Prompts ServerBLOCK
Model Context Protocol server for managing, storing, and providing prompts and prompt templates for LLM interactions.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Simple MCP server for managing AI prompts and agent configurations with direct claude CLI orchestration.
What It Does
- Stores prompts as JSON files in
data/prompts/ - Exposes MCP tools for querying and managing prompts
- Provides agent templates for project orchestration
- Works with Claude Desktop, Cursor, and other MCP clients
Quick Start
1. Install
pnpm install pnpm build
2. Start MCP Server
pnpm start
3. Configure Claude Desktop
Add to ~/.claude/mcp.json:
{
"mcpServers": {
"prompts": {
"command": "node",
"args": ["/absolute/path/to/mcp-prompts/dist/mcp-server-standalone.js"],
"env": {
"PROMPTS_DIR": "/absolute/path/to/mcp-prompts/data/prompts"
}
}
}
}4. Use in Claude
Ask Claude:
- "List all prompts tagged with esp32"
- "Get the esp32-fft-configuration-guide prompt"
- "Create a new prompt for Python FastAPI best practices"
Orchestrating Projects
Use the orchestrate script to analyze entire projects:
./scripts/orchestrate-project.sh ~/projects/mia analyze ./scripts/orchestrate-project.sh ~/projects/esp32-bpm-detector review
This automatically:
- Detects project type
- Loads appropriate main agent
- Spawns specialized subagents
- Runs comprehensive analysis
- Returns structured results
MCP Tools
Prompts Organization
data/prompts/ ├── main-agents/ # 7 project orchestration templates │ ├── main_agent_python_backend.json │ ├── main_agent_cpp_backend.json │ ├
47a741a9e4fcOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-fbs --env STRIPE_SECRET_KEY=${STRIPE_SECRET_KEY} --env STRIPE_WEBHOOK_SECRET=${STRIPE_WEBHOOK_SECRET} -- npx -y @sparesparrow/[email protected]{
"mcpServers": {
"mcp-fbs": {
"command": "npx",
"args": [
"-y",
"@sparesparrow/[email protected]"
],
"env": {
"STRIPE_SECRET_KEY": "${STRIPE_SECRET_KEY}",
"STRIPE_WEBHOOK_SECRET": "${STRIPE_WEBHOOK_SECRET}"
}
}
}
}Exposed tools (109)
92 read · 15 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
HighErrorRate | read | High error rate in API Gateway |
HighLatency | read | High latency in API Gateway |
add_prompt | write | |
aggregate_embedded_telemetry | read | Aggregate telemetry data from multiple embedded devices |
analyze_android_clipboard_patterns | read | Analyze clipboard usage patterns using cognitive prompts |
analyze_changed_code | read | Analyze code changes using git diff + static analysis |
analyze_code | read | Perform unified static code analysis on source files |
analyze_embedded_patterns | read | Analyze usage patterns across all embedded devices |
analyze_telemetry_patterns | read | Analyze telemetry patterns using cognitive prompts |
android-clipboard-analysis-workflow | read | Workflow for analyzing Android clipboard usage patterns |
android_launch_app | read | Launch an app on Android device |
android_play_sound | read | Play a sound on Android device |
android_show_toast | read | Show a toast message on Android device |
android_take_screenshot | read | Take a screenshot on Android device |
apply_template | write | |
available_tools | read | Debugging tools available |
backup_embedded_data | read | Backup data from all embedded devices |
build_config | read | Build system and configuration |
calibrate_esp32_sensors | read | Calibrate ESP32 sensors |
change_risk | read | Risk of making changes during debugging |
code | read | Code to review |
code_files | read | Key source files |
configure_esp32 | write | Send configuration to ESP32 device |
cpp-static-analysis-workflow | read | Systematic workflow for C++ static analysis |
cppcheck-config-desktop-general-default | read | Default cppcheck configuration for desktop C++ general analysis |
cppcheck-config-embedded-esp32-memory-default | read | Default cppcheck configuration for ESP32 embedded memory analysis |
cppcheck-config-embedded-esp32-security-default | read | Default cppcheck configuration for ESP32 embedded security analysis |
create_prompt | write | Create a new prompt |
database_type | read | Database system type |
debug_session_start | write | Start a debugging session with GDB/LLDB |
delete_prompt | destructive | |
detect-embedded-device-capabilities | read | Analyze embedded device capabilities and recommend appropriate tools |
detect-embedded-project-context | read | Analyze embedded project structure and requirements |
detect-project-context | read | Analyze project structure to determine type, language, and context |
discover_embedded_devices | read | Discover all available embedded devices (ESP32, Android) |
docker_exec_analysis | write | Execute analysis tools in Docker containers |
embedded-debugging-strategy-selection | read | Meta-cognitive strategy selection for embedded systems debugging |
embedded-memory-constrained-analysis | read | Memory analysis for resource-constrained embedded systems |
embedded-system-quality-assessment | read | Comprehensive quality assessment framework for embedded systems |
embedded-systems-constraints-knowledge | read | Core knowledge about embedded systems constraints and best practices |
embedded-to-software-debugging-analogy | read | Applying embedded systems debugging patterns to general software development |
emergency_embedded_shutdown | read | Emergency shutdown of all embedded devices |
endpoint | read | API endpoint path |
esp32-architecture-knowledge | read | ESP32 microcontroller architecture and constraints knowledge |
esp32-debugging-workflow | read | Systematic debugging workflow for ESP32 embedded systems |
execute_cross_device_workflow | write | Execute a workflow that coordinates multiple embedded devices |
files | read | List of key project files |
get_android_battery_status | read | Get Android device battery status |
get_android_clipboard | read | Get current clipboard content from Android device |
get_android_context | read | Get contextual information about Android device state |
get_android_device_info | read | Get Android device information and capabilities |
get_android_location | read | Get Android device location data |
get_android_network_status | read | Get Android device network status |
get_android_sensor_data | read | Get Android device sensor data |
get_embedded_context | read | Get contextual information about embedded device state |
get_embedded_device_status | read | Get status overview of all embedded devices |
get_esp32_status | read | Get current status and system information from ESP32 |
get_esp32_telemetry | read | Get current telemetry data from ESP32 device |
get_prompt | read | |
get_stats | read | |
get_telemetry_history | read | Get historical telemetry data from ESP32 |
git_analyze_history | write | Analyze git commit history for debugging insights |
hardware_platform | read | Target hardware platform |
hardware_specs | read | Target hardware specifications |
identify-analysis-goals | read | Determine the appropriate analysis goals based on project context and symptoms |
interfaces | read | Communication interfaces used |
language | read | Programming language of the code |
list_categories | read | List all prompt categories with counts. Use this to discover categories before drilling into one with list_prompts. |
list_prompts | read | |
list_slash_commands | read | List available slash commands |
memory-management-principles | read | Core principles of memory management across different programming paradigms |
memory_constraints | read | Memory limitations |
method | read | HTTP method |
mock-workflow | read | Mock workflow for development |
monitor_embedded_health | read | Monitor health and status of all embedded devices |
parameters | read | Request parameters description |
performance-regression-diagnosis | read | Systematic approach to diagnosing performance regressions |
performance_issues | read | Known performance issues |
predict_embedded_behavior | read | Predict device behavior based on historical patterns |
problem_description | read | Description of the debugging problem |
project_context | read | Project type and characteristics |
pylint-config-python-general-default | read | Default pylint configuration for Python general analysis |
pylint-config-python-security-default | read | Default pylint configuration for Python security analysis |
pytest-config-python-default | read | Default pytest configuration for Python test execution |
query | read | SQL query to optimize |
reset_esp32 | destructive | Reset the ESP32 device |
risk_level | read | Criticality of the project |
root_contents | read | Contents of root directory |
rt_requirements | read | Real-time requirements |
run_tests | write | Execute tests with automatic framework detection |
search_prompts | read | Search prompts by query |
select-debugging-strategy | read | Choose appropriate debugging strategy based on context and constraints |
set_android_clipboard | write | Set clipboard content on Android device |
slash_command | write | Execute a slash command to quickly apply a prompt template |
static-analysis-tools-knowledge | read | Knowledge about static analysis tools and their capabilities |
suggest_slash_commands | read | Get slash command suggestions based on a query |
symptoms | read | Issues or symptoms reported |
sync_android_clipboard | write | Synchronize clipboard across devices |
sync_clipboard_across_devices | write | Synchronize clipboard content across all devices |
system_access_level | read | Level of system access (full, limited, remote) |
table_size | read | Approximate table size |
time_available | read | Time available for debugging |
time_constraint | read | Available time for analysis |
two-phase-analysis-pattern | read | Universal two-phase analysis pattern applicable across domains |
update_prompt | write | |
use-git-integration-mcp | read | Demonstrates using MCP tools for git-based development workflows |
use-mcp-prompts-list | read | Demonstrates how to use the list_prompts MCP tool |
use-static-analysis-mcp | read | Demonstrates using MCP tools for static analysis workflows |
workflow_execute | write | Execute a multi-tool orchestrated workflow |
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
- ~/.aws:/root/.aws:ro
"POSTGRES_URL": "postgres://postgres:postgres@localhost:5432/mcp_prompts",
"POSTGRES_URL": "postgres://postgres:postgres@localhost:5432/mcp_prompts",
ENV POSTGRES_URL=postgres://postgres:postgres@postgres:5432/mcp_prompts
- POSTGRES_URL=postgres://postgres:postgres@postgres:5432/mcp_prompts
learning.db
dev-intelligence-orchestrator-v2.skill
dev-intelligence-orchestrator.skill
parse_build_errors.cpython-312.pyc
fetch('http://127.0.0.1:7250/ingest/d33ee5cc-2ed5-4c57-a04d-227ffe7b5c8f',{method:'POST',headers:{'Content-Type':'application/json'},body:JSON.stringify({location:'automatic-prompt-generation.service.fetch('http://127.0.0.1:7250/ingest/d33ee5cc-2ed5-4c57-a04d-227ffe7b5c8f',{method:'POST',headers:{'Content-Type':'application/json'},body:JSON.stringify({location:'project-scaffold.service.ts:188',mes"POSTGRES_URL": "postgres://postgres:postgres@localhost:5432/mcp_prompts",
delete_prompt, reset_esp32
.directory
.eslintignore
.npmrc.github
.prettierignore
.swcrc
"content": "# HAL Configuration Manager (ngapy-inspired)\n\nManage hierarchical configuration with intelligent caching for hardware abstraction layer.\n\n## Configuration Hierarchy\n\n```yaml\n# 1. Te
return require('crypto').createHash('md5').update(JSON.stringify(context)).digest('hex');import { IPromptRepository } from '../../core/ports/prompt-repository.interface';import { Prompt } from '../../core/entities/prompt.entity';import { PromptMetadata } from '../../core/entities/prompt-metadata.entity';import { ICatalogRepository } from '../../core/ports/catalog-repository.interface';import { IEventBus } from '../../core/ports/event-bus.interface';Gates applied: no_behavioural_pass.
47a741a9e4fcfull audit observations/trust-audit/mcp-server/sparesparrow__prompts-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 47a741a9e4fc | BLOCK | F | 46 | first audit |
Questions
What is the Prompts Server MCP server?
Model Context Protocol server for managing, storing, and providing prompts and prompt templates for LLM interactions.
What tools does Prompts Server expose?
109 in total: 92 read-only, 15 that write, and 2 that can delete or overwrite (delete_prompt, reset_esp32). Every one is listed on this page with its risk.
Is Prompts Server safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Prompts Server need?
It reads STRIPE_SECRET_KEY and STRIPE_WEBHOOK_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Prompts Server run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @sparesparrow/mcp-fbs at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (47a741a9e4fc), read on 2026-10-07. The repository is watched and re-audited when it changes.