mcp-hubCAUTION
Interactive micro-tools for humans and AI agents — a reference implementation of MCP Apps (SEP-1865) UI cards over Streamable HTTP MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
[](https://github.com/Gholls/mcp-hub/actions/workflows/ci.yml) [](./LICENSE)
Interactive micro-tools for humans and AI agents, served from `mcp.gholl.com`.
- For humans — a login-free playground of fast, single-purpose widgets.
- For AI agents — the same widgets exposed as MCP
tools that render as sandboxed iframe apps (MCP Apps).
Reference implementation. mcp-hub is a working reference for the MCP Apps interactive-UI pattern (SEP-1865): every tool ships a self-contained UI card over resources/read, side by side with the pure-data MCP path.One tool definition (shared/tools.ts) powers four surfaces: the gallery, the SEO landing page, the sandboxed embed, and the MCP server + discovery document.
Tools
39d530991e18OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-hub --env VITE_CF_ANALYTICS_TOKEN=${VITE_CF_ANALYTICS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-hub": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"VITE_CF_ANALYTICS_TOKEN": "${VITE_CF_ANALYTICS_TOKEN}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
mcp.gholl.com | read | Interactive micro-tools for humans and AI agents. Each tool renders a sandboxed UI card. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
const beacon = `<script defer src="https://static.cloudflareinsights.com/beacon.min.js" data-cf-beacon='{"token":"${token}"}'></script>`return html.replace('</head>', ` ${beacon}\n </head>`)import { Field, Segmented, StatCard, WidgetShell } from '../../components/ui.tsx'import { useMcp } from '../../lib/mcp-app.ts'import { Field, Segmented, Slider, WidgetShell } from '../../components/ui.tsx'import { WidgetShell } from '../../components/ui.tsx'import CopyButton from '../../components/CopyButton.tsx'
const binary = atob(base64)
const decoded = atob(result.base64)
@mcp-ui/client, @mcp-ui/server, @modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, echarts, lunar-typescript, react, react-dom
Gates applied: no_behavioural_pass.
39d530991e18full audit observations/trust-audit/mcp-server/gholls__mcp-hub.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 39d530991e18 | CAUTION | B | 89 | first audit |
Questions
What is the mcp-hub MCP server?
Interactive micro-tools for humans and AI agents — a reference implementation of MCP Apps (SEP-1865) UI cards over Streamable HTTP MCP.
What tools does mcp-hub expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is mcp-hub safe to connect to an agent?
With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does mcp-hub need?
It reads VITE_CF_ANALYTICS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does mcp-hub run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-hub at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (39d530991e18), read on 2026-10-09. The repository is watched and re-audited when it changes.