PlugMyPlugin
← Browse

mcp-server-smith

sigistry ★ 3

MCP Server Smith scaffolds, audits, and hardens Model Context Protocol servers against the MCP 2026-07-28 spec, catching security risks like confused-deputy and prompt-injection through static file analysis without running any server. It includes commands to audit existing servers, scaffold new ones on stateless Streamable HTTP transport, and migrate servers off the deprecated HTTP+SSE transport while ensuring OAuth 2.1/OIDC compliance.

DevOps Security No API key detected runs shell

Install

> /plugin marketplace add sigistry/marketplace/tree/HEAD/plugins/mcp-server-smith
> /plugin install mcp-server-smith

Source: https://github.com/sigistry/marketplace/tree/HEAD/plugins/mcp-server-smith

What it's made of

3 commands · 2 agents · 4 skills · 1 hook

Commands
3
Agents
2
Skills
4
MCP servers
0
Hooks
1 · PostToolUse

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
node
Talks to
nothing external detected

Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (sigistry).