Atlas / MCP servers / sparfenyuk / Mcp Proxy

Mcp ProxyCAUTION

mcp/sparfenyuk/mcp-proxy

A bridge between Streamable HTTP and stdio MCP transports

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
2,760
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://codecov.io/gh/sparfenyuk/mcp-proxy)

  • mcp-proxy
  • About
  • 1. stdio to SSE/StreamableHTTP
  • 1.1 Configuration
  • 1.2 Example usage
  • 2. SSE to stdio
  • 2.1 Configuration
  • 2.2 Example usage
  • Named Servers
  • Installation
  • Installing via PyPI
  • Installing via Github repository (latest)
  • Installing as container
  • Troubleshooting
  • Extending the container image
  • Docker Compose Setup
  • Command line arguments
  • Example config file
  • Testing

About

The mcp-proxy is a tool that lets you switch between server transports. There are two supported modes:

  1. stdio to SSE/StreamableHTTP
  2. SSE to stdio

1. stdio to SSE/StreamableHTTP

Run a proxy server from stdio that connects to a remote SSE server.

This mode allows clients like Claude Desktop to communicate to a remote server over SSE even though it is not supported natively.

graph LR
A["Claude Desktop"]  |stdio| B["mcp-proxy"]
B  |SSE| C["External MCP Server"]

style A fill:#ffe6f9,stroke:#333,color:black,stroke-width:2px
style B fill:#e6e6ff,stroke:#333,color:black,stroke-width:2px
style C fill:#e6ffe6,stroke:#333,color:black,stroke-width:2px

1.1 Configuration

This

Read from source at commit 82c7b53edf5aOBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-proxy --env API_ACCESS_TOKEN=${API_ACCESS_TOKEN} -- uvx mcp-proxy
claude-desktop
{
  "mcpServers": {
    "mcp-proxy": {
      "command": "uvx",
      "args": [
        "mcp-proxy"
      ],
      "env": {
        "API_ACCESS_TOKEN": "${API_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
echoreadEcho tool
test_toolreadA test tool
toolreadtool-description
tool-namereadtool-description
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/mcp_proxy/httpx_client.py:62
normalized_verify = False
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:176
If a default server is specified (the `command_or_url` argument without `--named-server` or `--named-server-config`), it will be accessible at the root paths (e.g., `http://127.0.0.1:8080/sse`).
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:178
Named servers (whether defined by `--named-server` or `--named-server-config`) will be accessible under `/servers/<server-name>/` (e.g., `http://127.0.0.1:8080/servers/fetch1/sse`).
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:433
mcp-proxy http://127.0.0.1:8080/sse

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha 82c7b53edf5afull audit observations/trust-audit/mcp-server/sparfenyuk__mcp-proxy.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2282c7b53edf5aCAUTIONB89source changed, verdict held
06

Questions

What is the Mcp Proxy MCP server?

A bridge between Streamable HTTP and stdio MCP transports

What tools does Mcp Proxy expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mcp Proxy safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mcp Proxy need?

It reads API_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcp Proxy run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-proxy.

How current is this page?

The grade is for one exact copy of the source (82c7b53edf5a), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement