Atlas / MCP servers / rekog-labs / Nest

NestCAUTION

mcp/rekog-labs/nest

A NestJS module to effortlessly create Model Context Protocol (MCP) servers for exposing AI tools, resources, and prompts.

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
200 216r · 5w · 6d
Transport
streamable-http
License
MIT
Stars
711
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[![CI][ci-image]][ci-url] [![Code Coverage][code-coverage-image]][code-coverage-url] [![NPM Version][npm-version-image]][npm-url] [![NPM Downloads][npm-downloads-image]][npm-url] [![NPM License][npm-license-image]][npm-url]

A NestJS module to effortlessly expose tools, resources, and prompts for AI, from your NestJS applications using the Model Context Protocol (MCP).

With @rekog/mcp-nest you define tools, resources, and prompts in a way that's familiar in NestJS and leverage the full power of dependency injection to utilize your existing codebase in building complex enterprise ready MCP servers.

Features

  • 🧩 NestJS Microservice Strategy: MCP runs as a CustomTransportStrategy, so tools/resources/prompts are real @MessagePattern handlers — guards, pipes, interceptors, and exception filters apply to them natively
  • 🚀 Multi-Transport Support: Streamable HTTP and STDIO — selected via the transports array
  • 🕰️ Dual-Era Protocol Support: One endpoint serves both the 2025-era protocol (initialize + sessions) and the stateless 2026-07-28 revision, concurrently — with no change to your tool code
  • 🔧 Tools: Expose NestJS methods as MCP tools with automatic discovery and Zod validation
  • 🛠️ Elicitation: Interactive tool calls with user input elicitation
  • 🔁 Multi Round-Trip Requests: Elicitation, sampling and roots on protocol revision 2026-07-28 — one handler serves both eras
  • 🌐 HTTP Request Access: Full access to request context within MCP handlers
  • 🔐 Per-Tool Authorization:
Read from source at commit 5b89b1c40933OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-nest --env ACCESS_TOKEN=${ACCESS_TOKEN} --env ALLOW_UNAUTHENTICATED_ACCESS=${ALLOW_UNAUTHENTICATED_ACCESS} --env AZURE_AD_CLIENT_SECRET=${AZURE_AD_CLIENT_SECRET} --env GITHUB_CLIENT_SECRET=${GITHUB_CLIENT_SECRET} -- npx -y @rekog/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-nest": {
      "command": "npx",
      "args": [
        "-y",
        "@rekog/[email protected]"
      ],
      "env": {
        "ACCESS_TOKEN": "${ACCESS_TOKEN}",
        "ALLOW_UNAUTHENTICATED_ACCESS": "${ALLOW_UNAUTHENTICATED_ACCESS}",
        "AZURE_AD_CLIENT_SECRET": "${AZURE_AD_CLIENT_SECRET}",
        "GITHUB_CLIENT_SECRET": "${GITHUB_CLIENT_SECRET}"
      }
    }
  }
}
03

Exposed tools (200)

216 read · 5 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
account-multi-paramreadMultiple parameters URI template
account-single-paramreadSingle parameter URI template
admin-actionreadOnly executable by admins
admin-deletedestructiveDelete user (admin only)
admin-greetreadAdmin-only greeting that requires admin scopes
admin-operationreadAdministrative operation
admin-reportsreadNeeds a role, not a scope
admin-toolreadTool requiring admin role
app-configreadApplication configuration
arktype-addwriteAdds two numbers; input and output validated by ArkType.
array-output-toolreadReturns a top-level JSON array, per the spec
askreadAsks via elicitation
async-guard-toolreadTool with async guard
audit-logreadView audit logs
auth-hello-worldreadA sample tool that accesses the authenticated user
authenticated-toolreadTool requiring authentication
bad-guard-toolreadTool whose guard fails by accessing an unavailable context
boomreadAlways throws — demonstrates the RPC exception filter
capitalreadAsks the client-side model for the capital of a country
cfgreadStatic config
class-filter-promptreadFalls through to class-level catch-all filter
class-filter-resourcereadFalls through to class-level catch-all filter
class-filter-toolreadFalls through to class-level catch-all filter
code-review-guidereadInstructions for reviewing code
configreadStatic config
config-datareadApplication configuration
context-probereadReturns details derived from the @Ctx() context
count-itemsreadCounts the given items
create-userwriteCreates a user, validated with class-validator
delete-userdestructiveDelete a user
deploywriteDeploys to an environment after the user confirms and gives a reason
docs-wildcard-paramreadWildcard (catch-all) URI template
duplicate-promptreadFirst version
duplicate-resourcereadFirst version
duplicate-toolreadFirst version
dynamic-configreadApplication configuration loaded at runtime
dynamic-echoreadEchoes its input
dynamic-searchreadRegistered at runtime
dynamic-statusreadService status
dynamic-toolreadA dynamically registered tool
escalate-ticketreadEscalate a ticket
escalate-ticket-allreadEscalate a ticket (admin AND auditor role)
escalate-ticket-dynamicreadEscalate a ticket (admin OR auditor role, dynamic)
explicitly-imported-toolreadA tool that is explicitly imported
external-configreadConfig resource from an external module
external-promptreadA prompt registered from an external module
external-toolreadA tool registered from an external module
external-tool-no-paramsreadA parameterless tool from an external module
fastify-hello-worldreadA test tool to verify Fastify adapter works
feature-configreadFeature configuration resource
feature-promptreadA feature prompt
file-contentreadRead a file at an arbitrary nested path
filter-toolreadThrows, but an exception filter rewrites the response
framework-detectorreadDetects which HTTP framework is being used
get-analyticsreadGet analytics data
get-collectionsreadGet available collections
get-orderwriteGet an order by ID
get-request-scopedreadReads a header from the raw request via @McpRawRequest()
get-userreadGet a user by ID
get-weatherreadGet current weather for a city
gone-promptreadWill be removed before the server starts serving
gone-toolreadWill be removed before the server starts serving
goodbyereadSays goodbye
greetreadReturns a greeting (watch the RPC interceptor tag the result)
greet-known-userreadBuilds a greeting prompt using data from the injected UserRepository
greet-logged-in-userreadGreets the currently logged-in user using their name from the request
greet-userreadReturns a personalized greeting
greet-user-interactivereadInteractive greeting with language selection
greet-user-metareadGreeting whose definition carries extra metadata
greet-user-structuredreadReturns a structured greeting with metadata
greet-worldreadReturns a simple Hello, World! message
greetingreadA simple greeting prompt
greeting-guidereadA guide for greeting users
greeting-promptreadA greeting prompt
greeting-resourcereadA static greeting resource
greeting-templatereadA dynamic greeting resource
guardedreadAlways denied by a guard
guarded-with-argsreadGuarded tool with parameters
helloreadSay hello
hello-worldreadA sample tool that gets the user by name
hello-world-dynamicreadA simple greeting dynamic resource
hello-world-dynamic-multiple-pathsreadA simple greeting dynamic resource with multiple paths
hello-world-dynamic-multiple-paths-errorreadA simple greeting dynamic resource with multiple paths
hello-world-elicitationreadReturns a greeting and simulates a long operation with progress updates
hello-world-errorreadA sample tool that throws an error
hello-world-not-foundreadA resource that throws not found
hello-world-rpc-errorreadA sample tool that throws a client-facing RpcException
hello-world-scopedreadA sample request-scoped tool that gets the user by name
hello-world-template-with-metareadA simple greeting dynamic resource with meta
hello-world-with-annotationsreadA sample tool with annotations
hello-world-with-metareadA simple greeting resource with meta
help-textreadHelp documentation
hot-registered-promptreadRegistered after server started
hot-registered-resourcereadRegistered after server started
hot-registered-toolreadRegistered after server started
image-content-demoreadDemonstrates the image content type for prompt messages
insatiablereadAlways asks for more
inspect-requestreadCompares @Inject(REQUEST) with @McpRawRequest()
interceptor-toolreadHas its result rewritten by an interceptor
interviewreadAsks which topic to interview about
interview-guidereadStructured interview questions
introreadAn intro prompt
invalid-output-schema-toolreadReturns an object that does not match its outputSchema
known-promptreadA prompt that exists
known-toolreadA tool that exists
languagereadThe language to use for the greeting
languages-informal-greetingsreadLanguages and their informal greeting phrases
late-arrivalreadRegistered after the subscription opened
list-rootsreadLists the client
list-usersreadList all users
log-demoreadEmits log messages while running
malformedreadReturns an invalid input_required result
mcp-toolreadan mcp tool
method-filter-promptreadMethod-level filter overrides class-level
method-filter-resourcereadMethod-level filter overrides class-level
method-filter-toolreadMethod-level filter overrides class-level
multi-guard-toolreadTool requiring both authentication and admin role
multilingual-greeting-guidereadSimple instruction for greeting users in their native languages
my-promptreadA prompt with error handling
my-resourcereadA resource with error handling
my-toolreadv1
namereadThe name of the person to greet
needs-inputreadAsks the client for more input via MRTR
not-mcp-greetingreadReturns a plain object, not MCP-compliant
not-mcp-structured-greetingreadReturns a plain object with outputSchema
output-schema-toolreadA tool to test outputSchema
ownership-toolreadTool with an ownership guard that reads tool arguments
pingreadA tool behind the header checks
pipe-toolreadUses a transform pipe on its payload
pizza-carouselreadA pizza carousel that can be filtered by topping
pizza-list-multireadA pizza list with multiple query parameters
pizza-mixedreadA resource with both path and query parameters
plainreadA tool visible to everyone
plain-reportreadAny authenticated caller
premium-featurereadPremium-only feature
premium-greetreadPremium greeting for users with premium role
premium-reportreadView a premium report
primary-toolreadA tool from the primary MCP server
process-datareadProcesses data with progress updates
prompt-to-keepreadShould remain
prompt-to-removedestructiveShould be removed
protected-helloreadA protected tool that requires authentication
public-greet-worldreadReturns a simple Hello, World! message
public-reportsreadNeeds nothing
public-searchreadPublic search endpoint
public-toolreadA public tool accessible to everyone
purge-reportsdestructivePurge reports (admin only)
raw-statereadEchoes the raw requestState
read-reportsreadRequires the reports:read scope
read-reports-anyreadNeeds either of two scopes
readmereadProject documentation
recommend-destinationreadt
reflector-guard-toolreadTool with a Reflector-based guard reading method metadata
repo-filereadA named segment followed by a catch-all path
report-droppedreadReports dropped input response keys
request-scope-testreadTests request scoping with Fastify
reregistered-promptreadOriginal
reregistered-resourcereadOriginal
reregistered-toolreadOriginal
resolver-callsreadHow often resolveUser ran, and who the context reports
resource-to-keepreadShould remain
resource-to-removedestructiveShould be removed
scopedreadRequires a scope nobody can hold over stdio
searchreadSearch content
search-collectionreadSearch across collections. Available: ${collectionNames}
search-knowledgereadSearch the knowledge base
secondary-toolreadA tool from the secondary MCP server
secure-actionreadRequires both authentication and admin role
server-a-external-toolreadTool registered externally for server A
server-a-toolreadOnly visible on server A
server-b-external-toolreadTool registered externally for server B
server-statusreadIdentify the server
server1-dynamic-toolreadDynamic tool for server 1
server1-promptreadPrompt for server 1
server1-resourcereadResource for server 1
server2-dynamic-toolreadDynamic tool for server 2
server2-promptreadPrompt for server 2
server2-resourcereadResource for server 2
shared-health-checkreadA health check tool from the shared module
shared-utility-toolreadA utility tool from the shared module
simple-helloreadA simple greeting tool
simple-toolreadA simple tool that gets the user by name
smart-searchreadSmart search with optional premium features
static-promptreadA statically defined prompt using decorators
static-resourcereadA statically defined resource using decorators
static-toolreadA statically defined tool
string-output-toolreadReturns a bare JSON string
structured-output-toolreadA tool with output schema validation
success-promptreadPrompt that succeeds
success-resourcereadResource that succeeds
success-toolreadTool that succeeds
summarizereadSummarize the provided text
super-admin-greetreadSuper admin greeting requiring both admin scopes AND super-admin role
system-configreadConfigure system settings
talkreadEmits a server log line
task-plannerreadCreates task planning prompts based on complexity
teaserreadFree for anyone
temp-promptreadTemporary prompt
temp-resourcereadTemporary resource
temp-toolreadTemporary tool
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/mcp-nest-auth/src/services/jwt-token.service.ts:176
this.logger.warn(`Token rejected: ${name}: ${message}`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
admin-delete, delete-user, prompt-to-remove, purge-reports, resource-to-remove, tool-to-remove
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
examples/azure-ad-provider/scripts/mint-jwt.ts:15
console.log(token);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-nest-auth/src/stores/typeorm/entities/authorization-code.entity.ts:3
import type { OAuthClient } from '../../oauth-store.interface';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-nest-auth/src/stores/typeorm/entities/oauth-client.entity.ts:9
import type { ClientApplicationType } from '../../../providers/oauth-provider.interface';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-nest-auth/src/stores/typeorm/entities/oauth-session.entity.ts:3
import type { OAuthClient } from '../../oauth-store.interface';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-nest-auth/src/stores/typeorm/typeorm-store.service.spec.ts:13
import { OAuthSession } from '../../providers/oauth-provider.interface';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-nest-auth/src/stores/typeorm/typeorm-store.service.ts:15
} from '../../interfaces/oauth-common.interface';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
docs/built-in-authorization-server.md:694
caller can make the server fetch `https://169.254.169.254/...` (the cloud
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
examples/built-in-authorization-server/README.md:96
e.g. `https://169.254.169.254/...` (the cloud instance-metadata endpoint). In
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/mcp-oauth-cimd.e2e.spec.ts:691
['link-local', 'https://169.254.169.254/client.json'],
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/built-in-authorization-server.md:378
"redirect_uris": ["http://127.0.0.1:33418/callback"],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/built-in-authorization-server.md:555
"redirect_uris": ["http://127.0.0.1:33418/callback"],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/built-in-authorization-server.md:694
caller can make the server fetch `https://169.254.169.254/...` (the cloud
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
e2e/built-in-authorization-server-cimd.test.ts:136
baseUrl = `http://127.0.0.1:${port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
e2e/built-in-authorization-server.test.ts:101
let baseUrl: string; // http://127.0.0.1:<port> — what we actually fetch/connect to
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
e2e/package.json
@modelcontextprotocol/client, zod, @types/node
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/azure-ad-oauth-provider/package.json
@nestjs/common, @nestjs/core, @nestjs/microservices, @nestjs/platform-express, @nestjs/typeorm, cookie-parser, jsonwebtoken, reflect-metadata
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/azure-ad-provider/package.json
@nestjs/common, @nestjs/core, @nestjs/jwt, @nestjs/microservices, @nestjs/passport, @nestjs/platform-express, @nestjs/typeorm, cookie-parser
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/built-in-authorization-server/package.json
@nestjs/common, @nestjs/core, @nestjs/jwt, @nestjs/microservices, @nestjs/platform-express, cookie-parser, jsonwebtoken, passport
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/custom-controllers/package.json
@modelcontextprotocol/client, @nestjs/common, @nestjs/core, @nestjs/microservices, @nestjs/platform-express, class-transformer, class-validator, reflect-metadata
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:26
- 🌐 **[HTTP Request Access](docs/tools.md#understanding-tool-method-parameters)**: Full access to request context within MCP handlers
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
examples/per-tool-authorization/README.md:59
See the shared report (`.rinorism/doc-report.md`) for the full access-matrix
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
packages/mcp-nest/README.md:25
- 🌐 **[HTTP Request Access](docs/tools.md#understanding-tool-method-parameters)**: Full access to request context within MCP handlers
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/built-in-authorization-server.md:850
- **POST** `/auth/token` - Token endpoint
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 5b89b1c40933full audit observations/trust-audit/mcp-server/rekog-labs__nest.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-285b89b1c40933CAUTIONB82first audit
06

Questions

What is the Nest MCP server?

A NestJS module to effortlessly create Model Context Protocol (MCP) servers for exposing AI tools, resources, and prompts.

What tools does Nest expose?

200 in total: 216 read-only, 5 that write, and 6 that can delete or overwrite (admin-delete, delete-user, prompt-to-remove, purge-reports, resource-to-remove). Every one is listed on this page with its risk.

Is Nest safe to connect to an agent?

With care. The audit graded it B (82/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Nest need?

It reads ACCESS_TOKEN, ALLOW_UNAUTHENTICATED_ACCESS, AZURE_AD_CLIENT_SECRET, GITHUB_CLIENT_SECRET, GOOGLE_CLIENT_SECRET, JWT_SECRET, MCP_FAKE_AUTH, MRTR_KEY and MRTR_STATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Nest run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @rekog/mcp-nest at 2.0.0-alpha.4.

How current is this page?

The grade is for one exact copy of the source (5b89b1c40933), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement