{"_id":"mcp-secure-server","_rev":"35-db3ed91da57122fdf7f9b57896ef2e47","name":"mcp-secure-server","dist-tags":{"security":"0.0.25-security","latest":"0.0.25-security"},"versions":{"0.0.1-security":{"name":"mcp-secure-server","version":"0.0.1-security","author":"","license":"ISC","_id":"mcp-secure-server@0.0.1-security","maintainers":[{"name":"mangwana","email":"jmangwana@github.com"}],"dist":{"shasum":"8c774f5fb480e895a936b03ee5823848b18d5235","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.1-security.tgz","fileCount":1,"integrity":"sha512-1PSBzGBpQgBaE+7EvBGfMSdYIXHqVV6U4gajsikXcob4C+CYQQZ40zTehnwwBoQzhBsZ5aKgEgEwaxeQatyOcA==","signatures":[{"sig":"MEQCIHP+1zMY72rfOmRp44QyShwwWvrcsyZ3zlpoanxh6ne2AiB+OibmvHQyQPefKDhOu3GYwbHKa1ZCWS3htiib+0MC8g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":222},"main":"index.js","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"mangwana","email":"jmangwana@github.com"},"_npmVersion":"10.9.2","directories":{},"_nodeVersion":"22.15.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.1-security_1767371094141_0.3834873169633972","host":"s3://npm-registry-packages-npm-production"}},"0.0.6-security":{"name":"mcp-secure-server","version":"0.0.6-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.6-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"75a182c8390d731e273f7919b9d77c67848af07f","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.6-security.tgz","fileCount":259,"integrity":"sha512-r4SjGtITIGcflrsHH+culdiVRfHgczwkzIzQDaKQV7uDycffrqA4vxmaQ831Yq1faIqWrDBjzc8FD4xIPr70tg==","signatures":[{"sig":"MEMCH3+LAVXjho5cIQHhLRjkQ5GFpVy520IFCsW3gdj6MV0CIBzKMAUWP3He4kn3Z52RjYzzTx64wjNJxokEl29iFuNQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":928825},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"acd35f1b2c584980598f5c5d56abe773f90919cb","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.5.1","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.5.0","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.6-security_1769106919157_0.8047877015185836","host":"s3://npm-registry-packages-npm-production"}},"0.0.7-security":{"name":"mcp-secure-server","version":"0.0.7-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.7-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"68210ad4e481f24c2941d651662ead646919da2d","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.7-security.tgz","fileCount":259,"integrity":"sha512-y4PMQPYBUkRvD46cVr9EyCcn5GyByTRMWnzL5S9risj5RjRq9dE/RXYuooWfKcmbZbdTi/FKy27ERbcrLqgo4g==","signatures":[{"sig":"MEYCIQCMNXtB4fEvdB4bLOiQBhBIaSF0dKvFXj43BZ3kj0IEgwIhAKW4PXl4uhDYSuFHZ+UEjp4FU9r6dy/nQ0L35xEgv9yf","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":928987},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"4c99da71468c29bb285a3f0d3ad644ef8b4abe7d","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.5.1","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.5.0","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.7-security_1769622557837_0.221883347726342","host":"s3://npm-registry-packages-npm-production"}},"0.0.8-security":{"name":"mcp-secure-server","version":"0.0.8-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.8-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"9ad74377b1cb3cb17310191cac2f3c1b130afb81","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.8-security.tgz","fileCount":259,"integrity":"sha512-6pOLZ/iFe4V4ea7EgUhvVPD+uDT3Qnwto/LXchJdzAdrCqFi8MjdaqbjkSI1ooK5fQY8HaIx3XNI4uO0wO8PTg==","signatures":[{"sig":"MEUCIQDCeB19JAp4lfod4EpOxpqS0WBSUVcOZU9KRKenJ3pnRQIgfRJul+9/K8xvHUr5DZ6SpbxZD2siIYr9stIw4dz8Nfk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":930548},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"d317c8d62f9edfb0f038dfce75dbfce2848d13b2","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.8.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.13.0","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.8-security_1772586063349_0.9654721641874473","host":"s3://npm-registry-packages-npm-production"}},"0.0.9-security":{"name":"mcp-secure-server","version":"0.0.9-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.9-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"5aded4376dfd6cc1eb3dafc0922dc71fb7f6011b","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.9-security.tgz","fileCount":259,"integrity":"sha512-Kq9jCceYwg9vS4iiKWw5wg9YhnBeTcOKUMrI08+vk8V2GesMOsymnc1yYWQGTFtZLnZ81whjEBMvVFR9+ZVdLQ==","signatures":[{"sig":"MEYCIQCuJiFIgLo7sq4OelWqQdBAHTmM5aJz6FFVEvJhoL+4HwIhAKAHV3k/NIGrngQfgd5X5g6LCinoyLoYLU6MHBV76PAO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":931924},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"3f6fd83d152ed0ea514b60053331d9ff8f7510a1","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.9-security_1775371722597_0.787852437168072","host":"s3://npm-registry-packages-npm-production"}},"0.0.10-security":{"name":"mcp-secure-server","version":"0.0.10-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.10-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"1bf1172a93ad7494867c8dd96edccc6b774397cb","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.10-security.tgz","fileCount":259,"integrity":"sha512-/e+WJlvm7VkCua9UQqwPawlKCrYIGxSAO8laVntknYyCxKbTgD6OXCf1UmtQbFOClLQ5TKTrP8usOxXd2Vz82Q==","signatures":[{"sig":"MEUCIQCMn7lWHai6m9Wnpc00P3dYdua0xTGSV/DhuvbFbIeH3wIgddaHcvys6nVJwE9BaqftIOqPgn01/XSqB1TPhsrNZ3M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":933186},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"f147391554ac3543b289788f9d6b06829b5a3a9c","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.10-security_1775687792704_0.13483048848833046","host":"s3://npm-registry-packages-npm-production"}},"0.0.11-security":{"name":"mcp-secure-server","version":"0.0.11-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.11-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"5fd6cac06bc249aa21a280ffc9a38eec7b9b26cf","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.11-security.tgz","fileCount":259,"integrity":"sha512-fYYO9cd1fC5hv7W0sg0X2XiF2/J5ZvsOI089EIDw778EdZSyFoBbjHPkR1+Y8qEPW0ubi7o2ld02fXnfYxInWw==","signatures":[{"sig":"MEUCIQC0LVbK66IL0HBUoDyqCWnGkAKyUh1duHxUdOsJ6ap64QIgcNe5jEyyC4hy0rYTo5LmUipl0v+gYq4bkntNoFSCamc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":934030},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"d833a87fb48ef738568f2066628ffaa08bbf6e90","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.11-security_1776283772843_0.8570313114596046","host":"s3://npm-registry-packages-npm-production"}},"0.0.12-security":{"name":"mcp-secure-server","version":"0.0.12-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.12-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"46eb8b8b065a03ace1ca76781824b79af5ca92a5","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.12-security.tgz","fileCount":259,"integrity":"sha512-lN6gG5q53+ggQdWkwFsh+4ssPbQObMwhkl9HBQAUxmZ6LsX33RSY+8DaQ4gkOMSfcuQrA4/tyAjZZXo/E4Yf7Q==","signatures":[{"sig":"MEQCIGENshjhmeND6UmNWneWiT2dDeJlE5oyf3iptr2cZNxzAiBoyXqboJAuxG5jHXQW9L/SELmr9gyUV9osRdb/H4BNiw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":934630},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"4fdac79ea9c9656252d685b9616640cf586b7ea3","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.12-security_1776283935160_0.9483281554695","host":"s3://npm-registry-packages-npm-production"}},"0.0.13-security":{"name":"mcp-secure-server","version":"0.0.13-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.13-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"fefb6986e8c6777c392d476dc9d13a1c81f6426e","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.13-security.tgz","fileCount":259,"integrity":"sha512-fWuYfKxEtWnKyC/Q497sUPuxYNqGaZ4EX4MHrN8Gjf7VfeOxGhWSsTXJzGp1T9KpkUXKJFDcSKWlCWKB3CtlyA==","signatures":[{"sig":"MEUCIQCZ9joUJsum714jQBm0Bysqk2JoZkE2Grb9P0DsvMounQIgY0PufN5F4syZxPWzxTilfznFyJho8g8K8PP4zZsZ3pQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":935512},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"be58977320e3544b257e57d5469f476f2105b512","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.13-security_1776284161766_0.2725048929474234","host":"s3://npm-registry-packages-npm-production"}},"0.0.14-security":{"name":"mcp-secure-server","version":"0.0.14-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.14-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"30bff17727085ccf7cb2036c0dd08bfd54930081","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.14-security.tgz","fileCount":259,"integrity":"sha512-UsyRvxXjzIuM1jlxqsfbYiShd4Q6hkPE18rJdKOo6KxCcjZhNFfgBaiZfpisdc0doikR39Tu3xy14HP0t3dmew==","signatures":[{"sig":"MEUCIQDJVhVSxlkPFVRG4g2NKJpcAB46EdoRiqrDGHOBhNQCNgIgAVDp8t3S5MYwE4VxGj6zCZy+4YAS6R4GLc4YS/d7rqk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":938926},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"ec57e84ae70dc86ea810d79dcbd5abc46b6bbc13","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.14-security_1777430311945_0.7605088601822241","host":"s3://npm-registry-packages-npm-production"}},"0.0.15-security":{"name":"mcp-secure-server","version":"0.0.15-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.15-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"b418e8b1c64a551118fa313e75beeb367f5246f9","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.15-security.tgz","fileCount":259,"integrity":"sha512-Dt/ulLiZpvgVviYZRZWg3EczntFPSbL8pKdoofMLYD9hmC6k17eLRCbbrcRwu1Pm6rMatUnzsCuDkfr6Ti8T4A==","signatures":[{"sig":"MEQCIH7qm6bwBbHNvsZcoTNOCUjcWxvLlwy+In06p1x5zXndAiBOWspdPSGIPeXbw53zHS8GmiHUTmyUdW0Yr+gqvnlbcw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":939856},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"ccfcad6eb8ea4a5fa1bd901372ad51cc52dd2641","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.15-security_1780884729507_0.42905194313657113","host":"s3://npm-registry-packages-npm-production"}},"0.0.16-security":{"name":"mcp-secure-server","version":"0.0.16-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.16-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"2cd012a373adfeb6dc2ce69305bad0235bf17cd7","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.16-security.tgz","fileCount":259,"integrity":"sha512-4dfx8MNV5NfHLUVMFTZ/yeUBZlKXddcJRiisabmrFHwsgmNbTaLipXJAyRyw7FhHJ2YQb4wwg/NXkX79oOWJXA==","signatures":[{"sig":"MEUCIQDgg0Hu57CBWCPg97H+v09Dj9utwZ7UQiOMWXX5hxOf6QIgOhTHbvmIPmJTMWDBBklt1icy9WC3GC1EviPOFCAMnMc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":939862},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"2cff548321f2c9791bed2b851970f40023758973","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.16-security_1781221351081_0.9035076745728379","host":"s3://npm-registry-packages-npm-production"}},"0.0.17-security":{"name":"mcp-secure-server","version":"0.0.17-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.17-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"e7cff4fe5383c2983e23c41b0155af42ad0ad757","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.17-security.tgz","fileCount":259,"integrity":"sha512-GzdwiZ+tLAwzFWgl0YspI1NmCCDNW0FR+PPiETZxWr+bvL3ivkIghtyc5UCCf4F1hw5lzSaE1opc+Sw9Aox+0A==","signatures":[{"sig":"MEUCIBA4Kyd3vOK4/3IvFTCORcABB+hqDxP/o21npWeLTNBTAiEAiEToJ/aet+eKo9mxe2zw39G+HUDPMxHf/S2ELGHsbRE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":941663},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"2cff548321f2c9791bed2b851970f40023758973","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.17-security_1781305091440_0.5204587084595562","host":"s3://npm-registry-packages-npm-production"}},"0.0.18-security":{"name":"mcp-secure-server","version":"0.0.18-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.18-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"8b99b9c7f18570b8246888feeaddcbb2e0db9266","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.18-security.tgz","fileCount":260,"integrity":"sha512-BTFQIWFy3XQXKMuk3kKyX8fDP4Czpuz9zxKADGPOhzH7EsocMS/Zg23eSvyIEr5t5v12SSh5IHlkeor7m+cL+Q==","signatures":[{"sig":"MEUCIQDfv/4fu5p/RKetd30YwNB6lcIN9I4TrUY70YwyBvL21AIgLRxz+bEbUyO0GO9nUEG7zKKwl0E2YQR/ytfnMQkQphM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":972070},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":"./dist/security/mcp-secure-server.js","./transport":"./dist/security/transport/index.js"},"gitHead":"080f992e6dba29070a99dbac2747e7aa012dc903","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.18-security_1782097831188_0.5834448551828264","host":"s3://npm-registry-packages-npm-production"}},"0.0.19-security":{"name":"mcp-secure-server","version":"0.0.19-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.19-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"cc3b52dd81eeed26fa364bcf46e8a62a896a837e","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.19-security.tgz","fileCount":260,"integrity":"sha512-xnuahTHPRD9hA8nDRwXAjtYsGxOL3Xg1YPva0BX6cxgDpqz2mXwJmICme8XlC4BXW7hP3xsN788lc1Vo59KQzA==","signatures":[{"sig":"MEQCIA+TXvuwOKPQOMAJZtlBzudWdRQdrf9PuBcpEEKMMOMsAiB4ZypEBXbB9xNOxXQp7WngIJEgVp09vjbslr40CL87UA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":991497},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":{"types":"./dist/types/security/mcp-secure-server.d.ts","default":"./dist/security/mcp-secure-server.js"},"./transport":{"types":"./dist/types/security/transport/index.d.ts","default":"./dist/security/transport/index.js"}},"gitHead":"506e35b34b37a3c4f4e6f0a2244bc9bcabc10d1a","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.19-security_1784347880692_0.5027298665778495","host":"s3://npm-registry-packages-npm-production"}},"0.0.20-security":{"name":"mcp-secure-server","version":"0.0.20-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.20-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"ea64c59321c04047adcce6b73de44d490765b70c","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.20-security.tgz","fileCount":260,"integrity":"sha512-JkS8u5P+nCfc3588SAwA/QUn+7PZPE2ENNeQrx5W00jAMIi9F+WDrF5IUVXaY0aNUKyTq3j2jkbda+SmRoQilw==","signatures":[{"sig":"MEYCIQCc6X5+eOKV7TilrCUdmRfSt3Z6/s0GR2mV8/QgErVqXQIhAMBQzaA8xF/JMZp3wtrT1+1r2hBmg9ozGhPCzI55rJOj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1004128},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":{"types":"./dist/types/security/mcp-secure-server.d.ts","default":"./dist/security/mcp-secure-server.js"},"./transport":{"types":"./dist/types/security/transport/index.d.ts","default":"./dist/security/transport/index.js"}},"gitHead":"ecb30716b87ed127f0412956738afb7af385b267","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.1.1","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.18.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^3.2.4","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.20-security_1787594046351_0.2717777887645785","host":"s3://npm-registry-packages-npm-production"}},"0.0.21-security":{"name":"mcp-secure-server","version":"0.0.21-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.21-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"f18bec9500010766d79a7338c2e5de5a7f379a1f","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.21-security.tgz","fileCount":264,"integrity":"sha512-F8L0uvYTvA+2ZOqOgJRFTVwX7BVnSZkYiH/oNC6EtrQ1WeNV/vNfWhJuCPG+vXQpz6Vyq2HeSemewQGFFLUgeA==","signatures":[{"sig":"MEQCHxlWAN1FEscWgg7txEgx2DgwPQrOTCtQh1h9PokbcTcCIQD4XrRNnVuj4s+HVu1rQ/k7mnHP3looLdv80GG0y+XE3Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIHPmeLAnV0JZ2apWTNnbl55GES80jUPpT4Co6ACplC9CAiEAl7Ns6Ix989040TOnRNTEGkSOHG7keb0O0i47PR0Z6m4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1055143},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":{"types":"./dist/types/security/mcp-secure-server.d.ts","default":"./dist/security/mcp-secure-server.js"},"./transport":{"types":"./dist/types/security/transport/index.d.ts","default":"./dist/security/transport/index.js"}},"gitHead":"5348b3ef614d0da5912a56ee11f86fc5888a916b","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.2.6","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"ws":"^8.21.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^4.1.11","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^4.1.11","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.21-security_1789102849032_0.17730761397880657","host":"s3://npm-registry-packages-npm-production"}},"0.0.22-security":{"name":"mcp-secure-server","version":"0.0.22-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.22-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"65313886ea4db2b5d293c45035758f147917cfae","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.22-security.tgz","fileCount":268,"integrity":"sha512-Ao51nAYt42YKhJRYQChE8N8OqFNhIioMvkpcR6bhscVLrgFtUOPGhMybpVYz87HKQ9h+TO6ZD3tM89OcmOIO/Q==","signatures":[{"sig":"MEYCIQC6C4l5FD4Y/BtQ1cVBv4YpYlOhBsfV3wTWmGS02gcaqAIhAPfcV4qNK4L5HMPAInuaWiBcj9Ef+zB3YxL3NazC9U4j","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIG4nwY4yktpsMXxvBjqaVIKAt/JhFBkIKsurTx1K9h+EAiAJq5kQ1MiGvDPxK1F7Bazlkae4B1tGiBtJdHhjEFbFxA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1062355},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":{"types":"./dist/types/security/mcp-secure-server.d.ts","default":"./dist/security/mcp-secure-server.js"},"./transport":{"types":"./dist/types/security/transport/index.d.ts","default":"./dist/security/transport/index.js"}},"gitHead":"b2ed5f3ecaf3b4c57a54a4a68a68817814024231","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.11.0","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.2.6","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.21.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^4.1.11","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^4.1.11","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.22-security_1789857565765_0.9122827274193952","host":"s3://npm-registry-packages-npm-production"}},"0.0.23-security":{"name":"mcp-secure-server","version":"0.0.23-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.23-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"4a9275ca46e2002fa511c5fb808841642ce8a228","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.23-security.tgz","fileCount":272,"integrity":"sha512-UiieGmrdi+NJ9pD7+u9+zELxdTSA4wzF39sn9fAg4MvpKgp8+TDP161IovdiIKy/IjrwpCSihYR58kZgOsl+AQ==","signatures":[{"sig":"MEUCIQDdyCU0XY/riRJ6NW4+HCi0Jt826pkcBvm958cR5BOzyQIgEA9XqDffrFeqltVw10cWdVAs66DmKqBSUE4v1GvlQuU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQD0J7TvlbsM9Bg65YPRsjO/eEWx7ukFw5g+xJVt3VaVAgIgXz6B2XF+ya+B927WwyqmDXYeOR2CXwmCEdjfX2enkog=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1077899},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":{"types":"./dist/types/security/mcp-secure-server.d.ts","default":"./dist/security/mcp-secure-server.js"},"./transport":{"types":"./dist/types/security/transport/index.d.ts","default":"./dist/security/transport/index.js"}},"gitHead":"35af3eed2f27a9b76250e50bb01fcd3d805d8470","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.19.1","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.2.6","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.21.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^4.1.11","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^4.1.11","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.23-security_1790193182319_0.5689802629500709","host":"s3://npm-registry-packages-npm-production"}},"0.0.24-security":{"name":"mcp-secure-server","version":"0.0.24-security","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"author":{"name":"aself101"},"license":"MIT","_id":"mcp-secure-server@0.0.24-security","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"homepage":"https://github.com/aself101/mcp-secure-server#readme","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"804b4437f749a58d4eaff6b47ef5f134863a40de","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.24-security.tgz","fileCount":272,"integrity":"sha512-iP6IRFoRbYz7fKog9e2ujqmWT2lIBVY1PdVVTRwF7OTWimHcN+Kbru7GAwQ1wiVC8Ou0ZjO1yuIJVUAlw3ZKew==","signatures":[{"sig":"MEUCIQDR8XCFMaFfui9nDLewH9cm+1V8Ukf5H113ghPNV+2sqwIgLPorPl6yJ0HKp+jOMbcX2yb5KZ380uHDFUE9+S4x+7o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDWY52n1wRBuL5OSywiqXHXttunybW+FNnsDdPZLSPTkAIhANKMe3E22BzTYHJWur58mOv6FD4fa4MKRW4qp0UlVsvG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1093992},"main":"./dist/index.js","type":"module","types":"./dist/types/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":{"types":"./dist/types/security/mcp-secure-server.d.ts","default":"./dist/security/mcp-secure-server.js"},"./transport":{"types":"./dist/types/security/transport/index.d.ts","default":"./dist/security/transport/index.js"}},"gitHead":"6f479d7cfa24a2fcb12a2fe764dd58c92b5d101c","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","check:types":"tsc -p test/types/tsconfig.json","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm run check:types && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.19.1","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.2.6","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.21.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^4.1.11","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^4.1.11","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-secure-server_0.0.24-security_1790197981181_0.4904891996081391","host":"s3://npm-registry-packages-npm-production"}},"0.0.25-security":{"_id":"mcp-secure-server@0.0.25-security","bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"dist":{"shasum":"ac0393d765df497fd4869ba0714c6037a4713500","tarball":"https://registry.npmjs.org/mcp-secure-server/-/mcp-secure-server-0.0.25-security.tgz","fileCount":272,"integrity":"sha512-db4BZFoPhyPvlzlSE0yUNhsSDCdGlfMUcod4JVOT7IPo+xX5lj17K2ox5GA3UgJnNCIyg3RRY6cFdmMpDy+YSQ==","signatures":[{"sig":"MEUCIQDVECPzINM7nHBAGUVyzsK8DMCkC31u0fzxra/iWLe0AQIgDjiZ0CJhS/nSsxpVOBCL7hyg4MUAkeNgXVmXhdnigng=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICv1Tv4/MU/Z5QrhrXZbb5nOrt/W+OewUsKd5U5sidvrAiEAjxHQWiSQWIHCGcbax3uRnDV9QEl8rGKgeH57bSxylv4="}],"unpackedSize":1097824},"main":"./dist/index.js","name":"mcp-secure-server","type":"module","types":"./dist/types/index.d.ts","author":{"name":"aself101"},"engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/types/index.d.ts","default":"./dist/index.js"},"./server":{"types":"./dist/types/security/mcp-secure-server.d.ts","default":"./dist/security/mcp-secure-server.js"},"./transport":{"types":"./dist/types/security/transport/index.d.ts","default":"./dist/security/transport/index.js"}},"gitHead":"63f484757f8d713a9218367967e989d24abac412","license":"MIT","scripts":{"lint":"eslint src/","test":"vitest","build":"tsc","clean":"rm -rf dist","start":"tsx cookbook/minimal-server/minimal-test-server.ts","test:ui":"vitest --ui","prebuild":"npm run clean","test:unit":"vitest run test/unit","typecheck":"tsc --noEmit","test:watch":"vitest --watch","check:types":"tsc -p test/types/tsconfig.json","test:coverage":"vitest run --coverage","minimal-server":"tsx cookbook/minimal-server/minimal-test-server.ts","prepublishOnly":"npm run build && npm run check:types && npm test","test:integration":"vitest run test/integration","test:performance":"vitest run test/performance"},"version":"0.0.25-security","_npmUser":{"name":"aself101","email":"okstory86@gmail.com"},"homepage":"https://github.com/aself101/mcp-secure-server#readme","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"_npmVersion":"11.19.1","description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","directories":{},"maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.1.13","winston":"^3.10.0","minimatch":"^10.2.6","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"ws":"^8.21.3","tsx":"^4.21.0","eslint":"^9.39.1","vitest":"^4.1.11","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^20.19.26","@vitest/coverage-v8":"^4.1.11","@typescript-eslint/parser":"^8.49.0","eslint-plugin-unused-imports":"^4.3.0","@typescript-eslint/eslint-plugin":"^8.49.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-secure-server_0.0.25-security_1790291134396_0.8240380868349952"}}},"time":{"created":"2026-01-02T16:24:54.141Z","modified":"2026-09-24T23:05:34.742Z","0.0.1-security":"2026-01-02T16:24:54.290Z","0.0.3-security":"2026-01-08T17:39:09.224Z","0.0.4-security":"2026-01-08T17:42:13.972Z","0.0.5-security":"2026-01-08T17:46:50.447Z","0.0.6-security":"2026-01-22T18:35:19.316Z","0.0.7-security":"2026-01-28T17:49:18.134Z","0.0.8-security":"2026-03-04T01:01:03.620Z","0.0.9-security":"2026-04-05T06:48:42.742Z","0.0.10-security":"2026-04-08T22:36:32.937Z","0.0.11-security":"2026-04-15T20:09:33.025Z","0.0.12-security":"2026-04-15T20:12:15.347Z","0.0.13-security":"2026-04-15T20:16:01.955Z","0.0.14-security":"2026-04-29T02:38:32.126Z","0.0.15-security":"2026-06-08T02:12:09.692Z","0.0.16-security":"2026-06-11T23:42:31.303Z","0.0.17-security":"2026-06-12T22:58:11.703Z","0.0.18-security":"2026-06-22T03:10:31.344Z","0.0.19-security":"2026-07-18T04:11:20.838Z","0.0.20-security":"2026-08-24T17:54:06.537Z","0.0.21-security":"2026-09-11T05:00:49.126Z","0.0.22-security":"2026-09-19T22:39:25.856Z","0.0.23-security":"2026-09-23T19:53:02.411Z","0.0.24-security":"2026-09-23T21:13:01.286Z","0.0.25-security":"2026-09-24T23:05:34.583Z"},"bugs":{"url":"https://github.com/aself101/mcp-secure-server/issues"},"author":{"name":"aself101"},"license":"MIT","homepage":"https://github.com/aself101/mcp-secure-server#readme","keywords":["mcp","security","claude","ai","validation","protection","framework","middleware"],"repository":{"url":"git+https://github.com/aself101/mcp-secure-server.git","type":"git"},"description":"Secure-by-default MCP server with 5-layer validation for defense-in-depth protection","maintainers":[{"name":"aself101","email":"okstory86@gmail.com"}],"readme":"# MCP Security Framework\n\n[![npm version](https://img.shields.io/npm/v/mcp-secure-server.svg)](https://www.npmjs.com/package/mcp-secure-server)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)\n[![Node.js](https://img.shields.io/badge/node-%3E%3D18.0.0-brightgreen)](https://nodejs.org)\n[![TypeScript](https://img.shields.io/badge/TypeScript-5.0+-blue.svg)](https://www.typescriptlang.org/)\n[![Tests](https://img.shields.io/badge/tests-1293%20passing-brightgreen)](test/)\n[![Coverage](https://img.shields.io/badge/coverage-93.8%25-brightgreen)](test/)\n\nA secure-by-default MCP server built on the official SDK with 5-layer validation. Provides defense-in-depth against traditional attacks and AI-driven threats.\n\nThis framework implements defense-in-depth security with zero configuration required, protecting MCP servers from path traversal, command injection, SQL injection, XSS, prototype pollution, SSRF, and 20+ additional attack vectors.\n\n## Quick Start\n\n### Installation\n\n```bash\nnpm install mcp-secure-server\n```\n\n**Upgrading to `0.0.23-security`:** three security fixes that can start rejecting calls a server\naccepted before. A tool's `maxArgsSize` is now enforced whether or not the tool declares\n`argsShape` (it was silently skipped without one); tool-call `arguments` that are not a plain\nobject are refused; and every byte-denominated size limit (`maxMessageSize`, `maxParamBytes`,\n`suspiciousMessageSize`, `maxArgsSize`, `maxEgressBytes`) now counts UTF-8 bytes rather than\ncharacters, so non-ASCII payloads near a limit measure up to 3x larger. Review your caps before\nupgrading. See [CHANGELOG.md](CHANGELOG.md).\n\n### Basic Usage\n\n```typescript\nimport { SecureMcpServer } from 'mcp-secure-server';\nimport { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';\nimport { z } from 'zod';\n\n// Create secure server with a security preset\nconst server = new SecureMcpServer(\n  { name: 'my-server', version: '1.0.0' },\n  {\n    securityLevel: 'standard',  // 'basic' | 'standard' | 'paranoid' | 'custom'\n    // Layer 4 denies any tools/call whose name is not registered here (fail\n    // closed). server.registerTool() below does NOT register with Layer 4 by itself.\n    toolRegistry: [{ name: 'calculator', sideEffects: 'none' }]\n  }\n);\n\n// Register tools exactly like McpServer — registerTool(), the MCP SDK's current API\nserver.registerTool('calculator', {\n  description: 'Basic calculator',\n  inputSchema: { left: z.number(), right: z.number() }\n}, async ({ left, right }) => {\n  return { content: [{ type: 'text', text: `Result: ${left + right}` }] };\n});\n\n// Connect - transport is automatically wrapped with security\nconst transport = new StdioServerTransport();\nawait server.connect(transport);\n```\n\n### Security Presets\n\nChoose your security level with a single option:\n\n```typescript\n// Development: relaxed limits, minimal validation\nconst devServer = new SecureMcpServer(\n  { name: 'dev', version: '1.0.0' },\n  { securityLevel: 'basic' }\n);\n\n// Production: balanced security (default)\nconst prodServer = new SecureMcpServer(\n  { name: 'prod', version: '1.0.0' },\n  { securityLevel: 'standard' }\n);\n\n// High-security: maximum protection\nconst secureServer = new SecureMcpServer(\n  { name: 'secure', version: '1.0.0' },\n  { securityLevel: 'paranoid' }\n);\n\n// Custom: override specific values within a preset\nconst customServer = new SecureMcpServer(\n  { name: 'custom', version: '1.0.0' },\n  {\n    securityLevel: 'standard',\n    maxRequestsPerMinute: 60  // Override just this value\n  }\n);\n```\n\n| Preset | Use Case | Message Size | Rate Limit | Burst | Automation Detection |\n|--------|----------|--------------|------------|-------|---------------------|\n| `basic` | Development, testing | 100KB | 120/min | 30/10s | Disabled |\n| `standard` | Production (default) | 50KB | 30/min | 10/10s | Enabled |\n| `paranoid` | High-risk, compliance | 25KB | 15/min | 5/5s | Enabled (strict) |\n| `custom` | Full control | You decide | You decide | You decide | You decide |\n\n### Programmatic Preset Access\n\nAccess preset configurations programmatically for dynamic configuration, validation, or custom tooling:\n\n```typescript\nimport {\n  SECURITY_PRESETS,\n  resolvePreset,\n  getDefaultPreset,\n  isValidPreset\n} from 'mcp-secure-server';\n\n// Get the default preset name\nconst defaultName = getDefaultPreset();  // 'standard'\n\n// Validate user input\nconst userInput = 'paranoid';\nif (isValidPreset(userInput)) {\n  const config = resolvePreset(userInput);\n  console.log(config.maxMessageSize);      // 25600\n  console.log(config.maxRequestsPerMinute); // 15\n}\n\n// Iterate all presets for documentation or UI\nfor (const [name, config] of Object.entries(SECURITY_PRESETS)) {\n  console.log(`${name}: ${config.maxRequestsPerMinute} req/min`);\n}\n\n// Build dynamic configuration\nfunction createServer(env: string) {\n  const level = env === 'production' ? 'paranoid' : 'basic';\n  return new SecureMcpServer(\n    { name: 'dynamic', version: '1.0.0' },\n    { securityLevel: level }\n  );\n}\n```\n\n### With Logging (Opt-in)\n\n```typescript\nconst server = new SecureMcpServer(\n  { name: 'my-server', version: '1.0.0' },\n  {\n    securityLevel: 'standard',\n    enableLogging: true,\n    verboseLogging: true,\n    logPerformanceMetrics: true,\n    logLevel: 'debug'\n  }\n);\n```\n\nFull TypeScript support with exported types for all parameters, configurations, and responses.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Architecture](#architecture)\n- [Security Layers](#security-layers)\n- [Installation](#installation)\n- [TypeScript Support](#typescript-support)\n- [Quick Start](#quick-start)\n- [Configuration](#configuration)\n- [Tool Policies Configuration](#tool-policies-configuration)\n- [API Reference](#api-reference)\n- [HTTP Transport](#http-transport)\n- [Layer 5 Customization](#layer-5-customization)\n- [Security Features](#security-features)\n- [Attack Coverage](#attack-coverage)\n- [Error Handling](#error-handling)\n- [Claude Desktop Integration](#claude-desktop-integration)\n- [Development](#development)\n- [Troubleshooting](#troubleshooting)\n- [Cookbook Examples](#cookbook-examples)\n\n## Cookbook Examples\n\nExample MCP servers demonstrating the security framework. Each server includes input validation and attack prevention.\n\n| Server | Description | Tools | Auth |\n|--------|-------------|-------|------|\n| [advanced-validation-server](cookbook/advanced-validation-server) | Layer 5 custom validators (PII detection, geofencing, business hours, egress tracking) | Financial query, batch process, export data, API call | None |\n| [api-wrapper-server](cookbook/api-wrapper-server) | Safe REST API wrapping with domain restrictions and rate limiting | Weather, currency conversion, news headlines | None |\n| [cli-wrapper-server](cookbook/cli-wrapper-server) | Safe CLI tool wrapping with command injection prevention | Git status, image resize, PDF metadata, video encode | None |\n| [database-server](cookbook/database-server) | Secure database operations with SQL injection prevention | User queries, order creation, report generation | None |\n| [filesystem-server](cookbook/filesystem-server) | Protected file system access with path traversal prevention | Read files, list directories, search files | None |\n| [http-server](cookbook/http-server) | Simple HTTP transport with `createHttpServer()` | Calculator, echo | None |\n| [image-gen-server](cookbook/image-gen-server) | Unified image generation across 5 providers (BFL, Google, Ideogram, OpenAI, Stability) | Generate, edit, upscale, describe images | API keys |\n| [kenpom-server](cookbook/kenpom-server) | College basketball analytics and efficiency ratings | Ratings, schedules, scouting reports, player stats | KenPom login |\n| [monitoring-server](cookbook/monitoring-server) | Observability with metrics, audit logging, and alerts | Security metrics, audit log, alerts, Prometheus export | None |\n| [multi-endpoint-server](cookbook/multi-endpoint-server) | Multiple HTTP endpoints with `createSecureHttpHandler()` | Admin (list-users, system-stats), Public (health, status) | None |\n| [nba-server](cookbook/nba-server) | NBA stats, live scores, and player data | Player stats, box scores, live scoreboard | None |\n| [transaction-server](cookbook/transaction-server) | Method chaining enforcement for secure transaction workflows | Session, accounts, prepare/confirm/execute transactions | None |\n\nSee the [cookbook README](cookbook/README.md) for setup instructions and detailed documentation.\n\n## Overview\n\nThe MCP Security Framework acts as a universal wrapper for any MCP server, providing comprehensive security validation through a multi-layered architecture. It implements:\n\n- **5-Layer Defense Pipeline** - Structure, Content, Behavior, Semantics, and Contextual validation\n- **Zero Configuration** - Security enabled by default with sensible defaults\n- **Universal Compatibility** - Works with any MCP server using @modelcontextprotocol/sdk\n- **Extensible Layer 5** - Add custom validators, domain restrictions, OAuth validation\n- **Tested** - 1264 tests with 93.76% line coverage, including a `dist/` smoke suite that runs the published artifact in a separate process\n- **Opt-in File Logging** - the audit logger is off by default; blocked requests always emit one `[SECURITY]` line to **stderr** (never stdout)\n- **Performance Optimized** - Content caching and efficient pattern detection\n- **Full TypeScript Support** - Complete type definitions with strict mode\n\n## Architecture\n\n```text\nRequest → Layer 1 → Layer 2 → Layer 3 → Layer 4 → Layer 5 → MCP Server\n           │          │          │          │          │\n        Structure  Content   Behavior  Semantics  Contextual\n        Validation Validation Validation Validation Validation\n```\n\n### Visual Overview\n\n```text\n                          MCP Security Framework (5 Layers by Default)\n                                          │\n    ┌─────────────┬─────────────┬─────────────┬─────────────┬─────────────┐\n    │             │             │             │             │             │\n┌───▼────┐  ┌─────▼─────┐  ┌────▼────┐  ┌────▼─────┐  ┌─────▼──────┐\n│ Layer 1│  │  Layer 2  │  │ Layer 3 │  │  Layer 4 │  │  Layer 5   │\n│ Struct.│  │  Content  │  │ Behavior│  │ Semantics│  │ Contextual │\n└────────┘  └───────────┘  └─────────┘  └──────────┘  └────────────┘\n│JSON-RPC│  │Injection  │  │Rate     │  │Tool      │  │Custom      │\n│Format  │  │Detection  │  │Limiting │  │Contracts │  │Validators  │\n│Size    │  │XSS/SQLi   │  │Burst    │  │Quotas    │  │Domain/OAuth│\n│Encoding│  │Path Trav. │  │Patterns │  │Policies  │  │Response Val│\n└────────┘  └───────────┘  └─────────┘  └──────────┘  └────────────┘\n```\n\n## Security Layers\n\n### Layer 1 - Structure Validation\n\nValidates the fundamental structure of incoming JSON-RPC messages.\n\n**Protections:**\n- JSON-RPC 2.0 format validation\n- Request size limits (default: 50KB)\n- Message encoding validation\n- Parameter count limits\n- Per-string parameter length limits (default: 5,000 chars)\n- Method name length limits\n\n**Configuration:**\n```typescript\n{\n  maxMessageSize: 50000,      // Maximum message size in bytes\n  maxParamCount: 100,         // Maximum recursive parameter count (set to Infinity to disable)\n  maxStringLength: 5000       // Maximum length of any single string parameter value (chars)\n}\n```\n\nMethod name length is capped at 100 characters. This limit is not configurable — MCP\nmethod names are protocol-level identifiers (`tools/call`, `resources/read`, …) and\nnever legitimately approach it.\n\n> **Note:** `maxMessageSize` must leave headroom above `maxStringLength` — the message\n> envelope is larger than the string it carries, and the message-size check fires first.\n\n### Layer 2 - Content Validation\n\nDetects and blocks malicious content patterns in request parameters.\n\n**Protections:** Path traversal, command injection, SQL/NoSQL injection, XSS, prototype pollution, XML entity attacks (XXE), CRLF injection, SSRF, CSV injection, LOLBins, GraphQL introspection, deserialization attacks, JNDI/Log4Shell, buffer overflow patterns, and more.\n\nSee [SECURITY.md](https://github.com/aself101/mcp-secure-server/blob/main/SECURITY.md#attack-vectors) for the complete list of 200+ attack patterns with examples.\n\n**Configuration:**\n```typescript\n{\n  maxParamBytes: 50000,       // Max serialized params payload (bytes)\n  contentValidation: {\n    enabled: true,\n    debugMode: false          // Enable for detailed pattern match info\n  }\n}\n```\n\n> **Note — the size caps stack.** A large payload faces four independent ceilings, and the\n> first one to fire names itself in the rejection: `maxMessageSize` (Layer 1 envelope),\n> `maxStringLength` (Layer 1, per string), `maxParamBytes` (Layer 2, serialized params),\n> and `suspiciousMessageSize` (Layer 3, hard block). Tools that legitimately accept large\n> structured payloads (bulk saves, document stores) need all four raised together — raising\n> only one moves the rejection to the next ceiling in the stack. The per-tool `maxArgsSize`\n> (Layer 4) is a fifth, tool-scoped ceiling that cannot admit what the global caps reject.\n\n> **Note — shell-access patterns require invocation context.** The `command.shellAccess`\n> patterns run at every security level (ALWAYS_CHECK), including STORAGE tools with\n> `relaxedFields`. As of 0.0.19-security they match shell *invocations*\n> (`powershell -enc …`, `cmd /c …`, non-shebang `/bin/sh`), not bare mentions — stored\n> prose like \"PowerShell users\" or a `#!/bin/sh` shebang no longer trips them. Known\n> limitation: stored content quoting a *complete* shell invocation (e.g. a security\n> report's reverse-shell example) is still rejected at STORAGE level. This is deliberate;\n> if it becomes a problem for your workload, the escape hatch is field-level exclusion via\n> `relaxedFields`, whose content is not pattern-scanned at all.\n\n### Layer 3 - Behavior Validation\n\nRate limiting and request pattern analysis to prevent abuse.\n\n**Protections:**\n- Requests per minute rate limiting\n- Requests per hour rate limiting\n- Burst detection (configurable time window)\n- Automation detection via timing analysis\n- Large message flagging\n\n**Configuration:**\n```typescript\n{\n  maxRequestsPerMinute: 30,   // Rate limit per minute\n  maxRequestsPerHour: 500,    // Rate limit per hour\n  burstThreshold: 10,         // Max requests in burst window\n  burstWindowMs: 10000,       // Burst detection window in ms (default: 10s)\n  suspiciousMessageSize: 20000, // BLOCK messages larger than this (bytes) — a hard\n                                // rejection, not a log-only flag; keep aligned with\n                                // maxMessageSize/maxParamBytes for large-payload tools\n  automationDetection: {\n    enabled: true,            // Enable timing-based automation detection\n    sampleSize: 5,            // Number of requests to analyze\n    maxVariance: 50,          // Max timing variance (ms) before flagging\n    minInterval: 100,         // Min avg interval (ms) to flag as automation\n    maxInterval: 2000         // Max avg interval (ms) to flag as automation\n  }\n}\n```\n\n**Automation Detection:** Analyzes request timing patterns to detect automated scripts. When enabled, it monitors the variance in request intervals - suspiciously consistent timing (low variance) indicates automation rather than human interaction.\n\n### Layer 4 - Semantic Validation\n\nTool contract enforcement and resource access policies.\n\n**Protections:**\n- Tool argument validation against schemas\n- Response size limits (egress control)\n- Per-tool quota enforcement\n- Side effect declarations\n- Filesystem access control via resource policies\n- Session management\n- Method chaining enforcement (opt-in)\n\n**Configuration:**\n```typescript\n{\n  toolRegistry: [\n    {\n      name: 'my-database-tool',\n      sideEffects: 'write',       // 'none' | 'read' | 'write' | 'network'\n      maxArgsSize: 5000,          // Max argument size in bytes\n      maxEgressBytes: 100000,     // Max response size\n      quotaPerMinute: 30,\n      quotaPerHour: 500,\n      argsShape: {                // Expected argument schema\n        query: { type: 'string' },\n        limit: { type: 'number' }\n      }\n    }\n  ],\n  resourcePolicy: {\n    allowedSchemes: ['file'],\n    rootDirs: ['./data', './public'],\n    denyGlobs: ['/etc/**', '**/*.key', '**/.env'],\n    maxPathLength: 4096,\n    maxReadBytes: 2000000         // 2MB max file read\n  },\n  maxSessions: 5000,\n  sessionTtlMs: 1800000            // 30 minutes\n}\n```\n\n#### Method Chaining Enforcement\n\nLayer 4 can enforce valid method call sequences to prevent abuse patterns like calling dangerous tools without proper initialization.\n\n**Enable chaining enforcement:**\n```typescript\n{\n  enforceChaining: true,           // Enable method chaining (default: false)\n  chainingDefaultAction: 'deny',   // 'allow' | 'deny' when no rule matches\n  chainingRules: [\n    // Allow any method to call initialize\n    { from: '*', to: 'initialize' },\n    // After initialize, can list tools, resources or resource templates\n    { from: 'initialize', to: 'tools/list' },\n    { from: 'initialize', to: 'resources/list' },\n    { from: 'initialize', to: 'resources/templates/list' },\n    // After listing tools, can call them\n    { from: 'tools/list', to: 'tools/call' },\n    // Tool-to-tool calls allowed\n    { from: 'tools/call', to: 'tools/call' },\n  ]\n}\n```\n\n**ChainingRule type:**\n```typescript\ninterface ChainingRule {\n  from: string;              // Method to transition from ('*' for any)\n  to: string;                // Method to transition to ('*' for any)\n  fromTool?: string;         // Tool name glob pattern (e.g., 'file-*', '*-http*')\n  toTool?: string;           // Tool name glob pattern\n  fromSideEffect?: SideEffectType;  // 'none' | 'read' | 'write' | 'network'\n  toSideEffect?: SideEffectType;\n  action?: 'allow' | 'deny'; // Default: 'allow'\n  id?: string;               // Rule identifier for logging (named in denial messages)\n}\n```\n\n`ChainingRule` and `SideEffectType` are exported from `mcp-secure-server`.\n\n**Default method allowlist.** Independently of chaining, Layer 4 refuses any method not in its\nallowlist with `INVALID_MCP_METHOD`. The defaults are `initialize`, `ping`, `tools/list`,\n`tools/call`, `resources/list`, `resources/read`, `resources/templates/list` (since\n0.0.23-security — before that every `ResourceTemplate` a server registered was undiscoverable),\n`prompts/list`, `prompts/get`, and the `notifications/initialized`, `notifications/cancelled` and\n`notifications/progress` notifications. The default chaining rules include\n`initialize → resources/templates/list` and `resources/templates/list → resources/read`. Add or\nremove methods with the `methodSpec` option (type `MethodSpecOverride`), which merges per method\nover these defaults.\n\n**Advanced example - block dangerous transitions:**\n```typescript\n{\n  enforceChaining: true,\n  chainingDefaultAction: 'allow',  // Allow by default\n  chainingRules: [\n    // Block read tools from calling write tools directly\n    {\n      from: 'tools/call',\n      to: 'tools/call',\n      fromSideEffect: 'read',\n      toSideEffect: 'write',\n      action: 'deny',\n      id: 'no-read-to-write'\n    },\n    // Block file-* tools from calling *-http* tools\n    {\n      from: 'tools/call',\n      to: 'tools/call',\n      fromTool: 'file-*',\n      toTool: '*-http*',\n      action: 'deny',\n      id: 'no-file-to-http'\n    }\n  ]\n}\n```\n\nRules are evaluated first-match-wins. Tool patterns use simple glob matching (`*` = any chars, `?` = single char).\n\n### Layer 5 - Contextual Validation\n\nCustom validators, domain restrictions, and response filtering. Fully extensible.\n\n**Protections:**\n- Custom validator registration with priorities\n- Domain blocklist/allowlist enforcement\n- OAuth URL validation\n- Response content validation (PII detection, etc.)\n- Cross-request state via context store\n- Global rules that run before validators\n\n**Configuration:**\n```typescript\n{\n  contextual: {\n    enabled: true,                // Set false to disable Layer 5\n    domainRestrictions: {\n      enabled: true,\n      blockedDomains: ['evil.com', 'malicious.net'],\n      allowedDomains: []          // Empty = allow all except blocked\n    },\n    oauthValidation: {\n      enabled: true,\n      allowedDomains: ['oauth.example.com'],\n      blockDangerousSchemes: true\n    },\n    rateLimiting: {\n      enabled: true,\n      limit: 20,\n      windowMs: 60000\n    }\n  }\n}\n```\n\n## Installation\n\n### From npm\n\n```bash\n# Install in your project\nnpm install mcp-secure-server\n\n# Or install globally\nnpm install -g mcp-secure-server\n```\n\n### From Source\n\n```bash\n# Clone the repository\ngit clone https://github.com/aself101/mcp-secure-server.git\ncd mcp-secure-server\n\n# Install dependencies\nnpm install\n\n# Build TypeScript\nnpm run build\n```\n\n**Dependencies** (regular, installed with the package — not peer dependencies):\n- `@modelcontextprotocol/sdk` - MCP SDK (the server you wrap is built on the copy installed here)\n- `zod` - Schema validation\n- `minimatch` - Glob matching for tool-policy names\n- `winston` - The optional audit logger's transports\n\n## TypeScript Support\n\nThis package is written in TypeScript with strict mode enabled (`noUncheckedIndexedAccess`, `strictNullChecks`). All exports include complete type definitions.\n\n`SecureMcpServer`'s registration methods — `tool`, `registerTool`, `resource`, `registerResource`,\n`prompt`, `registerPrompt` — carry the underlying `McpServer`'s own types (since 0.0.24-security;\nthey were `(...args: unknown[]) => unknown` before), so handler arguments are inferred from your\nZod schema exactly as with `McpServer`, and a handler must return a valid tool result.\n\n**Prefer `registerTool()` / `registerResource()` / `registerPrompt()`.** The MCP SDK marks\n`tool()`, `resource()` and `prompt()` `@deprecated` in favour of the `register*` forms, and because\nthese methods now carry the SDK's own types, that deprecation reaches your editor and linters\n(`@typescript-eslint/no-deprecated`). Both forms work and both are secured identically —\n`registerTool()` handlers get the same Layer 5 response wrapping as `tool()` handlers. Some examples\nbelow and in the cookbook still use `tool()`.\n\n**Use the same `zod` the MCP SDK resolves.** The SDK's tool typings accept Zod 3 and Zod 4 schemas\nthrough a compatibility layer; when your project's `zod` is a *different copy* from the one the\nSDK's types see (for example Zod 3.x in your app beside Zod 4.x under the SDK), TypeScript compares\nthe two type trees structurally and `tsc` can take minutes and exhaust memory. This is SDK\nbehaviour — plain `McpServer` does the same (measured: 55 s / 4.4 GB, out of memory, on a cookbook\nserver; 0.3 s / 330 MB with one copy). Check with `npm ls zod`; align to a single Zod 4 version.\n\n### Exported Types\n\n```typescript\nimport {\n  // Main classes\n  SecureMcpServer,\n  SecureTransport,\n  ContextualValidationLayer,\n  ContextualConfigBuilder,\n\n  // Factory functions\n  createContextualLayer,\n\n  // Type guards\n  isSeverity,\n  isViolationType,\n  isError,\n  getErrorMessage,\n\n  // Types\n  SecurityOptions,\n  ValidationResult,\n  Severity,\n  ViolationType,\n  ToolSpec,\n  ResourcePolicy,\n  ValidationContext\n} from 'mcp-secure-server';\n```\n\n### Type-Safe Configuration\n\n```typescript\nimport { SecureMcpServer } from 'mcp-secure-server';\nimport type { SecureMcpServerOptions } from 'mcp-secure-server';\n\nconst options: SecureMcpServerOptions = {\n  securityLevel: 'standard',\n  maxMessageSize: 50000,\n  maxParamCount: 100,           // Recursive key count limit (Infinity to disable)\n  maxStringLength: 5000,        // Per-string parameter length limit (chars)\n  maxParamBytes: 50000,         // Serialized params payload limit (bytes, Layer 2)\n  maxRequestsPerMinute: 30,\n  enableLogging: true,\n  contextual: {\n    enabled: true,\n    domainRestrictions: {\n      enabled: true,\n      blockedDomains: ['evil.com']\n    }\n  }\n};\n\nconst server = new SecureMcpServer(\n  { name: 'my-server', version: '1.0.0' },\n  options  // TypeScript validates all options\n);\n```\n\n> `SecureMcpServerOptions` is the constructor's actual parameter type and always carries\n> the full option set. The older `SecurityOptions` name is now a deprecated alias of it —\n> it was previously a separate interface that drifted out of sync with the real options.\n\n### Validation Results\n\n```typescript\ninterface ValidationResult {\n  passed: boolean;\n  allowed: boolean;               // alias of passed (backward compatibility)\n  severity: Severity;             // 'LOW' | 'MEDIUM' | 'HIGH' | 'CRITICAL'\n  reason: string | null;          // sanitized failure reason\n  violationType: ViolationType | string | null;  // 'PATH_TRAVERSAL' | 'SQL_INJECTION' | ...\n  confidence: number;             // 0.0 - 1.0\n  timestamp: number;\n  layerName: string | null;\n  detectionLayer?: string;\n  validatorSource?: string;\n  validationTime?: number;\n}\n```\n\nAll non-suffixed fields are **required** on the interface. In plain JavaScript, custom\nLayer 5 validators may return partial literals like `{ passed: true }` — the framework\nnormalizes them at runtime. In TypeScript, annotate custom validators loosely (or return\nthe full shape); a literal `{ passed: true }` does not satisfy `ValidationResult`.\n\n### Building from Source\n\n```bash\n# Install dependencies\nnpm install\n\n# Build TypeScript to JavaScript\nnpm run build\n\n# Output is in dist/\nls dist/\n# index.js, index.d.ts, security/*.js, security/*.d.ts, types/*.d.ts\n```\n\n## Configuration\n\n### Full Configuration Reference\n\n```typescript\nconst server = new SecureMcpServer(\n  { name: 'my-server', version: '1.0.0' },\n  {\n    // ═══════════════════════════════════════════\n    // Layer 1 & 2 - Structure & Content Validation\n    // ═══════════════════════════════════════════\n    maxMessageSize: 50000,        // Max message size (bytes)\n    maxParamCount: 100,           // Max recursive parameters (Infinity to disable)\n    maxStringLength: 5000,        // Max length of any single string parameter (chars)\n    maxParamBytes: 50000,         // Max serialized params payload (bytes, Layer 2)\n    // (method name length is fixed at 100 chars — not configurable)\n\n    // ═══════════════════════════════════════════\n    // Layer 2 - Content Validation\n    // ═══════════════════════════════════════════\n    // Enabled by default with all pattern detection\n\n    // ═══════════════════════════════════════════\n    // Layer 3 - Behavior Validation\n    // ═══════════════════════════════════════════\n    maxRequestsPerMinute: 30,     // Rate limit per minute\n    maxRequestsPerHour: 500,      // Rate limit per hour\n    burstThreshold: 10,           // Max requests in burst window\n    burstWindowMs: 10000,         // Burst window duration (ms)\n    suspiciousMessageSize: 20000, // Block large messages (bytes) — hard rejection\n    automationDetection: {        // Timing-based automation detection\n      enabled: true,              // Enable/disable detection\n      sampleSize: 5,              // Requests to analyze\n      maxVariance: 50,            // Max timing variance (ms)\n      minInterval: 100,           // Min interval to flag (ms)\n      maxInterval: 2000           // Max interval to flag (ms)\n    },\n\n    // ═══════════════════════════════════════════\n    // Layer 4 - Semantic Validation\n    // ═══════════════════════════════════════════\n    toolRegistry: [               // Tool constraints\n      {\n        name: 'my-tool',\n        sideEffects: 'write',\n        maxArgsSize: 5000,\n        maxEgressBytes: 100000,\n        quotaPerMinute: 30\n      }\n    ],\n    resourcePolicy: {             // Filesystem access control\n      allowedSchemes: ['file'],\n      rootDirs: ['./data'],\n      denyGlobs: ['/etc/**', '**/*.key'],\n      maxReadBytes: 2000000\n    },\n    maxSessions: 5000,\n    sessionTtlMs: 1800000,\n    methodSpec: {                 // Method allowlist — merges per method over the defaults\n      shape: {\n        'completion/complete': { required: [] },  // add a method the defaults refuse\n        'prompts/get': null,                      // null removes a default method\n      }\n    },\n    enforceChaining: false,       // Enable method chaining (default: false)\n    chainingDefaultAction: 'deny', // 'allow' | 'deny' when no rule matches\n    chainingRules: [              // Method transition rules\n      { from: '*', to: 'initialize' },\n      { from: 'initialize', to: 'tools/list' },\n      { from: 'tools/list', to: 'tools/call' },\n      { from: 'tools/call', to: 'tools/call' },\n      // Advanced: tool patterns and side effects\n      // { from: 'tools/call', to: 'tools/call', fromTool: 'read-*', toTool: 'write-*', action: 'deny' }\n    ],\n\n    // ═══════════════════════════════════════════\n    // Layer 5 - Contextual Validation\n    // ═══════════════════════════════════════════\n    contextual: {\n      enabled: true,              // false to disable Layer 5\n      domainRestrictions: {\n        enabled: true,\n        blockedDomains: ['evil.com'],\n        allowedDomains: []        // Empty = allow all except blocked\n      },\n      oauthValidation: {\n        enabled: true,\n        allowedDomains: ['oauth.example.com'],\n        blockDangerousSchemes: true\n      },\n      rateLimiting: {\n        enabled: true,\n        limit: 20,\n        windowMs: 60000\n      }\n    },\n\n    // ═══════════════════════════════════════════\n    // Error responses\n    // ═══════════════════════════════════════════\n    enableDetailedErrors: false,  // Include redacted violation reason in top-level\n                                  // error.message (detail is always in data.reason)\n\n    // ═══════════════════════════════════════════\n    // Logging (file/audit logger disabled by default; blocked requests still\n    // emit one [SECURITY] line to stderr — see ErrorSanitizerOptions.enableSecurityLogging)\n    // ═══════════════════════════════════════════\n    enableLogging: false,         // Enable security logging\n    verboseLogging: false,        // Detailed decision logs\n    logPerformanceMetrics: false, // Timing statistics\n    logLevel: 'info',             // 'debug' | 'info' | 'warn' | 'error'\n    logDir: './logs'              // Log directory; also settable via LOG_DIR env\n  }\n);\n```\n\n### Log Directory Resolution\n\nThe log directory is resolved in this order:\n\n1. `logDir` option passed to the constructor\n2. `LOG_DIR` environment variable\n3. `<cwd>/logs` (default)\n\nA relative value is resolved against the current working directory. Set `logDir`\nexplicitly when the process may run with a non-writable working directory — for\nexample, MCP hosts (such as Claude Desktop) that launch servers with `cwd=\"/\"`,\nwhere the default would resolve to the unwritable `/logs`.\n\nIf the resolved directory cannot be created or written, the logger **degrades to\nno-op logging** rather than crashing the host (logging must never crash the\napplication). When this happens it emits a one-time warning to **stderr**, and\n`getSecurityStats().logger.fileLoggingAvailable` reports `false` (with\n`writeErrors`/`lastWriteError` for late failures) so the degraded state is\nobservable rather than silent.\n\n## Tool Policies Configuration\n\nTool policies allow you to define security levels for individual MCP tools, enabling context-aware content validation. Tools that store documentation can have relaxed pattern detection, while tools that execute commands use full validation.\n\n### Security Levels\n\n| Level | Description | Use Case |\n|-------|-------------|----------|\n| `EXECUTION` | Full validation - all attack patterns checked | Command execution, file writes, system operations |\n| `QUERY` | Standard validation - SQL/NoSQL patterns added | Database queries, API calls, search operations |\n| `STORAGE` | Relaxed validation - critical patterns only | Issue trackers, notes, documentation storage |\n| `DISPLAY` | Minimal validation - XSS and deserialization only | Read-only queries, help output, status displays |\n\n### Configuration File\n\nCreate a `tool-policies.json` file in your project root or specify a path via the `TOOL_POLICIES_PATH` environment variable.\n\n**File resolution order:**\n1. `TOOL_POLICIES_PATH` environment variable\n2. `./tool-policies.json` (current working directory)\n3. `~/.config/mcp-secure-server/tool-policies.json` (user config)\n\n### Basic Example\n\n```json\n{\n  \"version\": \"2.0\",\n  \"tools\": {\n    \"save_note\": {\n      \"level\": \"STORAGE\",\n      \"relaxedFields\": [\"content\", \"title\"],\n      \"description\": \"Stores user notes\"\n    },\n    \"get_status\": {\n      \"level\": \"DISPLAY\",\n      \"description\": \"Read-only status query\"\n    },\n    \"execute_command\": {\n      \"level\": \"EXECUTION\",\n      \"description\": \"Runs shell commands\"\n    }\n  },\n  \"defaultLevel\": \"EXECUTION\"\n}\n```\n\n### Full Schema\n\n```json\n{\n  \"version\": \"2.0\",\n\n  \"basePolicies\": {\n    \"storage-content\": {\n      \"level\": \"STORAGE\",\n      \"relaxedFields\": [\"content\", \"description\", \"title\"],\n      \"description\": \"Base policy for content storage tools\"\n    },\n    \"display-readonly\": {\n      \"level\": \"DISPLAY\",\n      \"description\": \"Base policy for read-only tools\"\n    }\n  },\n\n  \"patterns\": [\n    { \"match\": \"get_*\", \"policy\": \"display-readonly\" },\n    { \"match\": \"list_*\", \"policy\": \"display-readonly\" },\n    { \"match\": \"search_*\", \"policy\": \"display-readonly\" },\n    { \"match\": \"{save,create,update}_*\", \"policy\": \"storage-content\" }\n  ],\n\n  \"tools\": {\n    \"execute_sql\": {\n      \"level\": \"QUERY\",\n      \"description\": \"Database queries with SQL injection checks\"\n    },\n    \"save_document\": \"storage-content\",\n    \"dangerous_operation\": {\n      \"level\": \"EXECUTION\",\n      \"description\": \"High-risk operation requiring full validation\"\n    }\n  },\n\n  \"defaultLevel\": \"EXECUTION\"\n}\n```\n\n### Schema Reference\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `version` | `\"2.0\"` | Required. Schema version (must be `\"2.0\"`) |\n| `basePolicies` | `object` | Optional. Reusable policy definitions |\n| `patterns` | `array` | Optional. Glob patterns for tool matching |\n| `tools` | `object` | Optional. Explicit tool policy definitions |\n| `defaultLevel` | `string` | Optional. Fallback level for unknown tools |\n\n### Policy Object\n\n```typescript\n{\n  level: 'EXECUTION' | 'QUERY' | 'STORAGE' | 'DISPLAY',  // Security level\n  relaxedFields?: string[],  // Fields with relaxed validation\n  skipPatterns?: string[],   // Pattern categories to skip\n  description?: string,      // Documentation\n  extends?: string           // Inherit from base policy\n}\n```\n\n### Pattern Matching\n\nPatterns use [minimatch](https://github.com/isaacs/minimatch) glob syntax:\n\n| Pattern | Matches |\n|---------|---------|\n| `get_*` | `get_users`, `get_status`, `get_config` |\n| `*_issues` | `query_issues`, `search_issues`, `list_issues` |\n| `{get,list}_*` | `get_users`, `list_users`, `get_config`, `list_items` |\n| `file-*` | `file-read`, `file-write`, `file-delete` |\n| `v?_tool` | `v1_tool`, `v2_tool` |\n\n**Resolution order:**\n1. Explicit tool definitions (highest priority)\n2. Pattern matching (first match wins)\n3. `defaultLevel` from config\n4. `EXECUTION` level (secure default)\n\n### Inheritance with `extends`\n\nPolicies can inherit from base policies and add/override fields:\n\n```json\n{\n  \"version\": \"2.0\",\n  \"basePolicies\": {\n    \"base-storage\": {\n      \"level\": \"STORAGE\",\n      \"relaxedFields\": [\"content\"]\n    }\n  },\n  \"tools\": {\n    \"save_note\": {\n      \"extends\": \"base-storage\",\n      \"relaxedFields\": [\"extra_field\"],\n      \"description\": \"Inherits STORAGE level, merges relaxedFields\"\n    }\n  }\n}\n```\n\nThe result for `save_note`:\n- `level`: `STORAGE` (inherited)\n- `relaxedFields`: `[\"content\", \"extra_field\"]` (merged and deduplicated)\n\n### Relaxed Fields\n\nThe `relaxedFields` array specifies parameter names that should use `STORAGE`-level validation regardless of the tool's overall level. Useful for tools that have both sensitive and content parameters:\n\n```json\n{\n  \"tools\": {\n    \"create_issue\": {\n      \"level\": \"QUERY\",\n      \"relaxedFields\": [\"description\", \"title\"],\n      \"description\": \"QUERY level for project/priority, STORAGE for text content\"\n    }\n  }\n}\n```\n\n### Runtime Registration\n\nYou can also register tool policies programmatically:\n\n```typescript\nimport { registerToolPolicy } from 'mcp-secure-server';\n\nregisterToolPolicy('my_custom_tool', {\n  level: 'STORAGE',\n  relaxedFields: ['content', 'notes'],\n  description: 'Custom documentation tool'\n});\n```\n\n### Loading Configuration Programmatically\n\n```typescript\nimport { initializeToolPolicies, resetToolPolicies } from 'mcp-secure-server';\n\n// Load from object\ninitializeToolPolicies({\n  version: '2.0',\n  patterns: [\n    { match: 'get_*', policy: { level: 'DISPLAY' } }\n  ],\n  defaultLevel: 'QUERY'\n});\n\n// Reset to defaults\nresetToolPolicies();\n```\n\n### Validation Behavior by Level\n\n| Level | Checks SQL/NoSQL | Checks Command Injection | Checks Path Traversal | Checks XSS |\n|-------|-----------------|-------------------------|----------------------|------------|\n| `EXECUTION` | ✅ All | ✅ All (6 sub-categories) | ✅ | ✅ All |\n| `QUERY` | ✅ All | ⚠️ Critical only (shellAccess, executionWrappers) | ✅ | ✅ All |\n| `STORAGE` | ❌ | ⚠️ Critical only (shellAccess, executionWrappers) | ❌ | ✅ Critical |\n| `DISPLAY` | ❌ | ⚠️ Critical only (shellAccess, executionWrappers) | ❌ | ✅ Critical |\n\nAll levels check critical sub-categories (shell access, execution wrappers, XSS basic/advanced vectors, deserialization). EXECUTION_ONLY sub-categories (systemInfo, fileOperations, networkOperations, basicInjection) run only at EXECUTION level to avoid false positives on common words like \"top\", \"curl\", \"grep\" in documentation content.\n\n### Advanced Tool Policy Helpers\n\nAdditional utilities for programmatic tool policy management:\n\n```typescript\nimport {\n  getToolsByLevel,\n  isRelaxedField,\n  isValidSecurityLevel,\n  defaultToolPolicies\n} from 'mcp-secure-server';\n\n// Get all tools configured at a specific security level\nconst storageLevelTools = getToolsByLevel('STORAGE');\n// Returns: ['save_note', 'create_document', ...]\n\n// Check if a field has relaxed validation for a tool\nif (isRelaxedField('save_note', 'content')) {\n  // 'content' field uses STORAGE-level validation\n}\n\n// Validate security level strings\nif (isValidSecurityLevel(userInput)) {\n  // userInput is 'EXECUTION' | 'QUERY' | 'STORAGE' | 'DISPLAY'\n}\n\n// Access default policies (useful for extending)\nconst defaults = defaultToolPolicies;\n```\n\n**Use cases:**\n- **Auditing:** List all tools at each security level\n- **Debugging:** Check if a specific field is relaxed\n- **Dynamic configuration:** Validate user-provided security levels\n- **Testing:** Access defaults for baseline comparison\n\n## API Reference\n\n### SecureMcpServer\n\nDrop-in replacement for McpServer with built-in 5-layer security.\n\n```typescript\nimport { SecureMcpServer } from 'mcp-secure-server';\n\nconst server = new SecureMcpServer(serverInfo, options);\n```\n\n#### MCP SDK Passthrough Methods\n\nSecureMcpServer delegates to the underlying McpServer for most operations. Some methods add security enhancements.\n\n**Enhanced Methods** (security added):\n\n| Method | Enhancement |\n|--------|-------------|\n| `tool()` | Response validation via Layer 5 |\n| `registerTool()` | Response validation via Layer 5 |\n| `connect()` | Wraps transport with SecureTransport |\n\n**Pure Passthrough Methods** (direct delegation to McpServer):\n\n```typescript\n// Resource and prompt registration\nserver.resource(name, uri, handler);\nserver.prompt(name, description, handler);\n\n// Connection management\nawait server.close();\nserver.isConnected();\n\n// Notification methods (MCP SDK passthrough)\nserver.sendResourceListChanged();\nserver.sendToolListChanged();\nserver.sendPromptListChanged();\n```\n\n**Example with all registration types:**\n\n```typescript\nconst server = new SecureMcpServer({ name: 'demo', version: '1.0.0' });\n\n// Tool registration (response validation enabled)\nserver.tool('add', 'Add numbers', { a: z.number(), b: z.number() },\n  async ({ a, b }) => ({ content: [{ type: 'text', text: `${a + b}` }] })\n);\n\n// Resource registration (passthrough)\nserver.resource('config', 'config://app', async () => ({\n  contents: [{ uri: 'config://app', text: JSON.stringify(config) }]\n}));\n\n// Prompt registration (passthrough)\nserver.prompt('greeting', 'Generate greeting', async () => ({\n  messages: [{ role: 'user', content: { type: 'text', text: 'Hello!' } }]\n}));\n\nawait server.connect(new StdioServerTransport());\n```\n\n#### Security Methods\n\n```typescript\n// Get security statistics\nconst stats = server.getSecurityStats();\n// {\n//   server: { uptime, totalLayers, enabledLayers, loggingEnabled },\n//   behaviorLayer?: { ...request/burst counters },\n//   logger?: { ...logging health, e.g. fileLoggingAvailable }  // only when logging enabled\n// }\n\n// Get detailed security report (requires enableLogging: true)\nconst report = server.getVerboseSecurityReport();\n\n// Generate full report to file (requires enableLogging: true)\nawait server.generateSecurityReport();\n\n// Graceful shutdown with final report\nawait server.shutdown();\n```\n\n#### Property Accessors\n\n```typescript\nserver.mcpServer;           // Access underlying McpServer\nserver.server;              // Access underlying Server\nserver.validationPipeline;  // Access validation pipeline\n```\n\n### SecureTransport\n\nLow-level transport wrapper for custom implementations.\n\n```typescript\nimport { SecureTransport } from 'mcp-secure-server';\n\nconst secureTransport = new SecureTransport(\n  transport,       // Original transport\n  validator,       // Validation function\n  {\n    errorSanitizer // Optional error sanitizer\n  }\n);\n```\n\n### HTTP Transport\n\nFor remote MCP servers, use the built-in HTTP transport with security validation. Zero external dependencies - uses `node:http` directly.\n\n```typescript\nimport { SecureMcpServer } from 'mcp-secure-server';\nimport { z } from 'zod';\n\nconst server = new SecureMcpServer(\n  { name: 'my-server', version: '1.0.0' },\n  { enableLogging: true }\n);\n\nserver.tool('add', 'Add two numbers', {\n  a: z.number(),\n  b: z.number()\n}, async ({ a, b }) => ({\n  content: [{ type: 'text', text: `${a + b}` }]\n}));\n\n// Create HTTP server with security validation\nconst httpServer = server.createHttpServer({ endpoint: '/mcp' });\nhttpServer.listen(3000, () => {\n  console.log('MCP server listening on http://localhost:3000/mcp');\n});\n```\n\n**Configuration options:**\n\n```typescript\ninterface HttpServerOptions {\n  endpoint?: string;                     // MCP endpoint path (default: '/mcp')\n  maxBodySize?: number;                  // Max body size in bytes (default: 51200 = 50KB)\n  requestTimeout?: number;               // Body parse timeout in ms (default: 30000)\n  sessionlessRequestsPerMinute?: number; // Per-client-IP cap on GET/DELETE (default: 60)\n  sessionlessRequestsPerHour?: number;   // Per-client-IP cap on GET/DELETE (default: 600)\n}\n```\n\n**GET and DELETE:** these carry no JSON-RPC body, so the 5-layer message pipeline\ndoes not run on them. They are gated instead by the per-IP error lockout (an IP\nthrottled for probing cannot open SSE streams or tear down sessions) and by the\n`sessionlessRequests*` ceilings above. On every method, a present `Mcp-Session-Id`\nmust be visible ASCII of at most 256 bytes or the request is rejected with 400\nbefore the SDK or the pipeline sees it.\n\n**Session ID handling:**\n\n| Source | Value | Used By |\n|--------|-------|---------|\n| `Mcp-Session-Id` header | Client-provided | Layer 4 method-chaining state; audit log correlation |\n| Missing header | `'stateless'` | One shared chaining state for all header-less clients |\n\n> **Layer 3 rate limits and Layer 4 per-tool quotas are process-global, not per session.**\n> They do not read the session id; every client draws from the same `maxRequestsPerMinute`\n> and per-tool budgets. *(Until 0.0.21 this table said the opposite.)* For per-client\n> ceilings on the HTTP path see `sessionlessRequests*` above and the per-IP error lockout.\n\n**Standalone function:**\n\n```typescript\nimport { SecureMcpServer, createSecureHttpServer } from 'mcp-secure-server';\n\nconst server = new SecureMcpServer({ name: 'x', version: '1.0' });\nconst httpServer = createSecureHttpServer(server, { endpoint: '/api/mcp' });\nhttpServer.listen(8080);\n```\n\n**Multiple endpoints:**\n\nFor services exposing multiple MCP servers on different paths, use `createSecureHttpHandler` to compose your own routing:\n\n```typescript\nimport { SecureMcpServer, createSecureHttpHandler } from 'mcp-secure-server';\nimport { createServer } from 'node:http';\n\n// Create separate MCP servers with different tools/permissions\nconst adminServer = new SecureMcpServer({ name: 'admin', version: '1.0' });\nconst publicServer = new SecureMcpServer({ name: 'public', version: '1.0' });\n\n// Register tools on each server\nadminServer.tool('delete-user', ...);\npublicServer.tool('get-status', ...);\n\n// Create handlers (validates requests, forwards to MCP SDK transport)\nconst adminHandler = createSecureHttpHandler(adminServer);\nconst publicHandler = createSecureHttpHandler(publicServer);\n\n// Compose with custom routing\nconst httpServer = createServer(async (req, res) => {\n  if (req.url?.startsWith('/api/admin')) return adminHandler(req, res);\n  if (req.url?.startsWith('/api/public')) return publicHandler(req, res);\n  res.writeHead(404).end(JSON.stringify({ error: 'Not found' }));\n});\n\nhttpServer.listen(3000);\n```\n\n| Function | Purpose |\n|----------|---------|\n| `createSecureHttpServer` | Single endpoint, includes routing |\n| `createSecureHttpsServer` | Same, with TLS (key/cert) — recommended for production |\n| `createSecureHttpHandler` | Request handler only, you provide routing |\n\n**CORS:** Add headers manually or wrap with a CORS middleware.\n\n**HTTPS:** Use the built-in factory (or deploy behind a TLS-terminating reverse proxy):\n\n```typescript\nimport { readFileSync } from 'node:fs';\nimport { createSecureHttpsServer } from 'mcp-secure-server';\n\nconst httpsServer = createSecureHttpsServer(server, {\n  key: readFileSync('server.key'),    // TLS private key (PEM string or Buffer)\n  cert: readFileSync('server.cert'),  // TLS certificate (PEM string or Buffer)\n  ca: undefined,                      // optional CA chain\n  endpoint: '/mcp'\n});\nhttpsServer.listen(3443);\n```\n\n### Available Exports\n\n```typescript\nimport {\n  SecureMcpServer,            // Main secure server class\n  SecureTransport,            // Transport wrapper\n  createSecureHttpServer,     // HTTP server factory (single endpoint)\n  createSecureHttpHandler,    // HTTP handler factory (multi-endpoint)\n  createSecureHttpsServer,    // HTTPS server factory with TLS\n  ErrorRateLimiter,           // Rate limiter for error responses\n  getClientIp,                // Extract client IP from request\n  ContextualValidationLayer,  // Layer 5 class\n  ContextualConfigBuilder,    // Builder for Layer 5 config\n  createContextualLayer,      // Factory for Layer 5\n  // Tool policy configuration\n  initializeToolPolicies,     // Load config from object\n  resetToolPolicies,          // Reset to defaults\n  registerToolPolicy,         // Register policy at runtime\n  getToolPolicy,              // Get policy for a tool\n  isRelaxedField,             // Check if field has relaxed validation\n  getToolsByLevel,            // List tools by security level\n  isValidSecurityLevel,       // Validate security level string\n  defaultToolPolicies,        // Default policy definitions\n  getToolPoliciesConfig,      // Get current policies config\n  loadToolPoliciesConfig,     // Load from file\n  matchesPattern,             // Check if tool matches pattern\n  resolvePolicy,              // Resolve policy for tool\n  ToolPolicyError,            // Config error class\n  // Security presets\n  SECURITY_PRESETS,           // All preset definitions\n  resolvePreset,              // Get preset by name\n  getDefaultPreset,           // Get default preset name\n  isValidPreset,              // Validate preset name\n  // Type guards\n  isSeverity,                 // Type guard for Severity\n  isViolationType,            // Type guard for ViolationType\n  isError,                    // Type guard for Error objects\n  getErrorMessage             // Safe error message extraction\n} from 'mcp-secure-server';\n```\n\n| Export | Description |\n|--------|-------------|\n| `SecureMcpServer` | Drop-in replacement for McpServer with 5-layer security |\n| `SecureTransport` | Transport wrapper for message-level validation |\n| `createSecureHttpServer` | HTTP server factory with security validation |\n| `createSecureHttpHandler` | HTTP handler for composing multi-endpoint servers |\n| `createSecureHttpsServer` | HTTPS server factory with TLS certificates |\n| `ErrorRateLimiter` | Rate limiter for clients generating excessive errors |\n| `getClientIp` | Extract client IP from request (X-Forwarded-For aware) |\n| `ContextualValidationLayer` | Layer 5 class for advanced customization |\n| `ContextualConfigBuilder` | Builder for Layer 5 configuration |\n| `createContextualLayer` | Factory function for Layer 5 with defaults |\n| `initializeToolPolicies` | Load tool policies from config object |\n| `resetToolPolicies` | Reset to default (empty) policies |\n| `registerToolPolicy` | Register single tool policy at runtime |\n| `getToolPolicy` | Get resolved policy for a tool name |\n| `isRelaxedField` | Check if a field has relaxed validation for a tool |\n| `getToolsByLevel` | List tools registered at a specific security level |\n| `isValidSecurityLevel` | Validate if a string is a valid security level |\n| `defaultToolPolicies` | Default policy definitions for tools |\n| `getToolPoliciesConfig` | Get current tool policies configuration |\n| `loadToolPoliciesConfig` | Load policies from JSON file |\n| `matchesPattern` | Check if tool name matches a pattern (glob-style) |\n| `resolvePolicy` | Resolve merged policy for a tool from config |\n| `ToolPolicyError` | Error class for config validation failures |\n| `SECURITY_PRESETS` | Object containing all preset definitions (basic, standard, paranoid) |\n| `resolvePreset` | Get preset configuration by name |\n| `getDefaultPreset` | Get the default preset name ('standard') |\n| `isValidPreset` | Validate if a string is a valid preset name |\n| `isSeverity` | Type guard to check if value is a valid Severity |\n| `isViolationType` | Type guard to check if value is a valid ViolationType |\n| `isError` | Type guard to check if value is an Error object |\n| `getErrorMessage` | Safely extract error message from unknown value |\n\n### Subpath Imports\n\nEverything is available from the root import, but two subpaths exist for consumers who\nwant a narrower dependency surface (e.g. bundlers tree-shaking a transport-only usage):\n\n```typescript\nimport { SecureMcpServer } from 'mcp-secure-server/server';       // server class only\nimport { SecureTransport } from 'mcp-secure-server/transport';    // transport layer only\n```\n\nBoth carry their own `types` conditions, so they resolve under `moduleResolution:\nnode16`/`nodenext`.\n\n### HTTP Utilities\n\n`ErrorRateLimiter` and `getClientIp` are the building blocks the HTTP factories use\ninternally — reach for them only when composing a custom handler around\n`createSecureHttpHandler`:\n\n```typescript\nimport { createSecureHttpHandler, ErrorRateLimiter, getClientIp } from 'mcp-secure-server';\n\nconst handler = createSecureHttpHandler(server);  // (req, res) => Promise<void>\nconst limiter = new ErrorRateLimiter();           // throttles clients spamming invalid requests\n\nhttp.createServer(async (req, res) => {\n  const ip = getClientIp(req);                    // X-Forwarded-For aware\n  if (limiter.shouldRateLimit(ip)) { res.writeHead(429).end(); return; }\n  await handler(req, res);\n  if (res.statusCode >= 400) limiter.recordError(ip);  // count rejections against the client\n});\n```\n\n## Layer 5 Customization\n\nLayer 5 is enabled by default. You can add custom validators at runtime for application-specific security rules.\n\n### Adding Custom Validators\n\n```typescript\nimport { SecureMcpServer } from 'mcp-secure-server';\n\nconst server = new SecureMcpServer(\n  { name: 'my-server', version: '1.0.0' },\n  {\n    contextual: {\n      domainRestrictions: {\n        enabled: true,\n        blockedDomains: ['evil.com']\n      }\n    }\n  }\n);\n\n// Access Layer 5\nconst layer5 = server.validationPipeline.layers[4];\n\n// Add custom validator with priority (lower = runs first)\nlayer5.addValidator('sensitive-data-check', (message, context) => {\n  if (message.params?.arguments?.creditCard) {\n    return {\n      passed: false,\n      reason: 'Credit card data not allowed in requests',\n      severity: 'HIGH',\n      violationType: 'SENSITIVE_DATA'\n    };\n  }\n  return { passed: true };\n}, { priority: 50, failOnError: true });\n```\n\n**Exceptions fail closed.** Since 0.0.21, `failOnError` defaults to `true` for validators,\nglobal rules and response validators: a validator that throws blocks the request (or the\nresponse) with `VALIDATOR_ERROR`, matching Layers 1–4. Pass `failOnError: false` for an\nadvisory validator whose failure should not block. Before 0.0.21 the default was `false`, so\na throwing authorization or rate-limit validator silently admitted the request.\n\n### Adding Global Rules\n\nGlobal rules run before validators and can short-circuit validation.\n\n```typescript\nlayer5.addGlobalRule((message) => {\n  // Block specific operations\n  if (message.method === 'admin/delete-all') {\n    return {\n      passed: false,\n      reason: 'Operation not permitted',\n      severity: 'CRITICAL',\n      violationType: 'POLICY_VIOLATION'\n    };\n  }\n  return null;  // null = pass, continue to validators\n});\n```\n\n### Adding Response Validators\n\nValidate responses before they're sent to clients.\n\n```typescript\nlayer5.addResponseValidator('pii-filter', (response) => {\n  const content = JSON.stringify(response);\n\n  // Check for SSN pattern\n  if (/\\d{3}-\\d{2}-\\d{4}/.test(content)) {\n    return {\n      passed: false,\n      reason: 'PII detected in response',\n      severity: 'HIGH',\n      violationType: 'DATA_LEAK'\n    };\n  }\n  return { passed: true };\n});\n```\n\n### Using Context Store\n\nCross-request state management with TTL support.\n\n```typescript\n// Set context with 5-minute TTL\nlayer5.setContext('user:session:abc123', {\n  authenticated: true,\n  roles: ['admin']\n}, 300000);\n\n// Get context\nconst session = layer5.getContext('user:session:abc123');\n\n// Use in validators\nlayer5.addValidator('auth-check', (message, context) => {\n  const session = layer5.getContext(`user:session:${context.sessionId}`);\n  if (!session?.authenticated) {\n    return {\n      passed: false,\n      reason: 'Authentication required',\n      severity: 'HIGH',\n      violationType: 'AUTH_REQUIRED'\n    };\n  }\n  return { passed: true };\n});\n```\n\n### Disabling Layer 5\n\n```typescript\nconst server = new SecureMcpServer(\n  { name: 'my-server', version: '1.0.0' },\n  { contextual: { enabled: false } }\n);\n```\n\n## Security Features\n\nSee [SECURITY.md](https://github.com/aself101/mcp-secure-server/blob/main/SECURITY.md) for full security documentation including:\n- Attack detection coverage (injection, XSS, SSRF, deserialization, etc.)\n- Security best practices applied\n- SSRF protection details\n- Error sanitization\n- Reporting vulnerabilities\n\n## Attack Coverage\n\nThe framework detects and blocks 200+ attack patterns across 19 categories including injection attacks, path traversal, SSRF, deserialization, and more.\n\nSee [SECURITY.md](https://github.com/aself101/mcp-secure-server/blob/main/SECURITY.md#attack-vectors) for the complete threat model with:\n- Attack vectors and examples\n- Severity levels and detection layers\n- Mitigation strategies\n- Violation type reference\n\n## Error Handling\n\n### Error Message Behavior\n\nError messages are **deterministic and type-specific** — each violation type maps to a consistent, descriptive message. This makes errors diagnosable from logs, MCP clients, and LLM tool-use contexts.\n\n| `enableDetailedErrors` | `error.message` | `data.reason` |\n|------------------------|-----------------|---------------|\n| `false` (default) | Type-specific (e.g. \"Request validation failed\") | Redacted internal reason |\n| `true` | Type-specific + redacted reason appended | Redacted internal reason |\n\nWhen `enableDetailedErrors` is `true`, the `error.message` field includes the redacted reason so the full diagnostic is visible without digging into the `data` envelope:\n\n```json\n{\n  \"error\": {\n    \"code\": -32602,\n    \"message\": \"Request validation failed: Content validation — path traversal pattern detected in parameter 'file_path'\",\n    \"data\": {\n      \"reason\": \"Content validation — path traversal pattern detected in parameter 'file_path'\",\n      \"layer\": \"VALIDATION_ERROR\"\n    }\n  }\n}\n```\n\nWhen `enableDetailedErrors` is `false`, the top-level message is the category only — the detailed reason is still available in `data.reason`:\n\n```json\n{\n  \"error\": {\n    \"code\": -32602,\n    \"message\": \"Request validation failed\",\n    \"data\": {\n      \"reason\": \"Content validation — path traversal pattern detected in parameter 'file_path'\",\n      \"layer\": \"VALIDATION_ERROR\"\n    }\n  }\n}\n```\n\n### Validation Error Structure\n\nWhen the security pipeline blocks a request, the framework returns a JSON-RPC error with diagnostic context in the `data` field:\n\n| Field | Description |\n|-------|-------------|\n| `timestamp` | When the error occurred (ISO 8601) |\n| `token` | Unique error token for log correlation |\n| `reason` | Redacted validation reason describing what failed and why |\n| `layer` | Which validation layer or violation type triggered the block |\n| `retryAfterMs` | Present only for `RATE_LIMIT_EXCEEDED` — milliseconds to wait |\n\nThe `reason` field is sanitized through the same credential/PII redaction pipeline used for logging, so it is safe to surface to clients while still providing actionable diagnostics.\n\n### Error Codes\n\n| Code | Violation Type | Meaning |\n|------|---------------|---------|\n| `-32602` | `VALIDATION_ERROR`, `POLICY_VIOLATION`, `CONTEXT_VIOLATION` | Invalid input or policy block |\n| `-32000` | `RATE_LIMIT_EXCEEDED` | Too many requests — check `retryAfterMs` |\n| `-32603` | `INTERNAL_ERROR` | Internal validation error |\n\n### Severity Levels\n\n| Severity | Description | Action |\n|----------|-------------|--------|\n| `CRITICAL` | Active exploit attempt (command injection, deserialization) | Block + Alert |\n| `HIGH` | Serious attack (SQL injection, path traversal) | Block |\n| `MEDIUM` | Suspicious activity (rate limit, size exceeded) | Block |\n| `LOW` | Minor policy violation | Block or Warn |\n\n### Outgoing Response Sanitization\n\nThe framework sanitizes outgoing JSON-RPC error responses that contain Zod validation patterns, with one important exception: **`-32602` (Invalid params) errors are preserved**. These errors describe the caller's input mistakes — field paths, expected types, and size limits — which are the input contract, not internal implementation details. Preserving them lets callers diagnose and fix their requests.\n\nFor non-`-32602` errors that contain Zod patterns (e.g., internal `-32603` errors), the framework replaces the response with a safe generic message:\n\n```json\n{\n  \"error\": {\n    \"code\": -32602,\n    \"message\": \"Invalid input parameters\",\n    \"data\": {\n      \"reason\": \"Input failed schema validation (Zod). Check parameter types and required fields.\",\n      \"layer\": \"OUTGOING_SANITIZER\"\n    }\n  }\n}\n```\n\nThis prevents internal Zod schema structures from leaking to clients while preserving actionable validation feedback on input errors.\n\n### Nested Tool Input Errors\n\nVersion `0.0.22-security` expands serialized Zod 3 `unionErrors` and Zod 4 `errors`\nwhen one union branch has a uniquely deeper field path. For example, an invalid\nsummary can name `analysis_summary.exploration_maps.0.metadata.framework` rather\nthan only `analysis_summary`. Equal-depth alternatives and malformed diagnostics\nretain their original union message. Expansion stops at 20 nested union levels.\nThe rewrite preserves JSON-RPC IDs/error codes and `isError` tool-result envelopes.\n\nThis requires branch details to reach the sanitizer. MCP SDK 1.30 formats only\nits top-level issues, so nested details can be lost before this package sees them.\nFor affected schemas, use the schema library's public error customization API to\ninclude actionable nested paths in the union message, or an upstream formatter\nthat preserves branches. The sanitizer cannot reconstruct discarded information.\nThis release does not change tool schemas or how a host displays them.\n\n### Type Guards for Error Handling\n\n```typescript\nimport { isError, getErrorMessage, isSeverity } from 'mcp-secure-server';\n\ntry {\n  await server.connect(transport);\n} catch (error) {\n  if (isError(error)) {\n    console.error('Error:', getErrorMessage(error));\n  }\n}\n\n// Validate severity values\nconst severity = 'HIGH';\nif (isSeverity(severity)) {\n  // TypeScript knows severity is Severity type\n}\n```\n\n## Claude Desktop Integration\n\nAdd to your Claude Desktop configuration (`claude_desktop_config.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"secure-server\": {\n      \"command\": \"node\",\n      \"args\": [\"path/to/your/server.js\"],\n      \"cwd\": \"/path/to/project\"\n    }\n  }\n}\n```\n\n### Test Server\n\nRun the included test server to verify the framework:\n\n```bash\nnpm start\n```\n\nThe test server includes 7 protected tools:\n- `debug-calculator` - Basic math operations\n- `debug-file-reader` - Safe file reading\n- `debug-echo` - Text echo service\n- `debug-database` - Database query simulation\n- `debug-http` - HTTP request simulation\n- `debug-parser` - JSON/XML parsing\n- `debug-image` - Image processing simulation\n\nAdd to Claude Desktop:\n\n```json\n{\n  \"mcpServers\": {\n    \"secure-test\": {\n      \"command\": \"npx\",\n      \"args\": [\"tsx\", \"cookbook/minimal-server/minimal-test-server.ts\"],\n      \"cwd\": \"/path/to/mcp-secure-server\"\n    }\n  }\n}\n```\n\n## Development\n\n### Running Tests\n\n```bash\n# Run all tests\nnpm test\n\n# Run specific test suites\nnpm run test:unit\nnpm run test:integration\nnpm run test:performance\n\n# Watch mode for development\nnpm run test:watch\n\n# Generate coverage report\nnpm run test:coverage\n```\n\n**Test Coverage:**\n- Overall: 93.76% lines, 87.78% branches (`npm run test:coverage`)\n- 1264 tests, including `test/integration/dist-smoke.test.ts`, which imports the compiled `dist/` in a separate `node` process\n- Mutation tests for severity levels\n- Boundary value tests for limits\n- Real attack vector validation\n\n### Running a Single Test\n\n```bash\nnpx vitest run test/unit/utils/canonical.test.js\n```\n\n### Linting\n\n```bash\nnpm run lint\n```\n\n### Project Structure\n\n```text\nsrc/\n├── index.ts                              # Main entry point & public exports\n├── types/                                # TypeScript type definitions\n│   ├── index.ts                          # Type exports & guards\n│   ├── layers.ts                         # Layer type definitions\n│   ├── messages.ts                       # MCP message types\n│   ├── policies.ts                       # Policy type definitions\n│   ├── server.ts                         # Server configuration types\n│   └── validation.ts                     # Validation result types\n└── security/\n    ├── index.ts                          # Security module exports\n    ├── mcp-secure-server.ts              # SecureMcpServer class\n    ├── constants.ts                      # Configuration constants\n    ├── transport/\n    │   ├── index.ts                      # Transport exports\n    │   ├── secure-transport.ts           # SecureTransport (stdio)\n    │   └── http-server.ts                # HTTP transport server\n    ├── layers/\n    │   ├── validation-layer-base.ts      # Base class for all layers\n    │   ├── layer1-structure.ts           # JSON-RPC validation\n    │   ├── layer2-content.ts             # Content/injection detection\n    │   ├── layer2-validators/            # Modular content validators\n    │   │   ├── index.ts                  # Validator exports\n    │   │   ├── pattern-detection.ts      # Attack pattern matching\n    │   │   ├── base64-css.ts             # Base64/CSS attack detection\n    │   │   └── data-semantics.ts         # Data format validation\n    │   ├── layer3-behavior.ts            # Rate limiting & burst detection\n    │   ├── layer4-semantics.ts           # Tool contracts & policies\n    │   ├── layer5-contextual.ts          # Custom validators\n    │   ├── contextual-config-builder.ts  # Layer 5 fluent configuration\n    │   └── layer-utils/\n    │       ├── content/\n    │       │   ├── canonicalize.ts       # Text normalization\n    │       │   ├── unicode.ts            # Unicode attack normalization\n    │       │   ├── dangerous-patterns.ts # Pattern configuration\n    │       │   ├── helper-utils.ts       # Content helper functions\n    │       │   ├── patterns/             # Attack pattern definitions\n    │       │   │   ├── index.ts          # Pattern exports & utilities\n    │       │   │   ├── injection.ts      # SQL/XSS/NoSQL patterns\n    │       │   │   ├── path-traversal.ts # Path traversal patterns\n    │       │   │   ├── network.ts        # SSRF/network patterns\n    │       │   │   └── overflow-validation.ts # Buffer/encoding patterns\n    │       │   └── utils/\n    │       │       ├── index.ts          # Utility exports\n    │       │       ├── text-decoding.ts  # Encoding detection\n    │       │       ├── hash-utils.ts     # Cache key generation\n    │       │       └── structural-analysis.ts # Deep structure analysis\n    │       └── semantics/\n    │           ├── semantic-policies.ts  # Tool/resource policies\n    │           └── semantic-quota","readmeFilename":"README.md"}