js — security grade SAFE, quality 61/100

Security audit verdict: SAFE · quality 61/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by mcp-auth · MCP Server · ★ 51

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is js safe to install? View the security audit →

About js

MCP Auth Node.js SDK The MCP spec requires OAuth 2.1 and other RFCs for auth. Instead of spending weeks on them, use MCP Auth to connect to a trusted provider with a few lines of code. mcp-auth targets the latest MCP specification and the MCP TypeScript SDK v2, implementing the spec's authorization requirements — RFC 9728 Protected Resource Metadata and RFC 8707 audience-bound token validation — for any OAuth 2.0 / OpenID Connect provider. Get started Is my provider supported? Check out the MCP-compatible providers to see which providers are supported. It also includes a tool for real-time checking of provider compatibility. Installation Or use your package manager of choice, such as or . Still on MCP SDK v1 (@model

authenticationauthorizationmcpmcp-servermodelcontextprotocolnodejsoauth2oidctypescript

Quick Facts

Stars51
Forks4
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score61.015837070893/100
Last Updated2026-08-31
Created2025-04-19
Platformsmcp, node
Est. Tokens~14k

Compatible Skills

These tools work well together with js for enhanced workflows:

  • QuantClaw-plugin — semantic(0.22)+complementary+same_lang+similar_pop+shared_platform (58%)
  • LLMOne — semantic(0.21)+complementary+same_lang+similar_pop+shared_platform (57%)

js alternative? Top 6 similar tools

Looking for a js alternative? If you're comparing js with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • server-google-news by ChanMeng666 · ⭐ 129

    【Star-crossed coders unite!⭐️】Model Context Protocol (MCP) server implementation providing Google News search

  • jetski by hyprmcp · ⭐ 212

    Authentication, analytics, and prompt visibility for MCP servers with zero code changes. Supports OAuth2.1, DC

  • easy-mcp by zcaceres · ⭐ 196

    Absurdly easy Model Context Protocol Servers in Typescript

  • claude-prompts by minipuft · ⭐ 182

    MCP server for reusable prompt templates, multi-step workflow chains, and quality gates — compose agentic work

  • claude-historian-mcp by Vvkmnn · ⭐ 178

    📜 An MCP server for conversation history search and retrieval in Claude Code

  • mcp-auth-proxy by sigbit · ⭐ 174

    MCP Auth Proxy is a secure OAuth 2.1 authentication proxy for Model Context Protocol (MCP) servers

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is js?

js is 🔐 Plug-and-play auth for Node.js MCP servers.. It is categorized as a MCP Server with 51 GitHub stars.

What programming language is js written in?

js is primarily written in TypeScript. It covers topics such as authentication, authorization, mcp.

How do I install or use js?

You can find installation instructions and usage details in the js GitHub repository at github.com/mcp-auth/js. The project has 51 stars and 4 forks, indicating an active community.

What license does js use?

js is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to js?

The top alternatives to js on Agent Skills Hub include server-google-news, jetski, easy-mcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools