Node BoilerplateSAFE
MCP Server implemented in JavaScript using Node.js that demonstrates how to build an MCP server with a custom prompt and custom tools, including one that loads an environment variable from a configuration file, to integrate seamlessly with AI-assisted environments like Cursor IDE.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Build and run a custom MCP Server in Node.js in just 2 minutes ⏱️
Overview · Features · Installation · Testing with MCP Inspector · Setting Environment Variables for Testing · Integrating with Cursor AI · Using the MCP Tool in Cursor (Agent Mode) · Code Overview · References & Resources · License
Overview
MCP (Model Context Protocol) is a framework that allows you to integrate custom tools into AI-assisted development environments—such as Cursor AI. MCP servers expose functionality (like data retrieval or code analysis) so that an LLM-based IDE can call these tools on demand. Learn more about MCP in the Model Context Protocol Introduction.
This project demonstrates an MCP server implemented in JavaScript using Node.js. It defines two tools: add, which takes two numeric inputs and returns their sum, and getApiKey, which retrieves the API key from the API_KEY environment variable. It also provides a predefined prompt add_numbers that allows AI models to infer the usage of the addition tool.
Requirements
- Node.js: Version 20 or higher is required.
Features
- MCP Integration: Exposes tool functionality to LLM-based IDEs.
- Addition Tool: Accepts two numeric parameters and returns their sum.
- MCP Prompt: Provides a predefined prompt ("add_numbers") that allow AI models to infer tool usage.
- Env Var Retrieval: Demonstrates how to load an example environment variable from the configuration file.
- Input Validation: Uses Zod for schema valida
ff3a99c3d05cOBSERVED · 2026-10-07Exposed tools (2)
1 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | Add two numbers |
getApiKey | read | Get the API key |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@modelcontextprotocol/sdk, zod
- **Env Var Retrieval:** Demonstrates how to load an example environment variable from the configuration file.
Gates applied: no_behavioural_pass.
ff3a99c3d05cfull audit observations/trust-audit/mcp-server/lucianoayres__node-boilerplate.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ff3a99c3d05c | SAFE | B | 89 | first audit |
Questions
What is the Node Boilerplate MCP server?
MCP Server implemented in JavaScript using Node.js that demonstrates how to build an MCP server with a custom prompt and custom tools, including one that loads an environment variable from a configuration file, to integrate seamlessly with AI-assisted environments like Cursor IDE.
What tools does Node Boilerplate expose?
2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Node Boilerplate safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Node Boilerplate need?
It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Node Boilerplate run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (ff3a99c3d05c), read on 2026-10-07. The repository is watched and re-audited when it changes.