Security-Hardened MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Security-Hardened MCP Servergenerate a UUID"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Security-Hardened MCP Server
A TypeScript Model Context Protocol server built to be defensible in an interview:
every security control is backed by an adversarial test or a committed artifact, or
it is listed as an open finding. Built on the official @modelcontextprotocol/sdk
(Streamable HTTP + stdio), Express 5, and Zod.
Status: M1 (schema validation) — strict input rejection and output validation are proven (T05 CLOSED): every registered tool's
inputSchemais a.strict()Zod object fed directly to the SDK, so unknown/extra keys, wrong types, and out-of-range values are rejected against the raw JSON-RPC arguments, and output is strict-validated before it leaves the server. Authentication, scopes, rate limiting, and the remaining eight tools are still open — all other threat-model rows remain OPEN.
Architecture
requestId → originCheck → bodyLimit → auth → httpRateLimit → concurrencyCap
→ StreamableHTTPServerTransport → McpServer dispatch
→ withGuards: authz → rate limit → arg cap → timeout
→ output validate → sanitize → audit(As of M1, withGuards steps 4/6/7/9 — arg byte cap, output validate, sanitize, and
structured error mapping — are live. The Express-layer middleware chain above
McpServer dispatch is still ordered stubs beyond requestId and body parsing.)
Related MCP server: MCP Server TypeScript
Tools (12 planned)
Tool | Scope | Demonstrates | Status |
|
| connectivity / baseline | Implemented |
|
| — | Implemented |
|
| — | Implemented |
|
| — | Implemented |
|
| hostile-schema handling (schema-of-death) | Implemented |
|
| — | Not yet implemented |
|
| — | Not yet implemented |
|
| SSRF defense (T06/T07) | Not yet implemented |
|
| AST sandbox (T09) | Not yet implemented |
|
| — | Not yet implemented |
|
| ReDoS defense (T08) | Not yet implemented |
|
| per-principal isolation (T10) | Not yet implemented |
Threat model
See docs/THREAT-MODEL.md. T05 is CLOSED as of M1; all other rows remain OPEN.
How to run
Prerequisites: Node 22 (nvm use), Docker.
npm ci
# HTTP (Streamable HTTP on :3000)
MODE=http PORT=3000 npm run dev
curl -s localhost:3000/healthz # -> {"status":"ok"}
# stdio (JSON-RPC over stdin/stdout; logs go to stderr)
npm run build
MODE=stdio node dist/index.js
# Docker
docker build -t security-hardened-mcp-server:latest .
docker run --rm -e MODE=http -p 3000:3000 security-hardened-mcp-server:latest
# or: docker compose up --buildInspect with MCP Inspector:
# HTTP: run the server, then open the Inspector and connect Streamable HTTP to
# http://localhost:3000/mcp
npx @modelcontextprotocol/inspector
# stdio: Inspector launches the server itself
MODE=stdio npx @modelcontextprotocol/inspector node dist/index.jsKnown limitations (M1)
Still no authentication, no scopes, no rate limiting —
withGuardssteps 1–3 areTODO(M2)/TODO(M3); per-tool authorization (scope enforcement) lands in M2.The per-tool arg byte-cap control (
withGuardsstep 4) exists and is unit-tested, but its dedicated adversarial proof, T04, lands in M3.5 of 12 tools implemented (
echo,get_time,hash_text,uuid_generate,json_validate); the remaining seven, and threat-model rows T06–T15, land in M2–M4.Not deployed; single-host only.
M1 Claim Audit
Resume phrase | Artifact | Verdict |
"12 authenticated tools" | 5 of 12 tools exist ( | NOT YET |
"schema validation" | Strict input rejection is genuine and server-side: | PROVEN |
"rate limiting" | none yet (M3); | NOT YET |
"load-tested to 50+ concurrent" | none yet (M5) | NOT YET |
"Schema validation" is now the one PROVEN phrase; the other three remain NOT YET as scoped. The per-tool arg byte-cap control (step 4) is implemented and unit-tested but its full adversarial proof is T04 (M3), so it is not yet claimed as an independently-proven line.
This server cannot be deployed
Maintenance
Related MCP Connectors
MCP server for progressive tool usage at any scale (see https://klavis.ai)
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
Self-hosted MCP server: 26 deterministic dev, security, and EVM tools.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
Related MCP Servers
- AlicenseBqualityDmaintenanceA simple TypeScript MCP server that provides two tools: one for greeting users with a customizable name and another for adding two numbers together.26 npmMIT
- -licenseNot gradedqualityNot gradedmaintenanceA production-ready TypeScript MCP server providing basic tools (add, echo, timestamp), resources (server info, greetings, data access), and prompt templates (analyze, code-review, summarize). Serves as a foundation for building custom MCP servers with extensible architecture.205 npm-
- FlicenseNot gradedqualityDmaintenanceA boilerplate project for quickly developing MCP servers using TypeScript, featuring example implementations of tools (calculator, greetings) and resources (server info) with Zod schema validation.-
- FlicenseNot gradedqualityDmaintenanceAn extensible TypeScript-based MCP server designed for Claude Code with a modular architecture for easily adding custom tools. It includes built-in examples like a calculator and echo tool, utilizing Zod for robust input validation and error handling.25 npm-