Atlas / MCP servers / lucianoayres / Node Boilerplate

Node BoilerplateSAFE

mcp/lucianoayres/node-boilerplate

MCP Server implemented in JavaScript using Node.js that demonstrates how to build an MCP server with a custom prompt and custom tools, including one that loads an environment variable from a configuration file, to integrate seamlessly with AI-assisted environments like Cursor IDE.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 1r · 1w · 0d
Transport
stdio
License
MIT
Stars
75
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Build and run a custom MCP Server in Node.js in just 2 minutes ⏱️

Overview · Features · Installation · Testing with MCP Inspector · Setting Environment Variables for Testing · Integrating with Cursor AI · Using the MCP Tool in Cursor (Agent Mode) · Code Overview · References & Resources · License

Overview

MCP (Model Context Protocol) is a framework that allows you to integrate custom tools into AI-assisted development environments—such as Cursor AI. MCP servers expose functionality (like data retrieval or code analysis) so that an LLM-based IDE can call these tools on demand. Learn more about MCP in the Model Context Protocol Introduction.

This project demonstrates an MCP server implemented in JavaScript using Node.js. It defines two tools: add, which takes two numeric inputs and returns their sum, and getApiKey, which retrieves the API key from the API_KEY environment variable. It also provides a predefined prompt add_numbers that allows AI models to infer the usage of the addition tool.

Requirements

  • Node.js: Version 20 or higher is required.

Features

  • MCP Integration: Exposes tool functionality to LLM-based IDEs.
  • Addition Tool: Accepts two numeric parameters and returns their sum.
  • MCP Prompt: Provides a predefined prompt ("add_numbers") that allow AI models to infer tool usage.
  • Env Var Retrieval: Demonstrates how to load an example environment variable from the configuration file.
  • Input Validation: Uses Zod for schema valida
Read from source at commit ff3a99c3d05cOBSERVED · 2026-10-07
02

Exposed tools (2)

1 read · 1 write · 0 destructive.

ToolRiskDescription
addwriteAdd two numbers
getApiKeyreadGet the API key
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:24
- **Env Var Retrieval:** Demonstrates how to load an example environment variable from the configuration file.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ff3a99c3d05cfull audit observations/trust-audit/mcp-server/lucianoayres__node-boilerplate.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ff3a99c3d05cSAFEB89first audit
05

Questions

What is the Node Boilerplate MCP server?

MCP Server implemented in JavaScript using Node.js that demonstrates how to build an MCP server with a custom prompt and custom tools, including one that loads an environment variable from a configuration file, to integrate seamlessly with AI-assisted environments like Cursor IDE.

What tools does Node Boilerplate expose?

2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Node Boilerplate safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Node Boilerplate need?

It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Node Boilerplate run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (ff3a99c3d05c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement