Skip to main content
interlace
Plugin: mcp-sdk-security

eslint-plugin-mcp-sdk-security

MCP SDK security — tool-input validation and transport hygiene

AI-Optimized Security

Every rule includes CWE, OWASP, and CVSS metadata for AI assistants to provide precise, context-aware fixes.

Install

npm install -D eslint-plugin-mcp-sdk-security

Live from GitHub

This content is fetched directly from README.md on GitHub and cached for 1 hour.

Live README from GitHubfrom eslint-plugin-mcp-sdk-security/README.md, cached for 1 hour.Edit on GitHub

⭐ If this plugin caught a real bug for you, star the repo — it's the signal that keeps these rules maintained.

Description

Security rules for code built on @modelcontextprotocol/sdk.

Scope: this plugin lints the MCP SDK's API shapesregisterTool, transports, handler signatures. It does not inspect MCP wire traffic, which isn't visible from source. Every rule gates on the SDK actually being imported, so it stays silent in files that don't use MCP.

  • Why — a linter nobody reads protects nothing. We would rather miss a finding than spend your attention on one that was never real.
  • How — evidence, not names. A rule fires on what the code does, resolved through the AST and ESLint's own scope analysis.
  • What — every finding carries its fix, in prose for a human and as structured JSON for an agent. Security rules add a CWE mapping and, where assigned, a CVSS score.

That trade costs recall, and we measure it: methodology · results · a false positive is a bug.

Getting Started

npm install eslint-plugin-mcp-sdk-security --save-dev

⚙️ Configuration Presets

PresetDescription
recommendedEnables every rule at error.
strictSame set as recommended; reserved for rules that are not yet safe by default.
minimalSame set as recommended; reserved for a reduced high-signal subset.

Usage

// eslint.config.js
import mcpSdkSecurity from 'eslint-plugin-mcp-sdk-security';

export default [
  mcpSdkSecurity.configs.recommended,
];

Or wire the rules yourself:

import mcpSdkSecurity from 'eslint-plugin-mcp-sdk-security';

export default [
  {
    plugins: { 'mcp-sdk-security': mcpSdkSecurity },
    rules: {
      'mcp-sdk-security/require-tool-input-schema': 'error',
    },
  },
];

oxlint

Every rule in this plugin runs on oxlint as well as ESLint:

{ "jsPlugins": ["eslint-plugin-mcp-sdk-security/oxlint"] }

📦 Compatibility

PackageVersion
@modelcontextprotocol/sdknpm
ESLintnpm
Node.jsnode

See the ESLint Version Support Policy for the full matrix.

Rules

Legend

IconDescription
💼Recommended: Included in the recommended preset.
⚠️Warns: Set to warn in recommended preset.
🔧Auto-fixable: Automatically fixable by the --fix CLI option.
💡Suggestions: Providing code suggestions in IDE.
🚫Deprecated: This rule is deprecated.
🟢Type-unaware: AST-only, runs in oxlint JS-plugin tier.
🟡Type-aware (refining): pure-AST primary path; types refine precision.
🟠Type-aware (graceful): requires TS program; silent without it.
RuleCWEOWASPCVSSDescription🧠💼⚠️🔧💡🚫
no-command-injection-in-toolCWE-78A03:2021Disallow an MCP tool argument being used directly as the command in a child_process call.🟢
no-tool-description-injectionCWE-1427A03:2021Require MCP tool descriptions and titles to be static text, since they reach the model as instructions.🟢
no-unvalidated-tool-argsCWE-20A03:2021Disallow a tool handler reading an argument its declared input schema does not include.🟢
require-tool-input-schemaCWE-20A03:2021Require an input schema when registering an MCP tool🟢

⭐ Support & follow

If this plugin caught a real bug for you, star the repo — stars are the signal that keeps the Interlace ESLint ecosystem maintained — and follow the writeups on Dev.to for the benchmarks and security research behind these rules.

GitHub stars

Part of the Interlace ESLint ecosystem — AI-native rules with LLM-optimized error messages:

Security

PluginDownloadsDescription
eslint-plugin-anthropic-securitydownloadsAnthropic SDK security.
eslint-plugin-browser-securitydownloadsXSS, DOM security.
eslint-plugin-drizzle-securitydownloadsDrizzle security.
eslint-plugin-express-securitydownloadsExpress middleware hardening.
eslint-plugin-gemini-securitydownloadsGoogle Gemini SDK security.
eslint-plugin-jwt-securitydownloadsToken security.
eslint-plugin-knex-securitydownloadsKnex security.
eslint-plugin-lambda-securitydownloadsAWS Lambda hardening.
eslint-plugin-mongodb-securitydownloadsMongoDB injection.
eslint-plugin-mysql-securitydownloadsMySQL security.
eslint-plugin-nestjs-securitydownloadsNestJS framework hardening.
eslint-plugin-node-securitydownloadsServer-side patterns.
eslint-plugin-openai-securitydownloadsOpenAI SDK security.
eslint-plugin-postgresql-securitydownloadsPostgreSQL security.
eslint-plugin-prisma-securitydownloadsPrisma security.
eslint-plugin-secure-codingdownloadsInjection prevention.
eslint-plugin-sequelize-securitydownloadsSequelize ORM security.
eslint-plugin-sqlite-securitydownloadsSQLite security.
eslint-plugin-supabase-securitydownloadsSupabase security.
eslint-plugin-typeorm-securitydownloadsTypeORM security.
eslint-plugin-vercel-ai-securitydownloadsAI SDK security.

Code quality

PluginDownloadsDescription
eslint-plugin-conventionsdownloadsTeam-specific habits and styles.
eslint-plugin-import-nextdownloadsFast cycle + import-graph analysis.
eslint-plugin-maintainabilitydownloadsCognitive load and clean-code patterns.
eslint-plugin-modernizationdownloadsESNext migration + syntax evolution.
eslint-plugin-modularitydownloadsStructural integrity and DDD patterns.
eslint-plugin-operabilitydownloadsProduction readiness and resource health.
eslint-plugin-react-a11ydownloadsReact accessibility / WCAG.
eslint-plugin-react-featuresdownloadsReact best practices and optimization.
eslint-plugin-reliabilitydownloadsRuntime stability and error safety.

📄 License

MIT © Ofri Peretz

Building secure JavaScript with Interlace? Star the repo to get new rules and CWE coverage as we ship them — or follow the AI-code-security benchmarks behind them.