HubBLOCK
A centralized manager for Model Context Protocol (MCP) servers with dynamic server management and monitoring
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/mcp-hub) [](https://opensource.org/licenses/MIT) [](./CONTRIBUTING.md)
MCP Hub acts as a central coordinator for MCP servers and clients, providing two key interfaces:
- Management Interface (/api/*): Manage multiple MCP servers through a unified REST API and web UI
- MCP Server Interface (/mcp): Connect ANY MCP client to access ALL server capabilities through a single endpoint
This dual-interface approach means you can manage servers through the Hub's UI while MCP clients (Claude Desktop, Cline, etc.) only need to connect to one endpoint (localhost:37373/mcp) to access all capabilities. Implements MCP 2025-03-26 specification.
Feature Support
9176d6f83189OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-hub --env API_KEY=${API_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-hub": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"API_KEY": "${API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Context7 | read | Up-to-date code documentation for LLMs. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
const { stdout } = await exec(curlCmd.join(' '));json5, @eslint/js, @modelcontextprotocol/sdk, @vitest/coverage-v8, chokidar, esbuild, eslint, express
"DB_PASSWORD": "${cmd: op read op://vault/db/password}",Gates applied: no_behavioural_pass.
9176d6f83189full audit observations/trust-audit/mcp-server/ravitemer__hub.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 9176d6f83189 | BLOCK | D | 69 | first audit |
Questions
What is the Hub MCP server?
A centralized manager for Model Context Protocol (MCP) servers with dynamic server management and monitoring
What tools does Hub expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Hub safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Hub need?
It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Hub run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-hub at 4.2.1.
How current is this page?
The grade is for one exact copy of the source (9176d6f83189), read on 2026-09-30. The repository is watched and re-audited when it changes.