Atlas / MCP servers / harsha-iiiv / Openapi Mcp Generator

Openapi Mcp GeneratorBLOCK

mcp/harsha-iiiv/openapi-mcp-generator-1

A tool that converts OpenAPI specifications to MCP server

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
39 29r · 8w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
636
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/openapi-mcp-generator) [](https://opensource.org/licenses/MIT) [](https://github.com/harsha-iiiv/openapi-mcp-generator) [](https://deepwiki.com/harsha-iiiv/openapi-mcp-generator)

Generate Model Context Protocol (MCP) servers from OpenAPI specifications.

This CLI tool automates the generation of MCP-compatible servers that proxy requests to existing REST APIs—enabling AI agents and other MCP clients to seamlessly interact with your APIs using your choice of transport methods.

✨ Features

  • 🔧 OpenAPI 3.0 Support: Converts any OpenAPI 3.0+ spec into an MCP-compatible server.
  • 🔁 Proxy Behavior: Proxies calls to your original REST API while validating request structure and security.
  • 🔐 Authentication Support: API keys, Bearer tokens, Basic auth, and OAuth2 supported via environment variables.
  • 🧪 Zod Validation: Automatically generates Zod schemas from OpenAPI definitions for runtime input validation.
  • ⚙️ Typed Server: Fully typed, maintainable TypeScript code output.
  • 🔌 Multiple Transports: Communicate over stdio, SSE via Hono, or StreamableHTTP.
  • 🧰 Project Scaffold: Generates a complete Node.js project with tsconfig.json, package.json, and entry point.
  • 🧪 Built-in HTML Test Clients: Test API interactions visually in your browser (for web-based transports).

🚀 Installation

npm install -g openapi-mcp-generator
You can also use yarn global add openapi-mcp-generator or pnpm add -g openapi-mcp-generator

🛠 Usage

# Generate an MCP server (stdio)
openapi-mcp-generator --input pa
Read from source at commit 70d0168da385OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add openapi-mcp-generator --env MY_TOKEN=${MY_TOKEN} --env SECRET=${SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "openapi-mcp-generator": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MY_TOKEN": "${MY_TOKEN}",
        "SECRET": "${SECRET}"
      }
    }
  }
}
03

Exposed tools (39)

29 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addPetwriteAdd a new pet to the store.
addpetwriteAdd a new pet to the store.
createUserreadThis can only be done by the logged in user.
createUsersWithListInputreadCreates list of users with given input array.
createuserreadThis can only be done by the logged in user.
createuserswithlistinputreadCreates list of users with given input array.
deleteOrderreadFor valid response try integer IDs with value < 1000. Anything above 1000 or non-integers will generate API errors.
deletePetdestructiveDelete a pet.
deleteUserreadThis can only be done by the logged in user.
deleteorderreadFor valid response try integer IDs with value < 1000. Anything above 1000 or non-integers will generate API errors.
deletepetdestructiveDelete a pet.
deleteuserreadThis can only be done by the logged in user.
findPetsByStatusreadMultiple status values can be provided with comma separated strings.
findPetsByTagsreadMultiple tags can be provided with comma separated strings. Use tag1, tag2, tag3 for testing.
findpetsbystatusreadMultiple status values can be provided with comma separated strings.
findpetsbytagsreadMultiple tags can be provided with comma separated strings. Use tag1, tag2, tag3 for testing.
getInventoryreadReturns a map of status codes to quantities.
getOrderByIdreadFor valid response try integer IDs with value <= 5 or > 10. Other values will generate exceptions.
getPetByIdreadReturns a single pet.
getUserByNamereadGet user detail based on username.
getXreadgets x
getinventoryreadReturns a map of status codes to quantities.
getorderbyidreadFor valid response try integer IDs with value <= 5 or > 10. Other values will generate exceptions.
getpetbyidreadReturns a single pet.
getuserbynamereadGet user detail based on username.
loginUserreadLog into the system.
loginuserreadLog into the system.
logoutUserreadLog user out of the system.
logoutuserreadLog user out of the system.
placeOrderwritePlace a new order in the store.
placeorderwritePlace a new order in the store.
updatePetwriteUpdate an existing pet by Id.
updatePetWithFormreadUpdates a pet resource based on the form data.
updateUserreadThis can only be done by the logged in user.
updatepetwriteUpdate an existing pet by Id.
updatepetwithformreadUpdates a pet resource based on the form data.
updateuserreadThis can only be done by the logged in user.
uploadFilewriteUpload image of the pet.
uploadfilewriteUpload image of the pet.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (21)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/generator/server-code.ts:274
const zodSchema = eval(zodSchemaString);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/index.ts:120
'-k, --insecure',
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/index.ts:227
['--insecure', Boolean(options.insecure)],
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/utils/security.ts:306
const insecureHttpsAgent = new https.Agent({ rejectUnauthorized: false });
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deletePet, deletepet
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
examples/pet-store-sse/src/index.ts:1127
const zodSchema = eval(zodSchemaString);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
examples/pet-store-streamable-http/src/index.ts:1127
const zodSchema = eval(zodSchemaString);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
examples/petstore-mcp/src/index.ts:2709
const zodSchema = eval(zodSchemaString);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/parser/extract-tools.ts:111
const hash = createHash('sha1').update(name).digest('hex').slice(0, HASH_LEN);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/parser/extract-tools.ts:219
const disambiguator = createHash('sha1')
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/integration.test.ts:148
responses: { '200': { $ref: 'http://169.254.169.254/latest' } },
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit.test.ts:65
expect(isExternalHttpRef('http://169.254.169.254/')).toBe(true);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/integration.test.ts:148
responses: { '200': { $ref: 'http://169.254.169.254/latest' } },
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit.test.ts:65
expect(isExternalHttpRef('http://169.254.169.254/')).toBe(true);
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/integration.test.ts:100
'--insecure',
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/unit.test.ts:395
expect(code).toContain('rejectUnauthorized: false');
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/pet-store-sse/package.json
@modelcontextprotocol/sdk, axios, dotenv, zod, json-schema-to-zod, hono, @hono/node-server, uuid
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/pet-store-streamable-http/package.json
@modelcontextprotocol/sdk, axios, dotenv, zod, json-schema-to-zod, hono, @hono/node-server, uuid
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/petstore-mcp/package.json
@modelcontextprotocol/sdk, axios, json-schema-to-zod, zod, @types/node, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@apidevtools/swagger-parser, commander, openapi-types, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, prettier
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 70d0168da385full audit observations/trust-audit/mcp-server/harsha-iiiv__openapi-mcp-generator-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2870d0168da385BLOCKD69first audit
06

Questions

What is the Openapi Mcp Generator MCP server?

A tool that converts OpenAPI specifications to MCP server

What tools does Openapi Mcp Generator expose?

39 in total: 29 read-only, 8 that write, and 2 that can delete or overwrite (deletePet, deletepet). Every one is listed on this page with its risk.

Is Openapi Mcp Generator safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Openapi Mcp Generator need?

It reads MY_TOKEN and SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Openapi Mcp Generator run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as openapi-mcp-generator at 4.1.0.

How current is this page?

The grade is for one exact copy of the source (70d0168da385), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement