Atlas / MCP servers / systempromptio / Systemprompt

SystempromptCAUTION

mcp/systempromptio/systemprompt

[DEPRECATED] Superseded by systempromptio/systemprompt-template and systempromptio/systemprompt-core. Reference MCP server implementation (OAuth 2.1, tools, prompts, resources, sampling, notifications).

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
15 14r · 1w · 0d
Transport
streamable-http
License
MIT
Stars
104
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

## ⚠️ Deprecated — no longer maintained This repository has been superseded. All new development and support lives in: - [systempromptio/systemprompt-template](https://github.com/systempromptio/systemprompt-template) — start here. Self-hosted evaluation of the full systemprompt.io AI governance infrastructure. - [systempromptio/systemprompt-core](https://github.com/systempromptio/systemprompt-core) — the underlying Rust library (MCP, A2A, OAuth 2.1, audit, compile-time extensions). Learn more at systemprompt.io. The original README is preserved below for historical reference.

[](https://www.npmjs.com/package/@systemprompt/systemprompt-mcp-server) [](https://opensource.org/licenses/MIT) [](https://twitter.com/tyingshoelaces_) [](https://discord.com/invite/wkAbSuPWpr)

Website | Documentation

Sponsored by systemprompt.io

This MCP server implementation is sponsored by [systemprompt.io](https://systemprompt.io) — creators of the world's first native mobile MCP client for iOS and Android — and provided completely free and open source to the community.

If you find this project useful, we'd appreciate:

  • ⭐ A star on this repository
  • 👍 A like/follow on our social channels
  • 🔗 Sharing with your network

Your support helps us continue creating valuable open source tools for the AI community!

🚀 Learn More: For an interactive walkthrough of this implementation with live SDK testing, visit systemprompt.io/mcp-server

A produc

Read from source at commit 6d47722a5470OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add systemprompt-mcp-server --env JWT_SECRET=${JWT_SECRET} --env MCP_ACCESS_TOKEN=${MCP_ACCESS_TOKEN} --env OAUTH_ISSUER=${OAUTH_ISSUER} --env REDDIT_CLIENT_SECRET=${REDDIT_CLIENT_SECRET} -- npx -y @systemprompt/[email protected]
claude-desktop
{
  "mcpServers": {
    "systemprompt-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@systemprompt/[email protected]"
      ],
      "env": {
        "JWT_SECRET": "${JWT_SECRET}",
        "MCP_ACCESS_TOKEN": "${MCP_ACCESS_TOKEN}",
        "OAUTH_ISSUER": "${OAUTH_ISSUER}",
        "REDDIT_CLIENT_SECRET": "${REDDIT_CLIENT_SECRET}"
      }
    }
  }
}
03

Exposed tools (15)

14 read · 1 write · 0 destructive.

ToolRiskDescription
code_generation_examplereadExample prompt that demonstrates resource injection for code generation
elicitation_examplereadDemonstrates the MCP elicitation pattern for requesting user input during tool execution. Shows how to create elicitation requests with schemas for user profiles, preferences, and credentials.
get_channelreadRetrieves posts from a specific Reddit subreddit (channel). This tool fetches a list of posts from the specified subreddit, sorted by your choice of hot, new, or controversial. It
get_commentreadRetrieves a specific Reddit comment and optionally its complete discussion thread. This tool should be used when you need to examine a particular comment
get_postwriteRetrieves a complete Reddit post including its title, content, metadata, and all associated comments and reply threads. This tool should be used when you need to examine a specific post
languagereadProgramming language to use
mcp_loggingreadRequest the server to log a message for debugging purposes
programmingreadComputer Programming
recentPostsreadJSON string of recent posts from configured subreddits
reddit_suggest_actionreadAnalyzes recent Reddit activity and suggests the next action
sampling_examplereadDemonstrates the MCP sampling pattern for AI-assisted operations. Shows how to create sampling requests for summarization, content generation, analysis, and translation tasks.
search_redditreadSearch Reddit posts across all subreddits or within a specific subreddit
structured_data_examplereadDemonstrates returning structured data alongside text content. Shows examples with user profiles, analytics, weather data, and product information with proper schema validation.
taskreadThe coding task to complete
validation_examplereadDemonstrates input validation with JSON Schema - validates user data and returns structured results
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (12 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
e2e-test/.env.example:15
MCP_BASE_URL=http://127.0.0.1:3000
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
e2e-test/typescript/test-utils.ts:16
export const MCP_BASE_URL = process.env.MCP_BASE_URL || `http://127.0.0.1:${process.env.PORT || '3000'}`;
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.test
.env.test
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/constants/sampling/code-generation-example.ts:10
import type { SamplingPrompt } from '../../types/sampling.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/constants/sampling/suggest-action.ts:1
import type { SamplingPrompt } from '../../types/sampling.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/tools/elicitation-example.ts:22
import type { MCPToolContext } from '../../types/request-context.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/tools/elicitation-example.ts:24
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/tools/get-channel.ts:1
import { getChannelSuccessMessage } from '../../constants/tool/get-channel.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
e2e-test/package.json
@modelcontextprotocol/sdk, dotenv, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, ajv-formats, cookie-parser, cors, dotenv, express, jose, zod
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:132
cat > .env << EOF
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6d47722a5470full audit observations/trust-audit/mcp-server/systempromptio__systemprompt.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076d47722a5470CAUTIONB89first audit
06

Questions

What is the Systemprompt MCP server?

[DEPRECATED] Superseded by systempromptio/systemprompt-template and systempromptio/systemprompt-core. Reference MCP server implementation (OAuth 2.1, tools, prompts, resources, sampling, notifications).

What tools does Systemprompt expose?

15 in total: 14 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Systemprompt safe to connect to an agent?

With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Systemprompt need?

It reads JWT_SECRET, MCP_ACCESS_TOKEN, OAUTH_ISSUER, REDDIT_CLIENT_SECRET and REDDIT_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Systemprompt run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @systemprompt/systemprompt-mcp-server at 1.0.1.

How current is this page?

The grade is for one exact copy of the source (6d47722a5470), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement