of servers: "stdio" and "sse". Each type has its own configuration options.
Common Options
45ceb1ff31ccOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add eliza-plugin-mcp -- npx -y @fleek-platform/[email protected]
{
"mcpServers": {
"eliza-plugin-mcp": {
"command": "npx",
"args": [
"-y",
"@fleek-platform/[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
MCP | read | Information about connected MCP servers, tools, and resources |
mcp | read | Plugin for connecting to MCP (Model Context Protocol) servers |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
.npmrc.template
@modelcontextprotocol/sdk, ajv, json5, typescript
Gates applied: no_behavioural_pass, no_license.
45ceb1ff31ccfull audit observations/trust-audit/mcp-server/fleek-platform__eliza-plugin-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 45ceb1ff31cc | SAFE | B | 89 | first audit |
Questions
What is the Eliza Plugin MCP MCP server?
ElizaOS plugin allowing agents to connect to MCP servers
What tools does Eliza Plugin MCP expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Eliza Plugin MCP safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Eliza Plugin MCP need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (45ceb1ff31cc), read on 2026-10-08. The repository is watched and re-audited when it changes.