mcp-server-template
Secure MCP server template in TypeScript and Python, safe by default.
What it is
Secure MCP server template in TypeScript and Python: a starting point for a Model Context Protocol server that is safe by default. Both reference implementations ship the same four read-only tools and the same controls: strict input validation, file access bounded to allowlisted directories, network access bounded to allowlisted hosts with SSRF protection, structured logs that redact secrets, a health tool, stdio transport by default, and an optional streamable HTTP transport that is bound to 127.0.0.1, requires a bearer token, rate-limits clients and caps request bodies. Tests, Dockerfiles with digest-pinned bases and non-root users, CI with Semgrep, gitleaks and CodeQL, and SBOMs on release are included.
Install
cd typescript
npm ci && npm run build && npm test
MCP_ALLOWED_DIRS=$PWD/../docs node dist/index.js # stdio server exposing one directory
From the README; see the full README for every option.
Links
Releases
Topics: agent-security, ai-agents, ai-security, devsecops, docker, fastmcp, github-actions, hacktoberfest, llm-security, mcp, mcp-server, model-context-protocol, python, sbom, security-automation, ssrf, template, template-repository, typescript