Mcp-UseSAFE
mcp-use is the framework for MCP with the best DX - Build AI agents, create MCP servers with UI widgets, and debug with built-in inspector. Includes client SDK, server SDK, React hooks, and powerful dev tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Repository moved to monorepo https://github.com/mcp-use/mcp-use
9d5c6a155ee9OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-use --env LANGFUSE_PUBLIC_KEY=${LANGFUSE_PUBLIC_KEY} --env LANGFUSE_SECRET_KEY=${LANGFUSE_SECRET_KEY} --env MCP_USE_API_KEY=${MCP_USE_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-use": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"LANGFUSE_PUBLIC_KEY": "${LANGFUSE_PUBLIC_KEY}",
"LANGFUSE_SECRET_KEY": "${LANGFUSE_SECRET_KEY}",
"MCP_USE_API_KEY": "${MCP_USE_API_KEY}"
}
}
}
}Exposed tools (8)
7 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Documents | read | User documents directory |
get-widget-info | read | Get information about available UI widgets |
get_weather | read | Get current weather for a location |
hello-world | read | A simple tool that returns hello world |
quick-poll | write | Create instant polls with interactive voting |
test-tool | read | Test tool |
test_tool | read | A test tool |
welcome-card | read | A welcoming card with server information |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
.prettierignore
.prettierrc.json
.yarnrc.yml
resolve(__dirname, '../../../..'), // From dist/templates
resolve(__dirname, '../../../../..'), // From dist
const clientDistPath = join(__dirname, '../../dist/client')
import { Badge } from '../../components/ui/badge'import { Button } from '../../components/ui/button'@eslint/js, @changesets/cli, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, eslint-import-resolver-typescript, eslint-plugin-import
commander, esbuild, globby, open, tsx, @types/node, typescript
commander, chalk, fs-extra, @types/node, @types/fs-extra, typescript, vitest
@mcp-ui/server, cors, express, @types/cors, @types/express, @types/node, @types/react, @types/react-dom
@mcp-ui/server, cors, express, @types/cors, @types/express, @types/node, @types/react, @types/react-dom
Gates applied: no_behavioural_pass.
9d5c6a155ee9full audit observations/trust-audit/mcp-server/mcp-use__mcp-use-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 9d5c6a155ee9 | SAFE | B | 89 | first audit |
Questions
What is the Mcp-Use MCP server?
mcp-use is the framework for MCP with the best DX - Build AI agents, create MCP servers with UI widgets, and debug with built-in inspector. Includes client SDK, server SDK, React hooks, and powerful dev tools.
What tools does Mcp-Use expose?
8 in total: 7 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcp-Use safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mcp-Use need?
It reads LANGFUSE_PUBLIC_KEY, LANGFUSE_SECRET_KEY and MCP_USE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mcp-Use run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-use at 1.0.6.
How current is this page?
The grade is for one exact copy of the source (9d5c6a155ee9), read on 2026-10-06. The repository is watched and re-audited when it changes.