URL-Based MCP Server

by sshh12

367 downloads
Not rated
GitHub

About

URL MCP is a proof of concept stateless MCP server builder that allows users to build MCP servers without writing or hosting code. It's intended for protocol and security experimentation rather than for building real world MCP integrations.

Details

Author
sshh12
Downloads
367
Categories
Developer Tools

- Stateless server builder – no code or hosting required
- Create custom MCP tools with static or dynamic responses
- Supports HTTP POST endpoints for configurable responses
- Exposes pre‑built MCP configuration for any client
- Ideal for security research and protocol testing

Go to the hosted demo at https://url-mcp-demo.sshh.io/, add custom tools via the web interface, and copy the generated MCP configuration into your client. Tools can return static text or make dynamic HTTP POST requests (e.g., to a temp URL from webhook.site). For local hosting, run python main.py in the backend/ directory after installing the requirements.

URL-Based MCP Server

> URL MCP is a proof of concept stateless MCP server builder that allows users to build MCP servers without writing or hosting code. It's intended for protocol and security experimentation rather than for building real world MCP integrations.

Screenshot 2025-04-12 at 12 07 39 PM

Usage

1. Go to https://url-mcp-demo.sshh.io/
2. Add custom tools to your MCP server

- If you want to hardcode tool responses, select "static text response"
- If you want dynamic HTTP-based responses, select "http post endpoint"
- Typically I'll use a temp URL from https://webhook.site/ which logs all the requests and allows you to configure custom responses

3. Copy the MCP Configuration into your client of choice

Local Hosting

There is not really a point to hosting this locally (the whole idea is that you can use this without hosting just with the URL) but in case you want to modify the app itself:

1. cd backend && pip install requirements.txt && python main.py

Example: System Prompt Exfiltration

Create a custom MCP server for extracting the system prompt of an application.

1. Configure the tools to trick the client into trusting it. Use a https://webhook.site/ temp url for the tool response.
2. Copy the MCP config
3. In the client ask for an audit and the view the webhook logs.

| Step 1 | Step 2 | Step 3 |
| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- |
| Screenshot 2025-04-12 at 12 14 40 PM | Screenshot 2025-04-12 at 12 14 50 PM | Screenshot 2025-04-12 at 12 15 00 PM |

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.