Test ClientBLOCK
An MCP Server that's also an MCP Client. Useful for letting Claude develop and test MCPs without needing to reset the application.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP middleware that acts as both a server (to Claude) and a client (to servers under test) for testing MCP servers during development.
Architecture
The MCP Test Client has a dual role:
- It's a server registered with Claude that exposes tools for testing
- It's a client that connects to and tests other MCP servers
┌─────────────┐ ┌───────────────────┐ ┌────────────────┐ │ │ Tools │ │ Client │ │ │ Claude │─────────>│ MCP Test Client │─────────>│ Server Under │ │ │ │ │ │ Test │ └─────────────┘ └───────────────────┘ └────────────────┘
This architecture lets you test MCP servers without registering them directly with Claude.
Features
- Deploy MCP servers to test environments
- Call individual tools with custom arguments
- Run automated test suites
- View server logs
- Test servers before formal registration with Claude
Implementation
The MCP Test Client is implemented with:
- Process Management: Spawns and manages MCP server processes
- MCP SDK Client: Uses the official MCP SDK to communicate with servers
- Custom Transport: Implements a custom transport for stdio communication
- Test Execution: Runs tests and validates responses
- CLI Interface: Provides an interactive testing interface
The current implementation is Phase 1 of the design plan, with future enhancements planned for Phases 2 and 3.
Installation
# Install dependencies npm install # Build the TypeScript project npm run build
Usage
As an MCP Server
The MCP Test Client is registered with Claude via the claude-mcp-local script. You can use the following tools:
- Deploy a server:
mcp__mcp-test__mcp_test_deploy_server({
name: "my-server",
source_path: "/path/to/server",
env_vars: {
"API_KEY": "${API_KEY}"
}
})- Call a tool
a1f9acaddff5OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-test-client -- npx -y [email protected]
{
"mcpServers": {
"mcp-test-client": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (6)
3 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
mcp_test_call_tool | read | Call a tool on a deployed MCP server |
mcp_test_deploy_server | write | Deploy an MCP server to a test environment |
mcp_test_get_logs | read | Get logs from a deployed MCP server |
mcp_test_list_servers | read | List all deployed MCP servers |
mcp_test_run_tests | write | Run tests against a deployed MCP server |
mcp_test_stop_server | write | Stop a deployed MCP server |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
## [](#before-you-begin) Before you begin
### [](#check-system-requirements) Check system requirements
### [](#install-and-authenticate) Install and authenticate
## [](#core-features-and-workflows) Core features and workflows
### [](#security-and-privacy-by-design) Security and privacy by design
cd "$(dirname "$0")/../../"
cd "$(dirname "$0")/../../.."
@modelcontextprotocol/sdk, dockerode, zod, @types/dockerode, @types/node, ts-node, typescript
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
load_dotenv() # load environment variables from .env
- **[iTerm MCP](https://github.com/ferrislucas/iterm-mcp)** - Integration with iTerm2 terminal emulator for macOS, enabling LLMs to execute and monitor terminal commands.
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass, no_license.
a1f9acaddff5full audit observations/trust-audit/mcp-server/willccbb__test-client-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a1f9acaddff5 | BLOCK | D | 69 | first audit |
Questions
What is the Test Client MCP server?
An MCP Server that's also an MCP Client. Useful for letting Claude develop and test MCPs without needing to reset the application.
What tools does Test Client expose?
6 in total: 3 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Test Client safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Test Client need?
No credential environment variables were found in its source, so it appears to need none.
How does Test Client run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-test-client at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (a1f9acaddff5), read on 2026-10-07. The repository is watched and re-audited when it changes.