Ez-McpSAFE
The easiest path to getting an MCP server going
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Get an MCP server running in under 2 minutes! This repository contains complete, ready-to-run templates for single file self-contained MCP servers in both Python/uv and TypeScript/Deno.
🚀 Why EZ-MCP?
- ⚡ Instant Setup: Copy, paste, run - no complex configuration needed
- 🎯 Production Ready: Both templates use official Anthropic SDKs
- 📚 Comprehensive Examples: Everything documented with working code
- 🔧 Easily Extensible: Add your own tools, resources, and prompts in minutes
- 💡 Perfect for Experimentation: The fastest way to test MCP ideas locally
📁 What You Get
Two functionally identical, battle-tested templates:
- `ez-mcp.py` - Python server using official MCP SDK with UV
- `ez-mcp.ts` - TypeScript server using official MCP SDK with Deno
Each template demonstrates all core MCP features:
- 📊 Resources: Dynamic data sources for LLM context
- 🛠️ Tools: Functions LLMs can call to perform actions
- 📝 Prompts: Reusable templates for LLM interactions
- ⚙️ Configuration: Environment variable support
⚡ Quick Test Drive
Want to see these servers in action? Pick your language and run:
Python Version
# Install uv (if not already installed) curl -LsSf https://astral.sh/uv/install.sh | sh # Clone and run immediately git clone cd ez-mcp uv run ez-mcp.py
TypeScript Version
# Install Deno (if not already installed) curl -fsSL https://deno.land/install.sh | sh # Clone and run immediately git clone cd ez-mcp deno run --allow-all ez-mcp.ts
Both servers will start immediately and show you what's available!
🎯 Create Your Own Server (Copy & Customise in 5 Minutes)
The fastest way to build your own MCP server is to copy one of our templates and customise it. Both templates are functionally identical and production-ready - just pick your preferred language!
For P
d850a4bd61e6OBSERVED · 2026-10-08Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
fetch_external_data | read | |
hello-someone | read | |
hello_someone | read | Say hello to someone |
my_new_tool | read | |
safe_division | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -fsSL https://deno.land/install.sh | sh
Gates applied: no_behavioural_pass.
d850a4bd61e6full audit observations/trust-audit/mcp-server/intellectronica__ez-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d850a4bd61e6 | SAFE | B | 89 | first audit |
Questions
What is the Ez-Mcp MCP server?
The easiest path to getting an MCP server going
What tools does Ez-Mcp expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ez-Mcp safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Ez-Mcp need?
It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Ez-Mcp run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (d850a4bd61e6), read on 2026-10-08. The repository is watched and re-audited when it changes.