Super Secret MCP Server
超级秘密 MCP 服务器
纯 Node.js 中的模型上下文协议 (MCP) 服务器实现,提供了一个有趣的工具来生成随机的美国州和签名汤组合。
特征
纯 Node.js 实现
符合 JSON-RPC 2.0 标准
MCP协议版本:2024-11-05
自定义日志系统
具有模式验证的工具支持
STDIO传输
Related MCP server: Vercel MCP Python Server
入门
先决条件
Node.js(推荐使用最新 LTS 版本)
MCP 检查器用于测试
安装
克隆存储库:
git clone git@github.com:gbti-network/mcp-basic-test.git
cd mcp-basic-test安装依赖项:
npm install运行检查器
使用 MCP Inspector 启动服务器:
npx @modelcontextprotocol/inspector -- node index.js服务器将启动并可通过 STDIO 进行连接。
可用工具
获取秘密密码
返回美国各州及其招牌汤的随机组合。示例包括:
新英格兰蛤蜊浓汤
路易斯安那秋葵浓汤
德克萨斯辣椒
加州海鲜汤
密歇根樱桃汤
输入模式:
{
"type": "object",
"properties": {},
"additionalProperties": false,
"required": []
}响应示例:
{
"content": [{
"type": "text",
"text": "New England Clam Chowder"
}]
}项目结构
.
├── index.js # Main server implementation
├── utils/
│ └── logger.js # Custom logging utility
├── .data/
│ ├── framework.md # Framework documentation
│ └── knowledge.md # Project knowledge base
└── .logs/ # Server logs directory发展
添加新工具
在
index.js中定义您的工具:
this.tools.set('toolName', {
name: 'toolName',
description: 'Tool description',
inputSchema: {
type: 'object',
properties: {},
additionalProperties: false,
required: []
},
handler: async (params) => {
// Tool implementation
return 'result';
}
});使用 MCP Inspector 进行测试:
连接到服务器
使用“列出工具”来验证工具注册
测试工具执行
日志记录
服务器使用具有多个级别的自定义日志系统:
DEBUG:详细的调试信息
信息:一般操作信息
WARN:警告信息
错误:错误条件
日志存储在.logs目录中。
与 Cascade 一起使用
选项 1:直接使用工具
当 MCP 服务器在 Cascade 中加载时,您可以直接使用getSecretPassphrase工具生成 state-soup 组合。
选项 2:自然语言界面
为了使该工具更加用户友好,您可以设置 Cascade 来响应有关密码的自然语言查询。以下是示例提示:
When users ask variations of "What is the secret passcode?", use the getSecretPassphrase tool to generate and return a US State + Soup combination as "Today's secret passcode is: [STATE] [SOUP]"这将允许用户使用自然问题获取密码,例如:
“密码是什么?”
“告诉我密码”
“今天的密码是多少?”
“告诉我秘密”
交互示例:
User: "What's the secret passcode?"
Cascade: "Today's secret passcode is: Louisiana Gumbo 🍜"选项 3:持久内存
对于更永久的设置,您可以创建一个跨会话持续存在的 Cascade 内存:
{
"Title": "Secret Passcode Handler",
"Content": "When the user asks any variation of 'What is the secret passcode?', use the getSecretPassphrase tool and return its result as 'Today's secret passcode is: [STATE] [SOUP]'",
"Tags": ["mcp_server", "secret_passcode", "tool_execution"]
}MCP 配置
要在 Cascade 中配置 MCP 服务器,请将以下内容添加到mcp_config.json中:
{
"mcpServers": {
"super-secret": {
"command": "npx",
"args": [
"--yes",
"node",
"<path-to-project>/index.js"
],
"disabled": false,
"autoApprove": [
"getSecretPassphrase"
]
}
}
}配置选项:
super-secret:您的 MCP 服务器的唯一标识符command:启动服务器的命令(在本例中为 npx)args:命令行参数--yes:自动批准 npm 包安装node:使用 Node.js 运行<path-to-project>/index.js:服务器文件的路径
disabled:服务器是否被禁用autoApprove:无需用户确认即可运行的工具列表
配置文件应放置在:
Windows:
%USERPROFILE%\.codeium\windsurf\mcp_config.jsonmacOS/Linux:
$HOME/.codeium/windsurf/mcp_config.json
测试
使用 MCP Inspector 启动服务器
验证服务器初始化
检查工具列表
测试工具执行
验证响应格式
贡献
分叉存储库
创建你的功能分支
提交你的更改
推送到分支
创建拉取请求
执照
该项目根据 MIT 许可证获得许可 - 有关详细信息,请参阅 LICENSE 文件。
致谢
模型上下文协议团队负责协议规范
MCP Inspector 测试工具团队
保持联系
在您最喜欢的平台上关注我们,了解最新动态、新闻和社区讨论:
Available Tools
1 toolgetSecretPassphraseD
Whats the password?
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description provides no behavioral information beyond the implied retrieval action. With no annotations provided, the description carries the full burden of behavioral disclosure but fails to mention anything about authentication requirements, rate limits, side effects, error conditions, or what format the password is returned in. It doesn't even clarify if this retrieves a specific password or prompts for one.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
While technically concise with just three words, this is under-specification rather than effective conciseness. The description doesn't earn its place - it provides almost no useful information. Good conciseness balances brevity with information density, which this description completely fails to achieve.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool that presumably retrieves sensitive authentication information, the description is completely inadequate. With no annotations, no output schema, and a tool name suggesting security implications, the description should provide critical context about what's being retrieved, security considerations, and usage constraints. Instead, it offers virtually no useful information.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has 0 parameters with 100% schema description coverage (empty schema), so there are no parameters to document. The description doesn't need to compensate for any parameter documentation gaps. The baseline for zero parameters is 4, as there's nothing for the description to add regarding parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description 'Whats the password?' is a tautology that essentially restates the tool name 'getSecretPassphrase' in question form. It doesn't specify what resource or system this password belongs to, what format the password is in, or what the tool actually does beyond the obvious implication of retrieving something. While it implies retrieval of a password, it lacks specificity about what kind of password or from where.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool, what context it applies to, what prerequisites might be needed, or any alternatives. It's a simple question with no usage context whatsoever. With no sibling tools mentioned, there's no need to distinguish from alternatives, but the description still fails to provide any usage guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- First observed
getSecretPassphrase
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusion or overlap between tools. The tool's purpose is singular and clearly defined, so disambiguation is perfect.
A single tool inherently has perfect naming consistency, as there are no other tools to compare it against. The naming follows a clear verb_noun pattern (getSecretPassphrase).
One tool is too few for most server purposes, as it severely limits functionality and scope. This feels thin and incomplete, even for a simple server, unless it's intentionally minimalistic.
The server's purpose is unclear from the single tool, but a 'secret passphrase' domain would typically require more operations (e.g., set, update, list, delete). With only a get operation, the surface is severely incomplete and will likely cause agent failures.
Maintenance
Related MCP Connectors
A paid remote MCP for CLI tool MCP, built to return verdicts, receipts, usage logs, and audit-ready
An MCP server that provides congressional transcripts
Hosted MCP server to manage a restaurant menu from AI agents - 39 tools over the DuckHub API.
One MCP server exposing every tool in the Gumball portfolio.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceA beginner-friendly MCP-inspired JSON-RPC server built with Node.js, offering basic client-server interaction through an 'initialize' capabilities handshake and an 'echo' function.3MIT
- AlicenseNot gradedqualityDmaintenanceA serverless MCP server deployed on Vercel that provides basic utility tools including echo, time retrieval, arithmetic operations, and mock weather information. Includes an interactive client application for testing and demonstration purposes.MIT
- FlicenseNot gradedqualityDmaintenanceA modular MCP server that provides tools for looking up country and state information. Designed as a demonstration of building extensible MCP servers with custom tool modules.-
- FlicenseNot gradedqualityFmaintenanceA basic MCP server implementation using Node.js and TypeScript that bridges AI models with external tools and data sources via JSON-RPC.2-