Atlas / MCP servers / mcp-use / Mcp-Use

Mcp-UseSAFE

mcp/mcp-use/mcp-use-1

mcp-use is the framework for MCP with the best DX - Build AI agents, create MCP servers with UI widgets, and debug with built-in inspector. Includes client SDK, server SDK, React hooks, and powerful dev tools.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 7r · 1w · 0d
Transport
streamable-http
License
—
Stars
171
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Repository moved to monorepo https://github.com/mcp-use/mcp-use

Read from source at commit 9d5c6a155ee9OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-use --env LANGFUSE_PUBLIC_KEY=${LANGFUSE_PUBLIC_KEY} --env LANGFUSE_SECRET_KEY=${LANGFUSE_SECRET_KEY} --env MCP_USE_API_KEY=${MCP_USE_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-use": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "LANGFUSE_PUBLIC_KEY": "${LANGFUSE_PUBLIC_KEY}",
        "LANGFUSE_SECRET_KEY": "${LANGFUSE_SECRET_KEY}",
        "MCP_USE_API_KEY": "${MCP_USE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (8)

7 read · 1 write · 0 destructive.

ToolRiskDescription
DocumentsreadUser documents directory
get-widget-inforeadGet information about available UI widgets
get_weatherreadGet current weather for a location
hello-worldreadA simple tool that returns hello world
quick-pollwriteCreate instant polls with interactive voting
test-toolreadTest tool
test_toolreadA test tool
welcome-cardreadA welcoming card with server information
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/inspector/.yarnrc.yml
.yarnrc.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/create-mcp-use-app/src/index.ts:26
resolve(__dirname, '../../../..'), // From dist/templates
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/create-mcp-use-app/src/index.ts:27
resolve(__dirname, '../../../../..'), // From dist
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/inspector/src/cli/inspect.ts:182
const clientDistPath = join(__dirname, '../../dist/client')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/inspector/src/client/components/Layout.tsx:13
import { Badge } from '../../components/ui/badge'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/inspector/src/client/components/Layout.tsx:14
import { Button } from '../../components/ui/button'
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@eslint/js, @changesets/cli, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, eslint-import-resolver-typescript, eslint-plugin-import
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
commander, esbuild, globby, open, tsx, @types/node, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/create-mcp-use-app/package.json
commander, chalk, fs-extra, @types/node, @types/fs-extra, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/create-mcp-use-app/src/templates/ui/package.json
@mcp-ui/server, cors, express, @types/cors, @types/express, @types/node, @types/react, @types/react-dom
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/create-mcp-use-app/src/templates/uiresource/package.json
@mcp-ui/server, cors, express, @types/cors, @types/express, @types/node, @types/react, @types/react-dom
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 9d5c6a155ee9full audit observations/trust-audit/mcp-server/mcp-use__mcp-use-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-069d5c6a155ee9SAFEB89first audit
06

Questions

What is the Mcp-Use MCP server?

mcp-use is the framework for MCP with the best DX - Build AI agents, create MCP servers with UI widgets, and debug with built-in inspector. Includes client SDK, server SDK, React hooks, and powerful dev tools.

What tools does Mcp-Use expose?

8 in total: 7 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mcp-Use safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Mcp-Use need?

It reads LANGFUSE_PUBLIC_KEY, LANGFUSE_SECRET_KEY and MCP_USE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcp-Use run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-use at 1.0.6.

How current is this page?

The grade is for one exact copy of the source (9d5c6a155ee9), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement