mcp-review
Verified Safeby ggange
Overview
An open-source platform for discovering, rating, and reviewing MCP (Model Context Protocol) servers, empowering developers to share experiences and make informed decisions.
Installation
npm run devEnvironment Variables
- DATABASE_URL
- NEXTAUTH_SECRET
- NEXTAUTH_URL
- GITHUB_ID
- GITHUB_SECRET
- CRON_SECRET
- NEXT_PUBLIC_APP_URL
- R2_ACCOUNT_ID
- R2_ACCESS_KEY_ID
- R2_SECRET_ACCESS_KEY
- R2_BUCKET_NAME
- REDIS_URL
Security Notes
The project demonstrates strong security practices including robust input validation (Zod with custom sanitization for text), CSRF protection for mutation endpoints, and distributed rate limiting for all API endpoints to prevent abuse and DoS attacks. Authentication is handled by NextAuth.js, and authorization checks are in place for sensitive actions (e.g., admin access, server ownership). Secrets are managed via environment variables and Cloudflare R2 is used for secure icon storage with a proxy endpoint that includes basic path traversal prevention. The cron job endpoint uses a timing-safe secret comparison. Prisma ORM helps prevent SQL injection. Overall, a highly security-conscious implementation.
Similar Servers
awesome-mcp-servers
This repository serves as a curated list of Model Context Protocol (MCP) servers, frameworks, and utilities, providing a comprehensive directory for developers and AI practitioners.
awesome-remote-mcp-servers
A curated directory for developers to discover, evaluate, and integrate high-quality, official remote Model Context Protocol (MCP) servers into their AI applications and LLM clients.
awesome-devops-mcp-servers
A curated list of Model Context Protocol (MCP) servers focused on DevOps tools and capabilities, enabling AI models to discover and interact with various local and remote resources.
awesome-mcp-servers
A comprehensive collection of Model Context Protocol (MCP) servers, standardizing AI application context provision.