Atlas / MCP servers / gholls / mcp-hub

mcp-hubCAUTION

mcp/gholls/mcp-hub

Interactive micro-tools for humans and AI agents — a reference implementation of MCP Apps (SEP-1865) UI cards over Streamable HTTP MCP.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
streamable-http
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

[](https://github.com/Gholls/mcp-hub/actions/workflows/ci.yml) [](./LICENSE)

Interactive micro-tools for humans and AI agents, served from `mcp.gholl.com`.

  • For humans — a login-free playground of fast, single-purpose widgets.
  • For AI agents — the same widgets exposed as MCP

tools that render as sandboxed iframe apps (MCP Apps).

Reference implementation. mcp-hub is a working reference for the MCP Apps interactive-UI pattern (SEP-1865): every tool ships a self-contained UI card over resources/read, side by side with the pure-data MCP path.

One tool definition (shared/tools.ts) powers four surfaces: the gallery, the SEO landing page, the sandboxed embed, and the MCP server + discovery document.

Tools

Read from source at commit 39d530991e18OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-hub --env VITE_CF_ANALYTICS_TOKEN=${VITE_CF_ANALYTICS_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-hub": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "VITE_CF_ANALYTICS_TOKEN": "${VITE_CF_ANALYTICS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
mcp.gholl.comreadInteractive micro-tools for humans and AI agents. Each tool renders a sandboxed UI card.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
vite.config.ts:42
const beacon = `<script defer src="https://static.cloudflareinsights.com/beacon.min.js" data-cf-beacon='{"token":"${token}"}'></script>`
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
vite.config.ts:43
return html.replace('</head>', `  ${beacon}\n  </head>`)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/widgets/api-uptime/index.tsx:10
import { Field, Segmented, StatCard, WidgetShell } from '../../components/ui.tsx'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/widgets/api-uptime/index.tsx:11
import { useMcp } from '../../lib/mcp-app.ts'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/widgets/chrono-energy/index.tsx:11
import { Field, Segmented, Slider, WidgetShell } from '../../components/ui.tsx'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/widgets/color-studio/index.tsx:5
import { WidgetShell } from '../../components/ui.tsx'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/widgets/color-studio/index.tsx:6
import CopyButton from '../../components/CopyButton.tsx'
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
shared/calc/jwt.ts:30
const binary = atob(base64)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/hash.test.ts:25
const decoded = atob(result.base64)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@mcp-ui/client, @mcp-ui/server, @modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, echarts, lunar-typescript, react, react-dom
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 39d530991e18full audit observations/trust-audit/mcp-server/gholls__mcp-hub.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0939d530991e18CAUTIONB89first audit
06

Questions

What is the mcp-hub MCP server?

Interactive micro-tools for humans and AI agents — a reference implementation of MCP Apps (SEP-1865) UI cards over Streamable HTTP MCP.

What tools does mcp-hub expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is mcp-hub safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does mcp-hub need?

It reads VITE_CF_ANALYTICS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does mcp-hub run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-hub at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (39d530991e18), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement