Skip to main content
Glama
Abanoub-Rodolf

mcp-server-starter-demo

README.md
# MCP Server Starter Demo

A free, deliberately small TypeScript MCP server from [ThynkQ](https://thynkq.com). It uses the current official SDK, runs over stdio, validates every input with Zod, and exposes two pure in-memory tools:

- `echo`: returns validated text unchanged;
- `text_stats`: counts words and characters.

It does not read files, call the network, spawn subprocesses, or accept secrets.

## Run it

Requires Node.js 22 or newer.

```bash
npm install
npm run check
npm start
```

Build first, then copy `configs/claude-desktop.example.json` and replace the placeholder with the absolute path to `dist/index.js`.

## Why this repository is limited

This is a public teaching demo, not the paid production starter. It intentionally omits:

- streamable HTTP transport;
- bearer authentication and constant-time comparison;
- rate limiting and DNS rebinding protection;
- structured redacted logging;
- typed safe error handling;
- the 72-test transport and security suite;
- three production client configurations and saved scan proof.

Those hardening layers are part of **MCP Server Starter Pro**, which is in final storefront preparation. Follow [ThynkQ's MCP work](https://thynkq.com/products/mcp-scan) for the release.

If you need a human review of a production MCP deployment, see [ThynkQ's MCP Risk Review](https://thynkq.com/services/mcp-risk-review).

## Related free project

Before connecting a third-party MCP server, run the free [MCP Security Review Preview](https://github.com/Abanoub-Rodolf/mcp-security-review-preview). It is a limited Claude Code preflight that keeps raw scanner evidence outside model-facing output.

Also free: the [mcp-scan](https://github.com/Abanoub-Rodolf/mcp-scan) security scanner, and the [MCP Security Evidence Redactor](https://github.com/Abanoub-Rodolf/mcp-security-evidence-redactor) for safe severity-count summaries of scan output.

## Security model

The client launches this process and communicates over stdin/stdout. All operational logging goes to stderr so stdout remains reserved for JSON-RPC. Both example tools are pure functions with bounded inputs.

## License

MIT. See [LICENSE](LICENSE).

Built by [Abanoub Rodolf Boctor](https://thynkq.com/about) at [ThynkQ](https://thynkq.com).

TDQS

A4/5.0

Scored across 2 tools

Disambiguation5/5

Echo returns input unchanged, while text_stats computes word and character counts. Their purposes are entirely distinct with no overlap or possibility of confusion.

Naming Consistency3/5

Echo is a bare verb, while text_stats is a compound noun with an underscore. There's no consistent verb_noun pattern, but both are short and readable.

Tool Count4/5

Two tools is below the typical 3-15 range, but for a starter demo server this minimal scope is intentionally appropriate and each tool earns its place.

Completeness5/5

The domain appears to be simple in-memory text operations. Echo and text_stats cover returning text and analyzing it, with no filesystem or network operations claimed, so no obvious gaps exist.

Maintenance

ActivityNo data
ResponsivenessNo issues