Atlas / MCP servers / ravitemer / Hub

HubBLOCK

mcp/ravitemer/hub

A centralized manager for Model Context Protocol (MCP) servers with dynamic server management and monitoring

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
sse · streamable-http
License
MIT
Stars
521
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mcp-hub) [](https://opensource.org/licenses/MIT) [](./CONTRIBUTING.md)

MCP Hub acts as a central coordinator for MCP servers and clients, providing two key interfaces:

  1. Management Interface (/api/*): Manage multiple MCP servers through a unified REST API and web UI
  2. MCP Server Interface (/mcp): Connect ANY MCP client to access ALL server capabilities through a single endpoint

This dual-interface approach means you can manage servers through the Hub's UI while MCP clients (Claude Desktop, Cline, etc.) only need to connect to one endpoint (localhost:37373/mcp) to access all capabilities. Implements MCP 2025-03-26 specification.

Feature Support

Read from source at commit 9176d6f83189OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-hub --env API_KEY=${API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-hub": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
Context7readUp-to-date code documentation for LLMs.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/marketplace.js:45
const { stdout } = await exec(curlCmd.join(' '));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
json5, @eslint/js, @modelcontextprotocol/sdk, @vitest/coverage-v8, chokidar, esbuild, eslint, express
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:281
"DB_PASSWORD": "${cmd: op read op://vault/db/password}",
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 9176d6f83189full audit observations/trust-audit/mcp-server/ravitemer__hub.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-309176d6f83189BLOCKD69first audit
06

Questions

What is the Hub MCP server?

A centralized manager for Model Context Protocol (MCP) servers with dynamic server management and monitoring

What tools does Hub expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Hub safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Hub need?

It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Hub run?

It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as mcp-hub at 4.2.1.

How current is this page?

The grade is for one exact copy of the source (9176d6f83189), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement