Home / MCP tooling

mcp-server-template

Secure MCP server template in TypeScript and Python, safe by default.

TypeScript · MIT · latest v0.1.0

What it is

Secure MCP server template in TypeScript and Python: a starting point for a Model Context Protocol server that is safe by default. Both reference implementations ship the same four read-only tools and the same controls: strict input validation, file access bounded to allowlisted directories, network access bounded to allowlisted hosts with SSRF protection, structured logs that redact secrets, a health tool, stdio transport by default, and an optional streamable HTTP transport that is bound to 127.0.0.1, requires a bearer token, rate-limits clients and caps request bodies. Tests, Dockerfiles with digest-pinned bases and non-root users, CI with Semgrep, gitleaks and CodeQL, and SBOMs on release are included.

Install

cd typescript
npm ci && npm run build && npm test
MCP_ALLOWED_DIRS=$PWD/../docs node dist/index.js        # stdio server exposing one directory

From the README; see the full README for every option.

Releases

Topics: agent-security, ai-agents, ai-security, devsecops, docker, fastmcp, github-actions, hacktoberfest, llm-security, mcp, mcp-server, model-context-protocol, python, sbom, security-automation, ssrf, template, template-repository, typescript