mcp-golang — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by metoro-io · MCP Server · ★ 1.2k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-golang safe to install? View the security audit →

About mcp-golang

mcp-golang mcp-golang is an unofficial implementation of the Model Context Protocol in Go. Write MCP servers and clients in golang with a few lines of code. Docs at https://mcpgolang.com Highlights 🛡️Type safety - Define your tool arguments as native go structs, have mcp-golang handle the rest. Automatic schema generati

Quick Facts

Stars1,231
Forks120
LanguageGo
CategoryMCP Server
LicenseMIT
Quality Score67.5185764326002/100
Open Issues45
Last Updated2026-02-25
Created2024-12-07
Platformsgo, mcp
Est. Tokens~76k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is mcp-golang?

mcp-golang is Write Model Context Protocol servers in few lines of go code. Docs at https://mcpgolang.com . Created by https://metoro.io. It is categorized as a MCP Server with 1.2k GitHub stars.

What programming language is mcp-golang written in?

mcp-golang is primarily written in Go.

How do I install or use mcp-golang?

You can find installation instructions and usage details in the mcp-golang GitHub repository at github.com/metoro-io/mcp-golang. The project has 1.2k stars and 120 forks, indicating an active community.

What license does mcp-golang use?

mcp-golang is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools