Production middleware for MCP servers. Auto transport, content wrapping, health checks, graceful shutdown, auth, rate limiting, structured request logging. Wraps the official Model Context Protocol SDK.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"mcp-helmet": {
"args": [
"-y",
"mcp-helmet"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Production middleware for MCP servers. Auth, sessions, health checks, graceful shutdown, transport ergonomics. Composable middleware borrowed in spirit from Express's helmet.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'mcp-helmet' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
Checked mcp-helmet against OSV.dev.
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in ai-ml / devops
Persistent memory using a knowledge graph
MCP server for using the GitLab API
Privacy-first. MCP is the protocol for tool access. We're the virtualization layer for context.
An open-source AI agent that brings the power of Gemini directly into your terminal.
MCP Security Weekly
Get CVE alerts and security updates for Mcp Helmet and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.