ElysiaSAFE
ElysiaJS plugin for Model Context Protocol with HTTP transport
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A comprehensive ElysiaJS plugin for implementing Model Context Protocol (MCP) servers with HTTP transport support.
Features
- HTTP Transport: Full HTTP-based MCP transport with Streamable HTTP
- Session Management: Stateful session handling via headers
- Type-Safe: Built with TypeScript and Zod validation
- Easy Integration: Simple plugin architecture for Elysia apps
- Comprehensive Support: Tools, Resources, Prompts, and Logging
- Custom Logger Support: Use any logger (pino, winston, bunyan, etc.)
- Error Handling: Proper JSON-RPC 2.0 error responses
- Testing: Full unit test coverage with Bun test runner
Installation
bun add elysia-mcp # or npm install elysia-mcp
Starter Template
To quickly get started with a pre-configured Elysia MCP project, you can use our starter template:
# Create a new project from the starter template bun create https://github.com/kerlos/elysia-mcp-starter my-mcp-project # Navigate to the project cd my-mcp-project # Install dependencies bun install # Start development server bun run dev
The elysia-mcp-starter template includes:
- Pre-configured Elysia setup with MCP plugin
- TypeScript configuration
- Development scripts
- Basic project structure
- Example MCP server implementation
Quick Start
import { Elysia } from 'elysia';
import { mcp } from 'elysia-mcp';
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { z } from 'zod';
const app = new Elysia()
.use(
mcp({
serverInfo: {
name: 'my-mcp-server',
version: '1.0.0',
},
capabilities: {
tools: {},
resources: {},
prompts: {},
logging: {},
},
setupServer: async (server: McpServer) => {
// Register your MCP tools, resources, and prompts here
server.registerTool(
d91a914f3e91OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add elysia-mcp -- npx -y [email protected]
{
"mcpServers": {
"elysia-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (13)
12 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | |
calculate | read | |
echo | read | |
get_time | read | |
greet | read | Greets a person by name |
multiply | read | |
notification-test | read | |
power | read | |
replace | read | |
reverse | read | |
uppercase | read | |
validate_user | read | |
word_count | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
streamable-http
@modelcontextprotocol/sdk, @biomejs/biome, @types/bun, @types/node, bun-plugin-dts, elysia, typescript
Gates applied: no_behavioural_pass.
d91a914f3e91full audit observations/trust-audit/mcp-server/kerlos__elysia-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d91a914f3e91 | SAFE | B | 89 | first audit |
Questions
What is the Elysia MCP server?
ElysiaJS plugin for Model Context Protocol with HTTP transport
What tools does Elysia expose?
13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Elysia safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Elysia need?
No credential environment variables were found in its source, so it appears to need none.
How does Elysia run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as elysia-mcp at 0.1.1.
How current is this page?
The grade is for one exact copy of the source (d91a914f3e91), read on 2026-10-08. The repository is watched and re-audited when it changes.