mcp-server-smith
MCP Server Smith scaffolds, audits, and hardens Model Context Protocol servers against the MCP 2026-07-28 spec, catching security risks like confused-deputy and prompt-injection through static file analysis without running any server. It includes commands to audit existing servers, scaffold new ones on stateless Streamable HTTP transport, and migrate servers off the deprecated HTTP+SSE transport while ensuring OAuth 2.1/OIDC compliance.
Install
Source: https://github.com/sigistry/marketplace/tree/HEAD/plugins/mcp-server-smith
What it's made of
3 commands · 2 agents · 4 skills · 1 hook
- Commands
- 3
- Agents
- 2
- Skills
- 4
- MCP servers
- 0
- Hooks
- 1 · PostToolUse
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
node- Talks to
- nothing external detected
Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (sigistry).