A battle-tested MCP server starter kit for TypeScript and Python. Built with strict SSRF guards, directory sandboxing, read-only SQLite, dual stdio + SSE transports, and 1-click client configs.
Production-Ready Dual Runtimes
Both implementations feature strict JSON-RPC schema contracts, transport abstraction (stdio + SSE), and zero unhandled errors.
Direct IPC pipes for desktop agents (zero open ports) • Containerized SSE for cloud services • Defensive sandbox guardrails
import { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
import { z } from 'zod';
import { assertSafeUrl } from './security/ssrf.js';
// 1. Initialize production server with graceful lifecycle
export const server = new McpServer({
name: 'bighub-mcp-production-server',
version: '1.0.0'
});
// 2. Register SSRF-hardened HTTP tool with strict input schema
server.tool(
'fetch_safe_url',
{ url: z.string().url().describe('Public HTTPS URL to retrieve') },
async ({ url }) => {
// Blocks private CIDRs (10.0.0.0/8, 127.0.0.0/8, AWS 169.254.169.254)
await assertSafeUrl(url);
const res = await fetch(url, { signal: AbortSignal.timeout(5000) });
return { content: [{ type: 'text', text: await res.text() }] };
}
);
// 3. Dual transport connection: stdio (desktop) or SSE (Docker/Cloud)
const transport = new StdioServerTransport();
await server.connect(transport);
from mcp.server.fastmcp import FastMCP
from pydantic import BaseModel, Field
from src.security.ssrf import validate_safe_url
import httpx
# 1. Initialize production server with async native transport
mcp = FastMCP(
"bighub-mcp-production-server",
dependencies=["pydantic", "httpx"]
)
# 2. Register SSRF-hardened HTTP tool with Pydantic validation
@mcp.tool()
async def fetch_safe_url(
url: str = Field(..., description="Public HTTPS URL to retrieve")
) -> str:
"""Safely fetch public web data, rejecting internal/private IP targets."""
await validate_safe_url(url)
async with httpx.AsyncClient(timeout=5.0) as client:
response = await client.get(url)
return response.text
# 3. Boot with unbuffered stdio or SSE transport
if __name__ == "__main__":
mcp.run(transport="stdio")
Select your agent or IDE and transport mode to inspect and copy production configs.
%APPDATA%\Claude\claude_desktop_config.json
3 Core Tools with Built-In Safety Boundaries
Most tutorial MCP servers grant LLMs unrestricted local access. This toolkit includes real-world guardrails out of the box so you can deploy with confidence.
Parameterized SQL execution with automatic AST-level read-only enforcement. Rejects DROP, DELETE, or mutating commands automatically.
Protects your infrastructure against LLM prompt-injection attacks. Intercepts DNS resolution and blocks private RFC 1918 subnets, cloud metadata IPs, and loopbacks.
Strict directory confinement preventing path traversal exploits (../../etc/passwd). Resolves canonical symlinks and verifies boundary roots.
Skip the Plumbing, Ship Your Tools
What's Inside the 98.5 KB Package
Type-safe, self-contained, and ready to deploy. No hidden telemetry or proprietary lock-in.
Zero bloated binaries, compiled sources ready for instant execution.
Automated download link delivered immediately on checkout screen & sent to your email.
Frequently Asked Questions
Claude Desktop, Cursor IDE, Google Antigravity, Windsurf, Roo-Code / Cline, and any other client adhering to the Anthropic Model Context Protocol specification v1.0+. Pre-configured JSON configuration files are included for all major tools.
No! Both TypeScript and Python runtimes can be executed natively on your host machine via Node.js (pnpm dev or node dist/index.js) and Python (python main.py). Docker and compose.yaml are optional, provided for containerized and cloud deployments.
Yes! The entire kit is licensed under the permissive MIT License. You have complete rights to use, modify, brand, and deploy it inside your commercial, open-source, or proprietary products.
If this kit doesn't save you hours of boilerplate setup time within your first week, simply reply to your receipt email within 14 days and we will issue a 100% full refund immediately. No friction, no questions asked.
Get instant access to the complete dual-runtime production MCP suite with pre-built security tools, client configs, and Docker orchestration.
⚡ Unlock Instant Download $3.00One-time payment • Lifetime updates • Instant .zip download
Dual TypeScript + Python, stdio + SSE, Tools & Configs