Atlas / MCP servers / himorishige / Hatago Hub

Hatago HubCAUTION

mcp/himorishige/hatago-hub

Hatago MCP Hub is a lightweight hub server that provides unified management for multiple MCP servers.

Verdict
CAUTION
Grade
C
Trust score
77 /100
Exposed tools
17 16r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 日本語

[](https://www.npmjs.com/package/@himorishige/hatago-mcp-hub) [](https://github.com/himorishige/hatago-mcp-hub/releases) [](https://deepwiki.com/himorishige/hatago-mcp-hub)

Hatago (旅籠) — A relay point connecting modern AI tools with MCP servers.

Overview

Hatago MCP Hub is a lightweight hub that unifies access to multiple MCP (Model Context Protocol) servers from tools like Claude Code, Codex CLI, Cursor, Windsurf, and VS Code.

Documentation

  • Docs index: docs/README.md
  • Canonical CLI & Hub guide: packages/mcp-hub/README.md
  • Public docs site (JA default): https://hatago.dev/ja/ — English: https://hatago.dev/en/

Dev.to: Getting Started with Multi-MCP Using Hatago MCP Hub — One Config to Connect Them All

✨ Features

🚀 Performance (v0.0.14)

  • 8.44x Faster Startup - 85.66ms → 10.14ms
  • 17% Smaller Package - 1.04MB → 854KB
  • Simplified Architecture - Direct server management without abstraction layers

🎯 Simple & Lightweight

  • Zero Configuration Start (HTTP mode) - npx @himorishige/hatago-mcp-hub serve --http
  • Non-invasive to Existing Projects - Doesn't pollute your project directory

🔌 Rich Connectivity

  • Multi-Transport Support - STDIO / HTTP / SSE
  • Remote MCP Proxy - Transparent connection to HTTP-based MCP servers
  • NPX Server Integration - Dynamic management of npm package MCP servers

🏮 Additional Features

Configuration Updates

  • Manual Restart Required - Configuration changes require server restart
  • Alternative Solutions:
  • Use process managers (PM2, nodem
Read from source at commit 196c0c071b15OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add hatago-transport --env API_KEY_2=${API_KEY_2} --env API_TOKEN=${API_TOKEN} --env AUTH_TOKEN=${AUTH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y @himorishige/[email protected]
claude-desktop
{
  "mcpServers": {
    "hatago-transport": {
      "command": "npx",
      "args": [
        "-y",
        "@himorishige/[email protected]"
      ],
      "env": {
        "API_KEY_2": "${API_KEY_2}",
        "API_TOKEN": "${API_TOKEN}",
        "AUTH_TOKEN": "${AUTH_TOKEN}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}"
      }
    }
  }
}
03

Exposed tools (17)

16 read · 1 write · 0 destructive.

ToolRiskDescription
addwriteAdd numbers
calcreadCalculator tool
calculatorreadMath tool
echoreadEcho input
echo_objectreadEcho the input as JSON
echo_toolreadEcho tool
failreadAlways fails
fetchreadFetch tool
greetingreadGenerate a greeting
namereadName to greet
no_handlerreadTool without handler
slowreadRespond slowly
stream_echoreadStream multiple chunks
summaryreadGenerate summary
test_promptreadA test prompt
test_toolreadTest tool
translatereadTranslate text
04

Trust audit

CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (7 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (24)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/hub/src/rpc/handlers.ts:151
logger.info(`[Hub] Registering progress token`, { progressToken, sessionId } as LogData);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-hub/src/node/cli.ts:191
console.log('  - Default endpoint: http://127.0.0.1:3535/mcp');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-hub/src/node/cli.ts:192
console.log('  - SSE endpoint: http://127.0.0.1:3535/sse');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-hub/src/node/cli.ts:193
console.log('  - Health check: http://127.0.0.1:3535/health');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/mcp-hub/src/workers/index.ts:77
origin: ['http://localhost:*', 'http://127.0.0.1:*', 'https://*.workers.dev'],
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/server/src/http.ts:55
origin: ['http://localhost:*', 'http://127.0.0.1:*'],
LOWInventory / provenance · inv.hidden_file · CWE-1104
.git-blame-ignore-revs
.git-blame-ignore-revs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
WARP.md
WARP.md
Why it matters. link not followed
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
packages/core/src/utils/env-expander.test.ts:135
expect(result.mcpServers.test.command).toBe('/usr/local/bin/server');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/hub/src/e2e/handshake.e2e.test.ts:18
fixturePath = join(__dirname, '../../../test-fixtures/dist/stdio-server.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/hub/src/e2e/streaming.e2e.test.ts:17
fixturePath = join(__dirname, '../../../test-fixtures/dist/stdio-server.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/hub/src/e2e/tools.e2e.test.ts:17
fixturePath = join(__dirname, '../../../test-fixtures/dist/stdio-server.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/hub/src/internal-resources.servers.smoke.test.ts:21
fixturePath = join(__dirname, '../../test-fixtures/dist/stdio-server.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-hub/src/node/cli.ts:19
const packageJson = JSON.parse(readFileSync(join(__dirname, '../../package.json'), 'utf-8')) as {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@eslint/js, eslint, eslint-config-prettier, prettier, typescript-eslint
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
@modelcontextprotocol/sdk, commander, chalk, @types/node, tsdown, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/core/package.json
@modelcontextprotocol/sdk, zod, tsdown, typescript, vitest
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/hub/package.json
@modelcontextprotocol/sdk, diff, hono, zod, zod-to-json-schema, @cloudflare/vitest-pool-workers, @cloudflare/workers-types, @types/node
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp-hub/package.json
@modelcontextprotocol/sdk, hono, commander, @types/node, tsdown, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/agents/hatago-code-reviewer.md:8
You are a Senior Code Reviewer for the Hatago project, an expert in Hono framework, MCP (Model Context Protocol), functional programming, and multi-runtime environments.
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:89
- CLI: `--env-file <path...>` to load environment variables before config parsing, and `--env-override` to overwrite existing values. Supports `KEY=VALUE` / `export KEY=VALUE`, `#` comments, quotes st
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:423
hatago serve --env-file ./.env # Load variables from .env before start (repeatable)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
packages/mcp-hub/README.md:68
hatago serve --env-file ./.env # Load variables from .env before start (can repeat)
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 196c0c071b15full audit observations/trust-audit/mcp-server/himorishige__hatago-hub.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08196c0c071b15CAUTIONC77first audit
06

Questions

What is the Hatago Hub MCP server?

Hatago MCP Hub is a lightweight hub server that provides unified management for multiple MCP servers.

What tools does Hatago Hub expose?

17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Hatago Hub safe to connect to an agent?

With care. The audit graded it C (77/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Hatago Hub need?

It reads API_KEY_2, API_TOKEN, AUTH_TOKEN, GITHUB_TOKEN, TOKEN, TOKEN1 and TOKEN2 from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Hatago Hub run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @himorishige/hatago-transport at 0.0.16.

How current is this page?

The grade is for one exact copy of the source (196c0c071b15), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement