Modular MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Modular MCP Serverread the contents of config.json"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Modular MCP Server
A config-driven, modular MCP (Model Context Protocol) server with zero dependencies. Just edit a JSON config file to enable/disable tools and plugins!
Features
Config-Driven: Enable/disable tools by editing
config.jsonZero Dependencies: Pure Node.js (18+), no npm packages needed
Plugin Architecture: Easy to add new plugins
Security: Built-in access controls and sandboxing per tool
Simple: ~500 lines of core code
Fast: Minimal overhead, direct tool execution
Related MCP server: Promethean OS MCP
Quick Start
# 1. Create or edit config.json
cp config.example.json config.json
# 2. Start the server
node server.js
# Or specify a config file
node server.js my-config.jsonHow It Works
Config File Structure
The config.json file controls everything:
{
"server": {
"name": "my-mcp-server",
"version": "1.0.0"
},
"plugins": [
{
"name": "utils",
"type": "builtin",
"module": "utils",
"enabled": true,
"tools": [
{
"name": "echo",
"enabled": true
},
{
"name": "calculate",
"enabled": true
}
]
}
]
}That's it! No code changes needed to add/remove tools.
Adding a Tool
Want to enable file operations? Just edit the config:
{
"plugins": [
{
"name": "filesystem",
"type": "builtin",
"module": "filesystem",
"enabled": true,
"tools": [
{
"name": "read_file",
"enabled": true,
"allowedPaths": [".", "/tmp"]
},
{
"name": "write_file",
"enabled": true
}
]
}
]
}Restart the server - done!
Disabling a Tool
Set "enabled": false:
{
"name": "delete_file",
"enabled": false // ← Tool won't be available
}Built-in Plugins
Filesystem Plugin
File and directory operations with path restrictions.
Tools:
read_file- Read file contentswrite_file- Write to fileslist_directory- List directory contentsfile_info- Get file metadatadelete_file- Delete files
Config Options:
{
"name": "read_file",
"enabled": true,
"allowedPaths": [".", "/tmp"], // Restrict access
"readonly": false // Make filesystem readonly
}Shell Plugin
Execute shell commands with whitelist/blacklist support.
Tools:
exec_command- Execute shell commands
Config Options:
{
"name": "exec_command",
"enabled": true,
"allowedCommands": ["ls", "pwd", "cat"], // Whitelist
"blockedCommands": ["rm", "sudo"], // Blacklist
"maxBuffer": 1048576 // 1MB output limit
}HTTP Plugin
Make HTTP requests with domain restrictions.
Tools:
http_get- GET requestshttp_post- POST requests
Config Options:
{
"name": "http_get",
"enabled": true,
"allowedDomains": ["api.github.com", "example.com"]
}Utils Plugin
Utility functions for common tasks.
Tools:
echo- Echo back input (testing)calculate- Safe math evaluationtimestamp- Get current timebase64_encode- Base64 encodingbase64_decode- Base64 decoding
Creating Custom Plugins
1. Create Plugin File
// plugins/my-plugin.js
export default {
// Optional initialization
async init(config) {
console.log('Plugin initialized:', config);
},
tools: {
my_tool: {
description: 'Description of what this tool does',
inputSchema: {
type: 'object',
properties: {
input: {
type: 'string',
description: 'Input parameter'
}
},
required: ['input']
},
async execute(args, config) {
// args = input parameters
// config = tool-specific config from config.json
return `Result: ${args.input}`;
}
}
}
};2. Add to Config
{
"plugins": [
{
"name": "my-plugin",
"type": "builtin",
"module": "my-plugin",
"enabled": true,
"tools": [
{
"name": "my_tool",
"enabled": true,
"customOption": "value"
}
]
}
]
}3. Restart Server
That's it! Your tool is now available.
External Plugins
Load plugins from outside the project:
{
"plugins": [
{
"name": "external-plugin",
"type": "external",
"module": "/absolute/path/to/plugin.js",
"enabled": true,
"tools": [...]
}
]
}Security Features
Path Restrictions
{
"name": "read_file",
"allowedPaths": ["./data", "/tmp"] // Only these paths accessible
}Command Whitelisting
{
"name": "exec_command",
"allowedCommands": ["ls", "cat", "grep"] // Only these commands
}Domain Filtering
{
"name": "http_get",
"allowedDomains": ["trusted-api.com"] // Only these domains
}Read-Only Mode
{
"name": "write_file",
"readonly": true // Prevent writes
}Configuration Reference
Server Config
{
"server": {
"name": "server-name", // MCP server name
"version": "1.0.0" // Server version
}
}Plugin Config
{
"name": "plugin-name", // Unique plugin identifier
"type": "builtin", // "builtin" or "external"
"module": "plugin-file", // Plugin file/path
"enabled": true, // Enable/disable entire plugin
"required": false, // Fail if plugin can't load
"tools": [...] // Array of tool configs
}Tool Config
{
"name": "tool-name", // Tool identifier
"enabled": true, // Enable/disable this tool
// ... custom options passed to tool's execute()
}Examples
Example 1: Read-Only Filesystem
{
"plugins": [
{
"name": "filesystem",
"type": "builtin",
"module": "filesystem",
"enabled": true,
"tools": [
{
"name": "read_file",
"enabled": true,
"allowedPaths": ["/var/log"]
},
{
"name": "list_directory",
"enabled": true
}
]
}
]
}Example 2: Safe Shell Access
{
"plugins": [
{
"name": "shell",
"type": "builtin",
"module": "shell",
"enabled": true,
"tools": [
{
"name": "exec_command",
"enabled": true,
"allowedCommands": ["ls", "pwd", "cat", "grep", "find"],
"blockedCommands": ["rm", "sudo", "su"],
"maxBuffer": 1048576
}
]
}
]
}Example 3: HTTP API Client
{
"plugins": [
{
"name": "http",
"type": "builtin",
"module": "http",
"enabled": true,
"tools": [
{
"name": "http_get",
"enabled": true,
"allowedDomains": [
"api.github.com",
"httpbin.org"
]
}
]
}
]
}Testing
Using MCP Inspector
# Install MCP Inspector
npm install -g @modelcontextprotocol/inspector
# Test your server
mcp-inspector node server.jsManual Testing
Send JSON-RPC requests via stdin:
# Initialize
echo '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{}}' | node server.js
# List tools
echo '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}' | node server.js
# Call a tool
echo '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"echo","arguments":{"message":"Hello!"}}}' | node server.jsLogging
Control log level via environment variable:
# Debug mode
LOG_LEVEL=DEBUG node server.js
# Quiet mode
LOG_LEVEL=ERROR node server.jsLog levels: ERROR, WARN, INFO (default), DEBUG
Architecture
┌─────────────────────────────────────┐
│ MCP Client (Claude) │
└─────────────┬───────────────────────┘
│ JSON-RPC over stdio
┌─────────────▼───────────────────────┐
│ core/mcp-protocol.js │
│ (JSON-RPC handler, stdio I/O) │
└─────────────┬───────────────────────┘
│
┌─────────────▼───────────────────────┐
│ core/plugin-manager.js │
│ (Loads plugins from config.json) │
└─────────────┬───────────────────────┘
│
┌───────┴───────┬─────────────┐
│ │ │
┌─────▼─────┐ ┌──────▼──────┐ ┌──▼────┐
│filesystem │ │ shell │ │ http │
│ plugin │ │ plugin │ │ plugin│
└───────────┘ └─────────────┘ └───────┘Files
.
├── server.js # Entry point
├── config.json # Your configuration
├── config.example.json # Example config
├── package.json # Project metadata
├── core/
│ ├── mcp-protocol.js # MCP/JSON-RPC implementation
│ ├── plugin-manager.js # Plugin loader
│ └── logger.js # Logging utility
├── plugins/
│ ├── filesystem.js # File operations
│ ├── shell.js # Shell commands
│ ├── http.js # HTTP requests
│ └── utils.js # Utilities
└── README.md # This fileFAQ
Q: How do I add a new tool?
A: Edit config.json and add the tool to a plugin's tools array. Restart the server.
Q: Can I create my own plugins?
A: Yes! Create a .js file in plugins/ following the plugin structure, then reference it in config.json.
Q: How do I restrict file access?
A: Use the allowedPaths option in the filesystem tool config.
Q: Is this secure?
A: It has built-in security features (path restrictions, command whitelisting, etc.), but treat it like any tool that executes code - configure it carefully and run with appropriate permissions.
Q: Can I use this in production?
A: Yes, but review the security settings carefully. Consider running in a container or with restricted user permissions.
License
MIT
Contributing
Contributions welcome! The codebase is intentionally simple and zero-dependency to keep it maintainable.
Available Tools
3 toolscalculateB
Perform a mathematical calculation (safe eval)
| Name | Required | Description | Default |
|---|---|---|---|
| expression | Yes | Mathematical expression to evaluate (e.g., "2 + 2 * 3") |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions 'safe eval' which hints at security considerations, but doesn't elaborate on what makes it safe, potential limitations, error handling, or performance characteristics. It adequately indicates this is a computational operation but lacks depth about behavioral traits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise at just 4 words plus a parenthetical. Every element earns its place: 'perform' establishes action, 'mathematical calculation' specifies domain, and '(safe eval)' adds important behavioral context. It's front-loaded with the core purpose and wastes no words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a single-parameter tool with 100% schema coverage but no annotations and no output schema, the description is minimally adequate. It covers the basic purpose and hints at safety, but doesn't explain what the tool returns, error conditions, or mathematical capabilities. Given the simplicity of the tool, it's complete enough for basic understanding but lacks depth for robust agent usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 100%, so the schema already fully documents the single 'expression' parameter. The description adds minimal value beyond what the schema provides - it reinforces that this is for mathematical calculations but doesn't add syntax details, format constraints, or examples beyond the schema's example. This meets the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with a specific verb ('perform') and resource ('mathematical calculation'), and the parenthetical 'safe eval' adds useful context. It distinguishes well from sibling tools like 'echo' and 'timestamp' by focusing on mathematical operations. However, it doesn't explicitly differentiate from potential mathematical siblings that might exist in other contexts.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention any prerequisites, limitations, or scenarios where other tools might be more appropriate. While the sibling tools are unrelated (echo, timestamp), the description offers no explicit usage context or exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
echoA
Echo back the input (useful for testing)
| Name | Required | Description | Default |
|---|---|---|---|
| message | Yes | Message to echo back |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It discloses the core behavior ('echo back the input'), but doesn't mention any side effects, error conditions, or response format. It's adequate but lacks depth for a tool with no annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise with just two phrases, front-loaded with the core purpose and followed by a brief usage hint. Every word earns its place with zero waste, making it highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (one parameter, no annotations, no output schema), the description is reasonably complete. It explains what the tool does and hints at usage, though it could benefit from more behavioral context (e.g., response format) to reach a 5.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 100%, so the schema already fully documents the single parameter. The description doesn't add any meaning beyond what the schema provides (e.g., it doesn't explain format constraints or examples), meeting the baseline for high coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with a specific verb ('echo back') and resource ('the input'), making it immediately understandable. However, it doesn't differentiate from sibling tools like 'calculate' or 'timestamp', which would require a 5.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides implied usage guidance by stating it's 'useful for testing', which suggests when to use it. However, it lacks explicit guidance on when to choose this tool over alternatives like 'calculate' or 'timestamp', or any exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
timestampB
Get current timestamp
| Name | Required | Description | Default |
|---|---|---|---|
| format | No | Format: "iso" (default), "unix", or "human" |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states what the tool does ('Get current timestamp') but doesn't mention any behavioral traits such as whether it's read-only, has side effects, requires authentication, or has rate limits. This leaves significant gaps in understanding how the tool behaves beyond its basic function.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise ('Get current timestamp'), consisting of just three words that directly convey the core function. It's front-loaded with no unnecessary details, making it efficient and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's low complexity (one optional parameter) and high schema coverage, the description is somewhat complete for basic use. However, with no output schema and no annotations, it lacks details on return values and behavioral context, which could be important for an agent to use it correctly in varied scenarios.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, documenting the 'format' parameter with its options and default. The description doesn't add any meaning beyond this, as it doesn't mention parameters at all. According to the rules, with high schema coverage, the baseline score is 3, which is appropriate here.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description 'Get current timestamp' clearly states the verb ('Get') and resource ('current timestamp'), making the purpose immediately understandable. However, it doesn't differentiate from sibling tools like 'calculate' or 'echo', which might also involve time-related operations or data retrieval.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like 'calculate' or 'echo'. It lacks context about specific scenarios or exclusions, leaving the agent to infer usage based on the tool name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
v1.0.0- First observed
calculate - First observed
echo - First observed
timestamp
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose with no overlap: calculate handles math operations, echo returns input for testing, and timestamp provides the current time. There is no ambiguity or confusion between these three functions.
All tool names follow a consistent pattern of using single, descriptive words (calculate, echo, timestamp) without mixing conventions like camelCase or snake_case. This uniformity makes the set predictable and easy to understand.
With only 3 tools, the server feels thin and limited in scope, potentially lacking coverage for broader utility needs. While each tool is distinct, the count is borderline low for a general-purpose utility server, suggesting it might be under-scoped.
The tools cover basic utility functions (math, testing, time), but there are notable gaps for a modular server, such as missing data transformation, file handling, or network operations. This limits the server's ability to handle more complex agent workflows effectively.
Maintenance
Related MCP Connectors
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
Personal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.
An MCP server that provides read access to your cloud storage providers, bank accounts and more.
A MCP server built for developers enabling Git based project management with project and personal…
Related MCP Servers
- FlicenseBqualityDmaintenanceProvides a complete end-to-end MCP server implementation with file system tools, web scraping capabilities, and system information access. Includes ready-to-use configuration files and integration examples for Claude Desktop, ChatGPT, and other AI models.6-
- FlicenseNot gradedqualityDmaintenanceA unified MCP server with composable tools for GitHub operations, file management, shell execution, kanban boards, Discord messaging, and package management. Features role-based security, HTTP/stdio transports, and a web-based development UI.-
- AlicenseNot gradedqualityDmaintenanceA modular MCP server providing file operations, web search, URL scraping, and sandboxed command execution for LLM interactions.1MIT
- FlicenseNot gradedqualityDmaintenanceA production-ready MCP server providing file, system, math, and text utilities through a simple CLI client.-