Atlas / MCP servers / mcp-router / Router

RouterCAUTION

mcp/mcp-router/router-1

MCP Router — development, support and security updates ended 2026-09-18. Historical source and final release for existing users.

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
2 1r · 1w · 0d
Transport
sse · stdio · streamable-http
License
NOASSERTION
Stars
2,149
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

End of support — September 18, 2026. Development, support and security updates have ended. Cloud services and billing have stopped. v0.6.4 is the final desktop release for existing users; local features remain available. New adoption is not recommended. End-of-support and migration guide.

The material below describes the historical product. Cloud features are no longer available.

MCP Router A Unified MCP Server Management App

[](https://github.com/mcp-router/mcp-router) [](https://discord.com/invite/dwG9jPrhxB) -@mcp__router-1DA1F2?style=flat&logo=x)

English | [日本語 | 中文]

🎯 Overview

MCP Router is a desktop application for simplifies the management of Model Context Protocol (MCP) servers.

✨ Key Features

  • 🌐 Universal — Connect to any MCP server
  • Remote or local servers
  • Supports DXT, JSON, Manual
  • 🖥️ Cross-platform — Windows and macOS
  • 🗂 Context Management — Keep growing MCP server contexts organized
  • Group MCP servers into Projects
  • Manage modes with Workspaces (like browser profiles)
  • Toggle tools on/off per server

🔒 Privacy & Security

Your Data Stays Local

  • ✅ All data is stored locally - Request logs, configurations, and server data remain on your device
  • ✅ Credentials are secure - API keys and authentication credentials are stored locally and never transmitted externally
  • ✅ Complete control - You have full control over your MCP server connections and data

Transparency

  • 🔍 Auditable
Read from source at commit 2053f05a089dOBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ui --env APPLE_API_KEY=${APPLE_API_KEY} --env APPLE_API_KEY_ID=${APPLE_API_KEY_ID} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env MCPR_TOKEN=${MCPR_TOKEN} -- npx -y @mcp_router/[email protected]
claude-desktop
{
  "mcpServers": {
    "ui": {
      "command": "npx",
      "args": [
        "-y",
        "@mcp_router/[email protected]"
      ],
      "env": {
        "APPLE_API_KEY": "${APPLE_API_KEY}",
        "APPLE_API_KEY_ID": "${APPLE_API_KEY_ID}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}",
        "MCPR_TOKEN": "${MCPR_TOKEN}"
      }
    }
  }
}
03

Exposed tools (2)

1 read · 1 write · 0 destructive.

ToolRiskDescription
tool_discoveryreadDiscover available tools across MCP servers.
tool_executewriteExecute a discovered tool on an MCP server.
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/electron/public/images/icon/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
public/images/icon/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
apps/electron/src/main/ui/tray.ts:25
"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAhIAAAISAQAAAACxRhsSAAABhGlDQ1BJQ0MgUHJvZmlsZQAAeJx9kT1Iw0AcxV9TS0WqDnYo4hChOtlFRRylikWwUNoKrTqYXPoFTRqSFBdHwbXg4Mdi1cHFWVcHV0EQ/ABxF5wUXaTE/yWFFjEeHPfj3
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cursorindexingignore
.cursorindexingignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/electron/e2e/fixtures/page-objects/server.page.ts:89
const servers = await this.page.$$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/electron/e2e/fixtures/page-objects/workspace.page.ts:66
const workspaces = await this.page.$$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/electron/e2e/fixtures/electron-app.ts:18
const appPath = path.join(__dirname, "../../.webpack/arm64/main/index.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/electron/forge.config.ts:15
require("dotenv").config({ path: path.resolve(__dirname, "../../.env") });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/electron/src/main/modules/auth/auth.service.ts:3
import { API_BASE_URL, mainWindow } from "../../../main";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/electron/src/main/modules/mcp-apps-manager/mcp-apps-manager.repository.ts:2
import { getSharedConfigManager } from "../../infrastructure/shared-config-manager";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/electron/src/main/modules/mcp-apps-manager/mcp-apps-manager.service.ts:37
import claudeIcon from "../../../../public/images/apps/claude.svg";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/electron/tests/security-utils.test.cjs:100
assert.throws(() => normalizeRemoteMcpUrl("https://127.0.0.1/mcp"));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/cli/package.json
@modelcontextprotocol/sdk, node-fetch, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/electron/package.json
@anthropic-ai/dxt, @codemirror/lang-javascript, @codemirror/state, @codemirror/theme-one-dark, @codemirror/view, @modelcontextprotocol/sdk, @tabler/icons-react, @types/react
Why it matters. 75 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@electron/rebuild, @eslint/js, @types/better-sqlite3, @types/node, @types/node-fetch, @types/react, @types/react-router-dom, @typescript-eslint/eslint-plugin
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/remote-api-types/package.json
@trpc/client, superjson, zod, @trpc/server, @types/node, eslint, tsup, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/shared/package.json
@types/node, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 2053f05a089dfull audit observations/trust-audit/mcp-server/mcp-router__router-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-232053f05a089dCAUTIONB82source changed, verdict held
06

Questions

What is the Router MCP server?

MCP Router — development, support and security updates ended 2026-09-18. Historical source and final release for existing users.

What tools does Router expose?

2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Router safe to connect to an agent?

With care. The audit graded it B (82/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Router need?

It reads APPLE_API_KEY, APPLE_API_KEY_ID, GITHUB_TOKEN and MCPR_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Router run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mcp_router/ui at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (2053f05a089d), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement