⚡
MCP Production Suite
Model Context Protocol Standard • TypeScript & Python Dual Runtime

Connect AI Agents to Real Tools. Safely and in Production.

A battle-tested MCP server starter kit for TypeScript and Python. Built with strict SSRF guards, directory sandboxing, read-only SQLite, dual stdio + SSE transports, and 1-click client configs.

GitHub: Dekiman/mcp-production-starter v1.0.0 MCP 1.0 Spec Compliant ⚖️ MIT License
Tested With: ● Claude Desktop ● Cursor IDE ● Google Antigravity ● Windsurf & Roo-Code
Instant .ZIP Delivery 14-Day Money-Back Guarantee Permissive MIT License

Clean Protocol Architecture

Production-Ready Dual Runtimes

Both implementations feature strict JSON-RPC schema contracts, transport abstraction (stdio + SSE), and zero unhandled errors.

System Topology: Transport & Security Isolation

Direct IPC pipes for desktop agents (zero open ports) • Containerized SSE for cloud services • Defensive sandbox guardrails

stdio • SSE :3001/:3002
1. CLIENT RUNTIMES Claude Desktop Cursor IDE Google Antigravity Windsurf & Roo-Code 2. TRANSPORTS stdio (IPC) stdin / stdout pipes ● Zero network exposure SSE (HTTP) Server-Sent Events Ports :3001 & :3002 ● Docker & Cloud deploy 3. DUAL-RUNTIME CORE TypeScript Engine Node 24+ • ESM • Zod McpServer JSON-RPC SDK Python Engine Python 3.13+ • Pydantic FastMCP Async Native Strict Schema Contracts 4. DEFENSIVE SANDBOX 🗄️ SQLite Safe Query AST Read-Only Enforced 🛡️ SSRF-Protected HTTP CIDR: 10/8, 169.254, RFC1918 📂 Sandboxed File Tool Root Path Traversal Guard
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
import { z } from 'zod';
import { assertSafeUrl } from './security/ssrf.js';

// 1. Initialize production server with graceful lifecycle
export const server = new McpServer({
  name: 'bighub-mcp-production-server',
  version: '1.0.0'
});

// 2. Register SSRF-hardened HTTP tool with strict input schema
server.tool(
  'fetch_safe_url',
  { url: z.string().url().describe('Public HTTPS URL to retrieve') },
  async ({ url }) => {
    // Blocks private CIDRs (10.0.0.0/8, 127.0.0.0/8, AWS 169.254.169.254)
    await assertSafeUrl(url);
    const res = await fetch(url, { signal: AbortSignal.timeout(5000) });
    return { content: [{ type: 'text', text: await res.text() }] };
  }
);

// 3. Dual transport connection: stdio (desktop) or SSE (Docker/Cloud)
const transport = new StdioServerTransport();
await server.connect(transport);
⚡ Interactive Config Playground • 1-Click JSON Presets

Client Configuration Presets

Select your agent or IDE and transport mode to inspect and copy production configs.

Paste config into: %APPDATA%\Claude\claude_desktop_config.json

Defensive Architecture by Default

3 Core Tools with Built-In Safety Boundaries

Most tutorial MCP servers grant LLMs unrestricted local access. This toolkit includes real-world guardrails out of the box so you can deploy with confidence.

🗄️

SQLite Query Tool

Parameterized SQL execution with automatic AST-level read-only enforcement. Rejects DROP, DELETE, or mutating commands automatically.

Schema Validation: Zod & Pydantic Safe Read-Only
🛡️

SSRF-Protected HTTP Tool

Protects your infrastructure against LLM prompt-injection attacks. Intercepts DNS resolution and blocks private RFC 1918 subnets, cloud metadata IPs, and loopbacks.

CIDR Filter: 10/8, 172.16/12, 192.168/16 Zero Leak
📂

Sandboxed File Inspector

Strict directory confinement preventing path traversal exploits (../../etc/passwd). Resolves canonical symlinks and verifies boundary roots.

Boundary Confinement Engine Path-Safe

Architectural Comparison

Skip the Plumbing, Ship Your Tools

Feature / Capability
DIY From Scratch
Turnkey Suite ($3.00)
Setup & Boilerplate Overhead
~4 Hours of Plumbing
< 3 Minutes
Runtimes Supported
Usually 1 runtime
TypeScript + Python Dual
Transports Out of Box
stdio only
Dual: stdio + SSE (:3001)
SSRF & Path Traversal Defense
❌ None (Vulnerable)
✔ Enterprise CIDR Guard
Client Config Templates
Manual JSON debugging
Claude, Cursor & Antigravity
Container Packaging
Write Dockerfile manually
Multi-stage + compose.yaml
Time & Opportunity Cost
Half a day of debugging
$3.00 One-time

Everything in the Bundle

What's Inside the 98.5 KB Package

Type-safe, self-contained, and ready to deploy. No hidden telemetry or proprietary lock-in.

📦 mcp-production-toolkit-v1.0.0.zip
├── typescript/ (Node 24+, ESM, Zod)
├── src/tools/ (sqlite, safe-http, file-sandbox)
├── src/security/ (ssrf, path traversal)
├── src/index.ts (stdio) & src/sse.ts (HTTP)
└── Dockerfile & package.json
├── python/ (Python 3.13+, Async, Pydantic)
├── src/tools/ (async db, safe web, filesystem)
├── src/security/ (CIDR block, sandbox root)
├── src/main.py (stdio) & src/sse.py (Starlette)
└── Dockerfile & requirements.txt
├── configs/ (Claude, Cursor, Antigravity)
├── scripts/ (validate_environment.js & .py)
├── compose.yaml (multi-container orchestration)
└── QUICKSTART.md (3-minute setup + troubleshooting)
Bundle Size 98.5 KB (.zip)

Zero bloated binaries, compiled sources ready for instant execution.

Cryptographic SHA-256 Hash
31280d47fe4c4ffe91df9f8b378575668d70af42fb858a5a92b57e654e5ad45b
⚡

Instant Download Delivery

Automated download link delivered immediately on checkout screen & sent to your email.

Got Questions?

Frequently Asked Questions

Which AI clients and IDEs are supported? ↓

Claude Desktop, Cursor IDE, Google Antigravity, Windsurf, Roo-Code / Cline, and any other client adhering to the Anthropic Model Context Protocol specification v1.0+. Pre-configured JSON configuration files are included for all major tools.

Do I need Docker installed to use this? ↓

No! Both TypeScript and Python runtimes can be executed natively on your host machine via Node.js (pnpm dev or node dist/index.js) and Python (python main.py). Docker and compose.yaml are optional, provided for containerized and cloud deployments.

Can I use this for client work and commercial software? ↓

Yes! The entire kit is licensed under the permissive MIT License. You have complete rights to use, modify, brand, and deploy it inside your commercial, open-source, or proprietary products.

How does the 14-Day Money-Back Guarantee work? ↓

If this kit doesn't save you hours of boilerplate setup time within your first week, simply reply to your receipt email within 14 days and we will issue a 100% full refund immediately. No friction, no questions asked.

🛡️ 14-Day Money-Back Guarantee — Get Instant Access ($3.00 USD) →
Ready to deploy

Save 4 Hours Today for Just $3.00.

Get instant access to the complete dual-runtime production MCP suite with pre-built security tools, client configs, and Docker orchestration.

⚡ Unlock Instant Download $3.00

One-time payment • Lifetime updates • Instant .zip download

MCP Production Suite
Instant .zip Download
Get Access $3.00
Secure Checkout

Turnkey MCP Server Starter Kit

Dual TypeScript + Python, stdio + SSE, Tools & Configs

Total Due (One-Time)
mcp-production-toolkit-v1.0.0.zip
$3.00
🔒 256-Bit SSL Encrypted ⚡ Instant Download 🛡️ 14-Day Refund