NestCAUTION
A NestJS module to effortlessly create Model Context Protocol (MCP) servers for exposing AI tools, resources, and prompts.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[![CI][ci-image]][ci-url] [![Code Coverage][code-coverage-image]][code-coverage-url] [![NPM Version][npm-version-image]][npm-url] [![NPM Downloads][npm-downloads-image]][npm-url] [![NPM License][npm-license-image]][npm-url]
A NestJS module to effortlessly expose tools, resources, and prompts for AI, from your NestJS applications using the Model Context Protocol (MCP).
With @rekog/mcp-nest you define tools, resources, and prompts in a way that's familiar in NestJS and leverage the full power of dependency injection to utilize your existing codebase in building complex enterprise ready MCP servers.
Features
- 🧩 NestJS Microservice Strategy: MCP runs as a
CustomTransportStrategy, so tools/resources/prompts are real@MessagePatternhandlers — guards, pipes, interceptors, and exception filters apply to them natively - 🚀 Multi-Transport Support: Streamable HTTP and STDIO — selected via the
transportsarray - 🕰️ Dual-Era Protocol Support: One endpoint serves both the 2025-era protocol (
initialize+ sessions) and the stateless2026-07-28revision, concurrently — with no change to your tool code - 🔧 Tools: Expose NestJS methods as MCP tools with automatic discovery and Zod validation
- 🛠️ Elicitation: Interactive tool calls with user input elicitation
- 🔁 Multi Round-Trip Requests: Elicitation, sampling and roots on protocol revision
2026-07-28— one handler serves both eras - 🌐 HTTP Request Access: Full access to request context within MCP handlers
- 🔐 Per-Tool Authorization:
5b89b1c40933OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-nest --env ACCESS_TOKEN=${ACCESS_TOKEN} --env ALLOW_UNAUTHENTICATED_ACCESS=${ALLOW_UNAUTHENTICATED_ACCESS} --env AZURE_AD_CLIENT_SECRET=${AZURE_AD_CLIENT_SECRET} --env GITHUB_CLIENT_SECRET=${GITHUB_CLIENT_SECRET} -- npx -y @rekog/[email protected]{
"mcpServers": {
"mcp-nest": {
"command": "npx",
"args": [
"-y",
"@rekog/[email protected]"
],
"env": {
"ACCESS_TOKEN": "${ACCESS_TOKEN}",
"ALLOW_UNAUTHENTICATED_ACCESS": "${ALLOW_UNAUTHENTICATED_ACCESS}",
"AZURE_AD_CLIENT_SECRET": "${AZURE_AD_CLIENT_SECRET}",
"GITHUB_CLIENT_SECRET": "${GITHUB_CLIENT_SECRET}"
}
}
}
}Exposed tools (200)
216 read · 5 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
account-multi-param | read | Multiple parameters URI template |
account-single-param | read | Single parameter URI template |
admin-action | read | Only executable by admins |
admin-delete | destructive | Delete user (admin only) |
admin-greet | read | Admin-only greeting that requires admin scopes |
admin-operation | read | Administrative operation |
admin-reports | read | Needs a role, not a scope |
admin-tool | read | Tool requiring admin role |
app-config | read | Application configuration |
arktype-add | write | Adds two numbers; input and output validated by ArkType. |
array-output-tool | read | Returns a top-level JSON array, per the spec |
ask | read | Asks via elicitation |
async-guard-tool | read | Tool with async guard |
audit-log | read | View audit logs |
auth-hello-world | read | A sample tool that accesses the authenticated user |
authenticated-tool | read | Tool requiring authentication |
bad-guard-tool | read | Tool whose guard fails by accessing an unavailable context |
boom | read | Always throws — demonstrates the RPC exception filter |
capital | read | Asks the client-side model for the capital of a country |
cfg | read | Static config |
class-filter-prompt | read | Falls through to class-level catch-all filter |
class-filter-resource | read | Falls through to class-level catch-all filter |
class-filter-tool | read | Falls through to class-level catch-all filter |
code-review-guide | read | Instructions for reviewing code |
config | read | Static config |
config-data | read | Application configuration |
context-probe | read | Returns details derived from the @Ctx() context |
count-items | read | Counts the given items |
create-user | write | Creates a user, validated with class-validator |
delete-user | destructive | Delete a user |
deploy | write | Deploys to an environment after the user confirms and gives a reason |
docs-wildcard-param | read | Wildcard (catch-all) URI template |
duplicate-prompt | read | First version |
duplicate-resource | read | First version |
duplicate-tool | read | First version |
dynamic-config | read | Application configuration loaded at runtime |
dynamic-echo | read | Echoes its input |
dynamic-search | read | Registered at runtime |
dynamic-status | read | Service status |
dynamic-tool | read | A dynamically registered tool |
escalate-ticket | read | Escalate a ticket |
escalate-ticket-all | read | Escalate a ticket (admin AND auditor role) |
escalate-ticket-dynamic | read | Escalate a ticket (admin OR auditor role, dynamic) |
explicitly-imported-tool | read | A tool that is explicitly imported |
external-config | read | Config resource from an external module |
external-prompt | read | A prompt registered from an external module |
external-tool | read | A tool registered from an external module |
external-tool-no-params | read | A parameterless tool from an external module |
fastify-hello-world | read | A test tool to verify Fastify adapter works |
feature-config | read | Feature configuration resource |
feature-prompt | read | A feature prompt |
file-content | read | Read a file at an arbitrary nested path |
filter-tool | read | Throws, but an exception filter rewrites the response |
framework-detector | read | Detects which HTTP framework is being used |
get-analytics | read | Get analytics data |
get-collections | read | Get available collections |
get-order | write | Get an order by ID |
get-request-scoped | read | Reads a header from the raw request via @McpRawRequest() |
get-user | read | Get a user by ID |
get-weather | read | Get current weather for a city |
gone-prompt | read | Will be removed before the server starts serving |
gone-tool | read | Will be removed before the server starts serving |
goodbye | read | Says goodbye |
greet | read | Returns a greeting (watch the RPC interceptor tag the result) |
greet-known-user | read | Builds a greeting prompt using data from the injected UserRepository |
greet-logged-in-user | read | Greets the currently logged-in user using their name from the request |
greet-user | read | Returns a personalized greeting |
greet-user-interactive | read | Interactive greeting with language selection |
greet-user-meta | read | Greeting whose definition carries extra metadata |
greet-user-structured | read | Returns a structured greeting with metadata |
greet-world | read | Returns a simple Hello, World! message |
greeting | read | A simple greeting prompt |
greeting-guide | read | A guide for greeting users |
greeting-prompt | read | A greeting prompt |
greeting-resource | read | A static greeting resource |
greeting-template | read | A dynamic greeting resource |
guarded | read | Always denied by a guard |
guarded-with-args | read | Guarded tool with parameters |
hello | read | Say hello |
hello-world | read | A sample tool that gets the user by name |
hello-world-dynamic | read | A simple greeting dynamic resource |
hello-world-dynamic-multiple-paths | read | A simple greeting dynamic resource with multiple paths |
hello-world-dynamic-multiple-paths-error | read | A simple greeting dynamic resource with multiple paths |
hello-world-elicitation | read | Returns a greeting and simulates a long operation with progress updates |
hello-world-error | read | A sample tool that throws an error |
hello-world-not-found | read | A resource that throws not found |
hello-world-rpc-error | read | A sample tool that throws a client-facing RpcException |
hello-world-scoped | read | A sample request-scoped tool that gets the user by name |
hello-world-template-with-meta | read | A simple greeting dynamic resource with meta |
hello-world-with-annotations | read | A sample tool with annotations |
hello-world-with-meta | read | A simple greeting resource with meta |
help-text | read | Help documentation |
hot-registered-prompt | read | Registered after server started |
hot-registered-resource | read | Registered after server started |
hot-registered-tool | read | Registered after server started |
image-content-demo | read | Demonstrates the image content type for prompt messages |
insatiable | read | Always asks for more |
inspect-request | read | Compares @Inject(REQUEST) with @McpRawRequest() |
interceptor-tool | read | Has its result rewritten by an interceptor |
interview | read | Asks which topic to interview about |
interview-guide | read | Structured interview questions |
intro | read | An intro prompt |
invalid-output-schema-tool | read | Returns an object that does not match its outputSchema |
known-prompt | read | A prompt that exists |
known-tool | read | A tool that exists |
language | read | The language to use for the greeting |
languages-informal-greetings | read | Languages and their informal greeting phrases |
late-arrival | read | Registered after the subscription opened |
list-roots | read | Lists the client |
list-users | read | List all users |
log-demo | read | Emits log messages while running |
malformed | read | Returns an invalid input_required result |
mcp-tool | read | an mcp tool |
method-filter-prompt | read | Method-level filter overrides class-level |
method-filter-resource | read | Method-level filter overrides class-level |
method-filter-tool | read | Method-level filter overrides class-level |
multi-guard-tool | read | Tool requiring both authentication and admin role |
multilingual-greeting-guide | read | Simple instruction for greeting users in their native languages |
my-prompt | read | A prompt with error handling |
my-resource | read | A resource with error handling |
my-tool | read | v1 |
name | read | The name of the person to greet |
needs-input | read | Asks the client for more input via MRTR |
not-mcp-greeting | read | Returns a plain object, not MCP-compliant |
not-mcp-structured-greeting | read | Returns a plain object with outputSchema |
output-schema-tool | read | A tool to test outputSchema |
ownership-tool | read | Tool with an ownership guard that reads tool arguments |
ping | read | A tool behind the header checks |
pipe-tool | read | Uses a transform pipe on its payload |
pizza-carousel | read | A pizza carousel that can be filtered by topping |
pizza-list-multi | read | A pizza list with multiple query parameters |
pizza-mixed | read | A resource with both path and query parameters |
plain | read | A tool visible to everyone |
plain-report | read | Any authenticated caller |
premium-feature | read | Premium-only feature |
premium-greet | read | Premium greeting for users with premium role |
premium-report | read | View a premium report |
primary-tool | read | A tool from the primary MCP server |
process-data | read | Processes data with progress updates |
prompt-to-keep | read | Should remain |
prompt-to-remove | destructive | Should be removed |
protected-hello | read | A protected tool that requires authentication |
public-greet-world | read | Returns a simple Hello, World! message |
public-reports | read | Needs nothing |
public-search | read | Public search endpoint |
public-tool | read | A public tool accessible to everyone |
purge-reports | destructive | Purge reports (admin only) |
raw-state | read | Echoes the raw requestState |
read-reports | read | Requires the reports:read scope |
read-reports-any | read | Needs either of two scopes |
readme | read | Project documentation |
recommend-destination | read | t |
reflector-guard-tool | read | Tool with a Reflector-based guard reading method metadata |
repo-file | read | A named segment followed by a catch-all path |
report-dropped | read | Reports dropped input response keys |
request-scope-test | read | Tests request scoping with Fastify |
reregistered-prompt | read | Original |
reregistered-resource | read | Original |
reregistered-tool | read | Original |
resolver-calls | read | How often resolveUser ran, and who the context reports |
resource-to-keep | read | Should remain |
resource-to-remove | destructive | Should be removed |
scoped | read | Requires a scope nobody can hold over stdio |
search | read | Search content |
search-collection | read | Search across collections. Available: ${collectionNames} |
search-knowledge | read | Search the knowledge base |
secondary-tool | read | A tool from the secondary MCP server |
secure-action | read | Requires both authentication and admin role |
server-a-external-tool | read | Tool registered externally for server A |
server-a-tool | read | Only visible on server A |
server-b-external-tool | read | Tool registered externally for server B |
server-status | read | Identify the server |
server1-dynamic-tool | read | Dynamic tool for server 1 |
server1-prompt | read | Prompt for server 1 |
server1-resource | read | Resource for server 1 |
server2-dynamic-tool | read | Dynamic tool for server 2 |
server2-prompt | read | Prompt for server 2 |
server2-resource | read | Resource for server 2 |
shared-health-check | read | A health check tool from the shared module |
shared-utility-tool | read | A utility tool from the shared module |
simple-hello | read | A simple greeting tool |
simple-tool | read | A simple tool that gets the user by name |
smart-search | read | Smart search with optional premium features |
static-prompt | read | A statically defined prompt using decorators |
static-resource | read | A statically defined resource using decorators |
static-tool | read | A statically defined tool |
string-output-tool | read | Returns a bare JSON string |
structured-output-tool | read | A tool with output schema validation |
success-prompt | read | Prompt that succeeds |
success-resource | read | Resource that succeeds |
success-tool | read | Tool that succeeds |
summarize | read | Summarize the provided text |
super-admin-greet | read | Super admin greeting requiring both admin scopes AND super-admin role |
system-config | read | Configure system settings |
talk | read | Emits a server log line |
task-planner | read | Creates task planning prompts based on complexity |
teaser | read | Free for anyone |
temp-prompt | read | Temporary prompt |
temp-resource | read | Temporary resource |
temp-tool | read | Temporary tool |
Trust audit
CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
this.logger.warn(`Token rejected: ${name}: ${message}`);admin-delete, delete-user, prompt-to-remove, purge-reports, resource-to-remove, tool-to-remove
console.log(token);
import type { OAuthClient } from '../../oauth-store.interface';import type { ClientApplicationType } from '../../../providers/oauth-provider.interface';import type { OAuthClient } from '../../oauth-store.interface';import { OAuthSession } from '../../providers/oauth-provider.interface';} from '../../interfaces/oauth-common.interface';
caller can make the server fetch `https://169.254.169.254/...` (the cloud
e.g. `https://169.254.169.254/...` (the cloud instance-metadata endpoint). In
['link-local', 'https://169.254.169.254/client.json'],
"redirect_uris": ["http://127.0.0.1:33418/callback"],
"redirect_uris": ["http://127.0.0.1:33418/callback"],
caller can make the server fetch `https://169.254.169.254/...` (the cloud
baseUrl = `http://127.0.0.1:${port}`;let baseUrl: string; // http://127.0.0.1:<port> — what we actually fetch/connect to
@modelcontextprotocol/client, zod, @types/node
@nestjs/common, @nestjs/core, @nestjs/microservices, @nestjs/platform-express, @nestjs/typeorm, cookie-parser, jsonwebtoken, reflect-metadata
@nestjs/common, @nestjs/core, @nestjs/jwt, @nestjs/microservices, @nestjs/passport, @nestjs/platform-express, @nestjs/typeorm, cookie-parser
@nestjs/common, @nestjs/core, @nestjs/jwt, @nestjs/microservices, @nestjs/platform-express, cookie-parser, jsonwebtoken, passport
@modelcontextprotocol/client, @nestjs/common, @nestjs/core, @nestjs/microservices, @nestjs/platform-express, class-transformer, class-validator, reflect-metadata
- 🌐 **[HTTP Request Access](docs/tools.md#understanding-tool-method-parameters)**: Full access to request context within MCP handlers
See the shared report (`.rinorism/doc-report.md`) for the full access-matrix
- 🌐 **[HTTP Request Access](docs/tools.md#understanding-tool-method-parameters)**: Full access to request context within MCP handlers
- **POST** `/auth/token` - Token endpoint
Gates applied: no_behavioural_pass.
5b89b1c40933full audit observations/trust-audit/mcp-server/rekog-labs__nest.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 5b89b1c40933 | CAUTION | B | 82 | first audit |
Questions
What is the Nest MCP server?
A NestJS module to effortlessly create Model Context Protocol (MCP) servers for exposing AI tools, resources, and prompts.
What tools does Nest expose?
200 in total: 216 read-only, 5 that write, and 6 that can delete or overwrite (admin-delete, delete-user, prompt-to-remove, purge-reports, resource-to-remove). Every one is listed on this page with its risk.
Is Nest safe to connect to an agent?
With care. The audit graded it B (82/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Nest need?
It reads ACCESS_TOKEN, ALLOW_UNAUTHENTICATED_ACCESS, AZURE_AD_CLIENT_SECRET, GITHUB_CLIENT_SECRET, GOOGLE_CLIENT_SECRET, JWT_SECRET, MCP_FAKE_AUTH, MRTR_KEY and MRTR_STATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Nest run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @rekog/mcp-nest at 2.0.0-alpha.4.
How current is this page?
The grade is for one exact copy of the source (5b89b1c40933), read on 2026-09-28. The repository is watched and re-audited when it changes.