modelcontextprotocol/typescript-sdk

MCPcommunity
modelcontextprotocolNOASSERTIONUpdated 3mo agoGitHub

The official TypeScript SDK for Model Context Protocol servers and clients

This is the branch which contains v2 of the SDK (currently in development, pre-alpha). We anticipate a stable v2 release in Q3 2026 along with the updated MCP spec. Until then, v1.x remains the recommended version for production use. v1.x will continue to receive bug fixes and security updates for at least 6 months after v2 ships to give people time to upgrade. For v1 documentation, see the V1…

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
13kGitHub stars
2kForks
3mo agoLast update
Package
Authormodelcontextprotocol
LicenseNOASSERTION
Sourcegithub
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: run `forge publish` from the repo to claim ownership
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface40 tools · 1 privileged
Security scan✓ CleanvHEAD · 3mo agoHow well does this scan work?
EvalsNone
IndexedJun 13, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 1 privileged
Statically extracted from the published packagevHEAD · 3mo ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

get-alertsNo description published

This tool published no description. Forge does not invent one.

get-forecastNo description published

This tool published no description. Forge does not invent one.

greetNo description published

This tool published no description. Forge does not invent one.

get-protocol-infoNo description published

This tool published no description. Forge does not invent one.

register_userNo description published

This tool published no description. Forge does not invent one.

create_eventNo description published

This tool published no description. Forge does not invent one.

update_shipping_addressNo description published

This tool published no description. Forge does not invent one.

payment-confirmNo description published

This tool published no description. Forge does not invent one.

third-party-authNo description published

This tool published no description. Forge does not invent one.

multi-greetNo description published

This tool published no description. Forge does not invent one.

get_weatherNo description published

This tool published no description. Forge does not invent one.

whoamiNo description published

This tool published no description. Forge does not invent one.

calculate-bmiNo description published

This tool published no description. Forge does not invent one.

list-filesNo description published

This tool published no description. Forge does not invent one.

fetch-dataNo description published

This tool published no description. Forge does not invent one.

delete-fileprivilegedNo description published

This tool published no description. Forge does not invent one.

process-filesNo description published

This tool published no description. Forge does not invent one.

summarizeNo description published

This tool published no description. Forge does not invent one.

collect-feedbackNo description published

This tool published no description. Forge does not invent one.

list-workspace-filesNo description published

This tool published no description. Forge does not invent one.

start-notification-streamNo description published

This tool published no description. Forge does not invent one.

collect-user-infoNo description published

This tool published no description. Forge does not invent one.

long-operationNo description published

This tool published no description. Forge does not invent one.

structured-toolNo description published

This tool published no description. Forge does not invent one.

v1-to-v2No description published

This tool published no description. Forge does not invent one.

pingNo description published

This tool published no description. Forge does not invent one.

test-with-failing-transformNo description published

This tool published no description. Forge does not invent one.

test-rollbackNo description published

This tool published no description. Forge does not invent one.

testNo description published

This tool published no description. Forge does not invent one.

echoNo description published

This tool published no description. Forge does not invent one.

main.rsNo description published

This tool published no description. Forge does not invent one.

lib.rsNo description published

This tool published no description. Forge does not invent one.

profileNo description published

This tool published no description. Forge does not invent one.

test-request-infoNo description published

This tool published no description. Forge does not invent one.

test-query-paramsNo description published

This tool published no description. Forge does not invent one.

close-stream-toolNo description published

This tool published no description. Forge does not invent one.

test-callback-toolNo description published

This tool published no description. Forge does not invent one.

test-old-version-toolNo description published

This tool published no description. Forge does not invent one.

test-no-callback-toolNo description published

This tool published no description. Forge does not invent one.

test-standalone-callback-toolNo description published

This tool published no description. Forge does not invent one.

0 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

This is the branch which contains v2 of the SDK (currently in development, pre-alpha). We anticipate a stable v2 release in Q3 2026 along with the updated MCP spec. Until then, v1.x remains the recommended version for production use. v1.x will continue to receive bug fixes and security updates for at least 6 months after v2 ships to give people time to upgrade. For v1 documentation, see the V1 API docs. For v2 API docs, see . We're temporarily restricting PRs to contributors only to manage…

Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.