mcp-server-starter-demo
README.md
# MCP Server Starter Demo
A free, deliberately small TypeScript MCP server from [ThynkQ](https://thynkq.com). It uses the current official SDK, runs over stdio, validates every input with Zod, and exposes two pure in-memory tools:
- `echo`: returns validated text unchanged;
- `text_stats`: counts words and characters.
It does not read files, call the network, spawn subprocesses, or accept secrets.
## Run it
Requires Node.js 22 or newer.
```bash
npm install
npm run check
npm start
```
Build first, then copy `configs/claude-desktop.example.json` and replace the placeholder with the absolute path to `dist/index.js`.
## Why this repository is limited
This is a public teaching demo, not the paid production starter. It intentionally omits:
- streamable HTTP transport;
- bearer authentication and constant-time comparison;
- rate limiting and DNS rebinding protection;
- structured redacted logging;
- typed safe error handling;
- the 72-test transport and security suite;
- three production client configurations and saved scan proof.
Those hardening layers are part of **MCP Server Starter Pro**, which is in final storefront preparation. Follow [ThynkQ's MCP work](https://thynkq.com/products/mcp-scan) for the release.
If you need a human review of a production MCP deployment, see [ThynkQ's MCP Risk Review](https://thynkq.com/services/mcp-risk-review).
## Related free project
Before connecting a third-party MCP server, run the free [MCP Security Review Preview](https://github.com/Abanoub-Rodolf/mcp-security-review-preview). It is a limited Claude Code preflight that keeps raw scanner evidence outside model-facing output.
Also free: the [mcp-scan](https://github.com/Abanoub-Rodolf/mcp-scan) security scanner, and the [MCP Security Evidence Redactor](https://github.com/Abanoub-Rodolf/mcp-security-evidence-redactor) for safe severity-count summaries of scan output.
## Security model
The client launches this process and communicates over stdin/stdout. All operational logging goes to stderr so stdout remains reserved for JSON-RPC. Both example tools are pure functions with bounded inputs.
## License
MIT. See [LICENSE](LICENSE).
Built by [Abanoub Rodolf Boctor](https://thynkq.com/about) at [ThynkQ](https://thynkq.com).
TDQS
A4/5.0
Scored across 2 tools
Disambiguation5/5
Echo returns input unchanged, while text_stats computes word and character counts. Their purposes are entirely distinct with no overlap or possibility of confusion.
Naming Consistency3/5
Echo is a bare verb, while text_stats is a compound noun with an underscore. There's no consistent verb_noun pattern, but both are short and readable.
Tool Count4/5
Two tools is below the typical 3-15 range, but for a starter demo server this minimal scope is intentionally appropriate and each tool earns its place.
Completeness5/5
The domain appears to be simple in-memory text operations. Echo and text_stats cover returning text and analyzing it, with no filesystem or network operations claimed, so no obvious gaps exist.
Maintenance
ActivityNo data
ResponsivenessNo issues