mcp-kit — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by my-mcp-hub · MCP Server · ★ 97

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-kit safe to install? View the security audit →

About mcp-kit

Create-MCP-Kit A CLI tool to create MCP (Model Context Protocol) applications with ease. [![][npm-release-shield]][npm-release-link] [![][codecov-shield]][codecov-link] [![][github-release-date-shield]][github-release-date-link] [![][github-action-build-shield]][github-action-build-link] [![][github-license-shield]][github-license-link] Features 🚀 Quick project scaffolding 📦 TypeScript support out of the box 🛠️ Built-in development tools 🔧 Configurable project templates 🌐 Multiple Transport Modes (stdio/streamable-http/sse) 📚 Comprehensive APIs Usage or or Project Types create-mcp-kit supports generating two types of projects: MCP Server Create an MCP server that provides tools, resources, and prompts for MCP clients.

clijavascriptmcpmcp-climcp-clientmcp-kitmcp-servermodel-context-protocolnodejsproject-generator

Quick Facts

Stars97
Forks3
LanguageHandlebars
CategoryMCP Server
LicenseMIT
Quality Score68.0299043149684/100
Open Issues8
Last Updated2026-09-23
Created2025-07-16
Platformscli, mcp
Est. Tokens~18k

Compatible Skills

These tools work well together with mcp-kit for enhanced workflows:

  • soloncode — semantic(0.25)+complementary+rare_topics+similar_pop+shared_platform (48%)
  • agentpipe — semantic(0.18)+complementary+rare_topics+similar_pop+shared_platform (46%)
  • director — semantic(0.60)+rare_topics+similar_pop+shared_platform (45%)
  • gob — semantic(0.16)+complementary+rare_topics+similar_pop+shared_platform (45%)

mcp-kit alternative? Top 6 similar tools

Looking for a mcp-kit alternative? If you're comparing mcp-kit with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcptoon by activeing123 · ⭐ 207

    One zero-dependency CLI for every MCP server and agent skill. Token optimization, tool discovery and context c

  • mcp-google-map by cablate · ⭐ 466

    18 Google Maps tools and 3 Agent Skills for place search, routes, travel planning, and local SEO—via MCP or st

  • mesh by decocms · ⭐ 337

    One secure endpoint for every MCP server. Deploy anywhere.

  • vurb.ts by vinkius-labs · ⭐ 251

    TypeScript framework for building production MCP servers. Fluent tool API, FSM gating, presenters, semantic ro

  • easy-mcp by zcaceres · ⭐ 196

    Absurdly easy Model Context Protocol Servers in Typescript

  • claude-prompts by minipuft · ⭐ 182

    MCP server for reusable prompt templates, multi-step workflow chains, and quality gates — compose agentic work

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Frequently Asked Questions

What is mcp-kit?

mcp-kit is An interactive CLI for scaffolding ready-to-develop MCP servers and clients in TypeScript or JavaScript.. It is categorized as a MCP Server with 97 GitHub stars.

What programming language is mcp-kit written in?

mcp-kit is primarily written in Handlebars. It covers topics such as cli, javascript, mcp.

How do I install or use mcp-kit?

You can find installation instructions and usage details in the mcp-kit GitHub repository at github.com/my-mcp-hub/mcp-kit. The project has 97 stars and 3 forks, indicating an active community.

What license does mcp-kit use?

mcp-kit is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to mcp-kit?

The top alternatives to mcp-kit on Agent Skills Hub include mcptoon, mcp-google-map, mesh. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools