Atlas / MCP servers / samanhappy / Mcphub

McphubBLOCK

mcp/samanhappy/mcphub

Self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.

Verdict
BLOCK
Grade
F
Trust score
40 /100
Exposed tools
85 76r · 7w · 2d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
2,465
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An open-source, self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.

[](https://github.com/samanhappy/mcphub/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@samanhappy/mcphub) [](https://hub.docker.com/r/samanhappy/mcphub) [](LICENSE) [](https://discord.gg/2BJehJZVH5) [](https://github.com/samanhappy/mcphub/stargazers)

English | Français | 中文版

MCPHub provides a unified control point between AI clients and MCP servers. Connect local and remote MCP servers once, organize and route their capabilities through stable endpoints, control access with authentication, scoped credentials, and per-user visibility, and operate everything with centralized logs, activity tracking, and health monitoring.

It works with MCP clients such as Claude Code, Cursor, Cherry Studio, OpenWebUI, and other MCP-compatible applications.

🌐 Website, Demo & Docs

🚀 Features

Connect once, expose everywhere

  • Smart Routing ⭐ - AI-powered tool discovery using vector semantic search (Learn more)
  • Unified MCP Gateway - Expose all connected servers through stable MCP endpoints, including routes for groups and individual servers
  • Server Aliases and Routing - D
Read from source at commit 77e1aac586dfOBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcphub --env ACCESS_TOKEN=${ACCESS_TOKEN} --env ADMIN_PASSWORD=${ADMIN_PASSWORD} --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} -- npx -y @samanhappy/mcphub@dev
claude-desktop
{
  "mcpServers": {
    "mcphub": {
      "command": "npx",
      "args": [
        "-y",
        "@samanhappy/mcphub@dev"
      ],
      "env": {
        "ACCESS_TOKEN": "${ACCESS_TOKEN}",
        "ADMIN_PASSWORD": "${ADMIN_PASSWORD}",
        "API_KEY": "${API_KEY}",
        "AUTH_TOKEN": "${AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (85)

76 read · 7 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AliceGread
BobGread
FetchreadHTTP fetch tool
FirecrawlreadWeb scraping
IntroreadIntroduction
MixedGread
Pageread
areadaa
admin-groupreadowned by admin
apps-open_dashboardreadOpen dashboard
apps-poll_dashboardreadRefresh dashboard
breadbb
blankreadFetch fallback conditions
builtin-no-optional-fieldsread
call_toolwriteSTEP 3 of 3: Use this tool AFTER describe_tool to actually execute/invoke any tool you found. This is the execution step.\n\nWorkflow: search_tools → describe_tool → call_tool with the chosen tool name and required arguments.\n\nIMPORTANT: Always use describe_tool first to get the tool
create_objectwriteCreate object
create_thingwriteCreate thing
currentreadFetch current conditions
current_timereadCurrent time
db-db-queryread
delete_objectdestructiveDelete object by id
delete_objectsdestructiveBulk delete objects
describe_toolreadSTEP 2 of 3: Use this tool AFTER search_tools to get the full parameter schema for a specific tool. This provides the complete inputSchema needed to correctly invoke the tool with call_tool.\n\nWorkflow: search_tools → describe_tool → call_tool
example-openapiread
fetch_htmlreadFetch HTML
fetch_urlreadFetch a URL
find_userreadFind a user
getOtherreadother
getProtectedreadprotected
getSubreadsub
getUsersreadGet users
get_current_timereadGet current time
get_recordreadGet a record by id
get_tenant_recordreadGet a record within a tenant
get_usersreadGet users
gmail-list_accountsreadList accounts
gmail-send_emailwriteSend an email
layered-openapiread
legacyread
list_by_tagsreadList records by tags
loginreadlogin
new-apiread
new-toolreadNew tool
oauth-serverread
open-dashboardreadOpen the dashboard
org-searchreadOrg web search
preadpp
pingreadping
plain-openapiread
poll-dashboardreadRefresh dashboard data
poll_dashboardreadRefresh an MCP App
rreadrd
readreadRead access to your MCP servers and tools
read_internalreadread
redisreadFast in-memory data store and cache
redis-getreadGet a cache value
remote-serverread
replace_flagsreadReplace flags
resource_disabledreadUpstream disabled description
resource_hostsreadUpstream hosts description
resource_no_overridereadUpstream no-override description
s1-treada tool
searchreadSearch
search_toolsreadSearch for relevant tools across ${scopeDescription}.
seerr-get_moviereadGet a movie
serenareadmy server note
shared-serverread
summarizereadSummarize text
tread
test-dao-groupreadTest group for DAO operations
test-groupreadTest group for development
timeread
time-current_timereadGet current time
time-disabled_toolread
time-poll_dashboardreadRefresh an MCP App
u8read
undefinedreadFetch undefined fallback conditions
upload_docwriteUpload a doc
upload_filewriteUpload a file
weather-alpharead
weather-betaread
weather-currentread
weather-forecastread
writewriteExecute tools and modify MCP server configurations
xreada desc
04

Trust audit

BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (13 observation(s))
Network
declared (8 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/clients/openapi.ts:517
return yaml.load(raw);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:38
# DB_URL=postgresql://mcphub:password@localhost:5432/mcphub
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
articals/intro2.md:5
现代 AI 应用场景中,将大模型(LLM)与各种数据源和工具无缝对接,往往需要手动编写大量胶水代码,并且无法快速复用。MCP(Model Context Protocol)协议由 Anthropic 在 2024 年开源,旨在提供类似“USB‐C”接口般的标准化通信方式,简化 AI 助手与内容仓库、业务系统等的集成流程。然而,MCP 服务器部署常常需要大量环境依赖、手动配置及持续运行,开发者常因安
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
articals/intro2.md:228
尽管目前各家平台都在陆续推出各类 MCP 云服务,但在数据隐私、合规性和定制化需求日益增长的背景下,MCPHub 仍然是一个值得关注的本地部署解决方案。
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude
.claude
Why it matters. link not followed
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:115
#         export DB_URL="postgresql://postgres:postgres@localhost:5432/mcphub_test"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/configuration/docker-setup.mdx:117
- DB_URL=postgresql://mcphub:password@postgres:5432/mcphub
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/configuration/docker-setup.mdx:385
- DB_URL=postgresql://mcphub:password@postgres:5432/mcphub
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/configuration/environment-variables.mdx:174
DB_URL=postgresql://mcphub:secret@db:5432/mcphub
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/controllers/bearerKeyController.test.ts:58
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/controllers/serverController.test.ts:513
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/controllers/serverController.test.ts:522
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/controllers/serverController.test.ts:531
token: 'mcphub_abcdefghijklmnopqrstuvwxyz',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/integration/personal-credentials.test.ts:527
token: 'unrelated-scope-token',
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/features/server-management.mdx:167
"SLACK_BOT_TOKEN": "xoxb-your-bot-token",
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/zh/features/server-management.mdx:151
"SLACK_BOT_TOKEN": "xoxb-your-bot-token",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_object, delete_objects
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coveragerc
.coveragerc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
frontend/src/components/ui/Badge.tsx:3
import { cn } from '../../utils/cn';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
frontend/src/components/ui/Button.tsx:3
import { cn } from '../../utils/cn';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
frontend/src/i18n.ts:6
import enTranslation from '../../locales/en.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
frontend/src/i18n.ts:7
import zhTranslation from '../../locales/zh.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
frontend/src/i18n.ts:8
import frTranslation from '../../locales/fr.json';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/clients/__tests__/openapi-external-ref.test.ts:94
const client = makeSchemaClient('http://169.254.169.254/latest/meta-data/');
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 77e1aac586dffull audit observations/trust-audit/mcp-server/samanhappy__mcphub.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2377e1aac586dfBLOCKF40source changed, verdict held
2026-09-1844de2b355405BLOCKF40first audit
06

Questions

What is the Mcphub MCP server?

Self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.

What tools does Mcphub expose?

85 in total: 76 read-only, 7 that write, and 2 that can delete or overwrite (delete_object, delete_objects). Every one is listed on this page with its risk.

Is Mcphub safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (40/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mcphub need?

It reads ACCESS_TOKEN, ADMIN_PASSWORD, API_KEY, AUTH_TOKEN, AZURE_OPENAI_API_KEY, BETTER_AUTH_BASE_PATH, BETTER_AUTH_DISABLE_AUTO_CREATE, BETTER_AUTH_ENABLED, BETTER_AUTH_GITHUB_ENABLED, BETTER_AUTH_GOOGLE_ENABLED, BETTER_AUTH_OIDC_DISCOVERY_URL and BETTER_AUTH_OIDC_ENABLED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcphub run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @samanhappy/mcphub at dev.

How current is this page?

The grade is for one exact copy of the source (77e1aac586df), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement