No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by ivo-toby · MCP Server · ★ 294
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp-openapi-server safe to install? View the security audit →
OpenAPI MCP Server A Model Context Protocol (MCP) server that exposes OpenAPI endpoints as MCP tools, along with optional support for MCP prompts and resources. This server allows Large Language Models to discover and interact with REST APIs defined by OpenAPI specifications through the MCP protocol. 📖 Documentation User Guide - For users wanting to use this MCP server with Claude Desktop, Cursor, or other MCP clients Library Usage - For developers creating custom MCP servers using this package as a library Developer Guide - For contributors and developers working on the codebase AuthProvider Guide - Detailed authentication patterns and examples User Guide This section covers how to use the MCP server as an end user with Claude Desktop, Cursor, or other MCP-compatible tools. Overview This MCP server can be used in two ways: CLI Tool: Use directly with command-line arguments for quick setup Library: Import and use the class in your own Node.js applications for custom implementations The server supports two transport methods: Stdio Transport (default): For direct integration with AI systems like Claude Desktop that manage MCP connecti
| Stars | 294 |
| Forks | 61 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 74.959625212859/100 |
| Open Issues | 8 |
| Last Updated | 2026-06-15 |
| Created | 2024-12-05 |
| Platforms | mcp, node |
| Est. Tokens | ~22k |
These tools work well together with mcp-openapi-server for enhanced workflows:
Explore other popular mcp server tools:
mcp-openapi-server is MCP Server (Model Context Protocol) for turning OpenAPI specifications into a MCP Resource. It is categorized as a MCP Server with 294 GitHub stars.
mcp-openapi-server is primarily written in TypeScript.
You can find installation instructions and usage details in the mcp-openapi-server GitHub repository at github.com/ivo-toby/mcp-openapi-server. The project has 294 stars and 61 forks, indicating an active community.
mcp-openapi-server is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: