Atlas / MCP servers / willccbb / Test Client

Test ClientBLOCK

mcp/willccbb/test-client-1

An MCP Server that's also an MCP Client. Useful for letting Claude develop and test MCPs without needing to reset the application.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
6 3r · 3w · 0d
Transport
stdio
License
—
Stars
127
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP middleware that acts as both a server (to Claude) and a client (to servers under test) for testing MCP servers during development.

Architecture

The MCP Test Client has a dual role:

  • It's a server registered with Claude that exposes tools for testing
  • It's a client that connects to and tests other MCP servers
┌─────────────┐          ┌───────────────────┐          ┌────────────────┐
│             │  Tools   │                   │  Client  │                │
│   Claude    │─────────>│  MCP Test Client  │─────────>│  Server Under  │
│             │          │                   │          │     Test       │
└─────────────┘          └───────────────────┘          └────────────────┘

This architecture lets you test MCP servers without registering them directly with Claude.

Features

  • Deploy MCP servers to test environments
  • Call individual tools with custom arguments
  • Run automated test suites
  • View server logs
  • Test servers before formal registration with Claude

Implementation

The MCP Test Client is implemented with:

  • Process Management: Spawns and manages MCP server processes
  • MCP SDK Client: Uses the official MCP SDK to communicate with servers
  • Custom Transport: Implements a custom transport for stdio communication
  • Test Execution: Runs tests and validates responses
  • CLI Interface: Provides an interactive testing interface

The current implementation is Phase 1 of the design plan, with future enhancements planned for Phases 2 and 3.

Installation

# Install dependencies
npm install

# Build the TypeScript project
npm run build

Usage

As an MCP Server

The MCP Test Client is registered with Claude via the claude-mcp-local script. You can use the following tools:

  1. Deploy a server:
mcp__mcp-test__mcp_test_deploy_server({
name: "my-server",
source_path: "/path/to/server",
env_vars: {
"API_KEY": "${API_KEY}"
}
})
  1. Call a tool
Read from source at commit a1f9acaddff5OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-test-client -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-test-client": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (6)

3 read · 3 write · 0 destructive.

ToolRiskDescription
mcp_test_call_toolreadCall a tool on a deployed MCP server
mcp_test_deploy_serverwriteDeploy an MCP server to a test environment
mcp_test_get_logsreadGet logs from a deployed MCP server
mcp_test_list_serversreadList all deployed MCP servers
mcp_test_run_testswriteRun tests against a deployed MCP server
mcp_test_stop_serverwriteStop a deployed MCP server
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/claude-code/cc-overview.md:123
## [](#before-you-begin) Before you begin
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/claude-code/cc-overview.md:125
### [](#check-system-requirements) Check system requirements
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/claude-code/cc-overview.md:147
### [](#install-and-authenticate) Install and authenticate
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/claude-code/cc-overview.md:178
## [](#core-features-and-workflows) Core features and workflows
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/claude-code/cc-overview.md:182
### [](#security-and-privacy-by-design) Security and privacy by design
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/build-and-register.sh:17
cd "$(dirname "$0")/../../"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/register-with-claude.sh:14
cd "$(dirname "$0")/../../.."
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dockerode, zod, @types/dockerode, @types/node, ts-node, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/mcp/github-modelcontextprotocol-python-sdk-README.md:365
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp/modelcontextprotocol.io-quickstart-client.md:91
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
docs/mcp/modelcontextprotocol-servers-README.md:133
- **[iTerm MCP](https://github.com/ferrislucas/iterm-mcp)** - Integration with iTerm2 terminal emulator for macOS, enabling LLMs to execute and monitor terminal commands.
Why it matters. remote text is to be obeyed as instructions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/mcp/modelcontextprotocol.io-quickstart-server.md:61
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha a1f9acaddff5full audit observations/trust-audit/mcp-server/willccbb__test-client-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a1f9acaddff5BLOCKD69first audit
06

Questions

What is the Test Client MCP server?

An MCP Server that's also an MCP Client. Useful for letting Claude develop and test MCPs without needing to reset the application.

What tools does Test Client expose?

6 in total: 3 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Test Client safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Test Client need?

No credential environment variables were found in its source, so it appears to need none.

How does Test Client run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-test-client at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (a1f9acaddff5), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement