Security Considerations

by shane-kercheval

18 261 downloads Not rated yet Apache-2.0
GitHub

About

mcp-this lets you turn any command-line tool into an MCP tool and create structured prompt templates that any MCP Client (e.g. Claude Desktop) can use. er for any command

Details

License
Apache-2.0

Explore

- Define CLI commands as MCP tools using <<parameter>> placeholders in YAML
- Create reusable AI prompt templates with {{argument}} Handlebars syntax
- Use --config-path, --config-value, or MCP_THIS_CONFIG_PATH for configuration
- Pre-built presets: default (read-only), editing (file manipulation), github (GitHub integration)
- Optional parameters are automatically omitted from commands if not provided
- Supports conditional sections in prompts with {{#if}} blocks

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Security Considerations
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

git clone https://github.com/your-username/mcp-this.git
cd mcp-this
uv sync

curl -LsSf https://astral.sh/uv/install.sh | sh

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "my-tools": {
      "command": "uvx",
      "args": ["mcp-this", "--config-path", "/path/to/my-tools.yaml"]
    }
  }
}

| Method | Usage | Example |
|--------|--------|---------|
| YAML File | --config-path <path> | --config-path ./my-tools.yaml |
| JSON String | --config-value <json> | --config-value '{"tools":{...}}' |
| Environment Variable | MCP_THIS_CONFIG_PATH | export MCP_THIS_CONFIG_PATH=./tools.yaml |
| Built-in Preset | --preset <n> | --preset default |

from mcp import ClientSession, StdioServerParameters
from mcp.client.stdio import stdio_client

server_params = StdioServerParameters(
command='uvx',
args=['mcp-this', '--config-path', '/path/to/tools.yaml'],
)

async with stdio_client(server_params) as (read, write):
async with ClientSession(read, write) as session:
await session.initialize()

uvx mcp-this --config-path ./my-tools.yaml

Create my-tools.yaml:

tools:
  web-scraper:
    description: Fetch a webpage and convert it to clean, readable text
    execution:
      command: curl -s '<<url>>' | lynx -dump -stdin
    parameters:
      url:
        description: URL of the webpage to fetch
        required: true

find-large-files:
description: Find files larger than specified size in a directory
execution:
command: find '<<directory>>' -type f -size +<<size>> -exec ls -lh {} \;
parameters:
directory:
description: Directory to search
required: true
size:
description: Minimum file size (e.g., 100M, 1G)
required: true

prompts:
summarize-webpage:
description: Generate a structured summary of webpage content
template: |
Please analyze the following webpage content and provide:

1. Main Topic: What is this page about?
2. Key Points: {{num_points}} most important points
3. Target Audience: Who is this content for?
{{#if focus}}4. {{focus}} Analysis: Specific insights about {{focus}}{{/if}}

Content:
{{content}}
arguments:
content:
description: Webpage content to summarize
required: true
num_points:
description: Number of key points to extract (default 5)
required: false
focus:
description: Specific aspect to focus on (e.g., technical, business, educational)
required: false

file-analysis:
description: Analyze files for specific purposes
template: |
Analyze the following files for {{analysis_type}}:

{{#if criteria}}Focus on: {{criteria}}{{/if}}

{{files}}

Please provide:
- Summary of findings
- Recommendations
- {{#if format}}Output in {{format}} format{{/if}}
arguments:
files:
description: File contents or paths to analyze
required: true
analysis_type:
description: Type of analysis (security, performance, quality, etc.)
required: true
criteria:
description: Specific criteria or standards to check against
required: false
format:
description: Output format (markdown, JSON, report, etc.)
required: false


Using Prompts in Claude Desktop:
1. Click the + icon in the message input
2. Select "Add from mcp-this-custom"
3. Choose your prompt (e.g., "summarize-webpage")
4. Fill in the arguments - Claude will guide you through the required and optional fields

yaml
tools:
tool-name:
description: "Description with usage examples"
execution:
command: "command-template <<parameter1>> <<optional_param>>"
parameters:
parameter1:
description: "Parameter description"
required: true
optional_param:
description: "Optional parameter description"
required: false

Key Points:
- Use <<parameter>> placeholders in commands
- Parameters marked required: false are removed from commands if not provided
- Use command: >- for multi-line commands (not command: |)

For convenience, mcp-this includes ready-to-use collections of tools and prompts:

- default - Safe, read-only tools (file exploration, web scraping)
- editing - File manipulation tools (create, edit, delete)
- github - GitHub integration tools (PR analysis, repository operations) + specialized prompts (code-review, create-pr-description)

Quick usage:

json
{
"mcpServers": {
"mcp-this": {
"command": "uvx",
"args": ["mcp-this", "--preset", "default"]
}
}
}

> See README_PRESETS.md for complete preset documentation, tool lists, dependencies, and advanced setup.

---

yaml
tools:
git-status-summary:
description: Get a concise overview of git repository status
execution:
command: >-
echo "=== Branch ===" && git branch --show-current &&
echo "=== Status ===" && git status --porcelain &&
echo "=== Recent Commits ===" && git log --oneline -5
parameters: {}

test-runner:
description: Run tests with optional pattern matching
execution:
command: >-
if [ -n "<<pattern>>" ]; then
npm test -- --grep "<<pattern>>"
else
npm test
fi
parameters:
pattern:
description: Test pattern to match (optional)
required: false

docker-container-logs:
description: Get logs from a Docker container
execution:
command: docker logs <<container_name>> --tail <<lines>>
parameters:
container_name:
description: Name or ID of the Docker container
required: true
lines:
description: Number of log lines to show (default 100)
required: false
default: "100"


yaml
tools:
port-checker:
description: Check what process is using a specific port
execution:
command: lsof -i :<<port>>
parameters:
port:
description: Port number to check
required: true

service-status:
description: Check the status of a system service
execution:
command: systemctl status <<service_name>>
parameters:
service_name:
description: Name of the service to check
required: true

disk-usage-analyzer:
description: Analyze disk usage and find largest directories
execution:
command: >-
echo "=== Disk Usage Summary ===" &&
df -h <<path>> &&
echo "=== Largest Directories ===" &&
du -h <<path>> | sort -hr | head -10
parameters:
path:
description: Path to analyze (default current directory)
required: false
default: "."


---

tools = await session.list_tools()
print([tool.name for tool in tools.tools])

result = await session.call_tool(
'git-status-summary',
{}
)
print(result.content[0].text)

---

uvx mcp-this --config-path ./my-tools.yaml
```

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "security considerations": {
            "mcp-this": {
                "command": "uvx",
                "args": [
                    "mcp-this",
                    "--config-path",
                    "./my-tools.yaml"
                ]
            }
        }
    }
}

McpServers

{
    "mcp-this": {
        "command": "uvx",
        "args": [
            "mcp-this",
            "--config-path",
            "./my-tools.yaml"
        ]
    }
}

⚠️ Important: mcp-this executes shell commands based on your configuration. Always:

- Use trusted configuration files only
- Validate user inputs in production environments
- Run with minimal necessary privileges
- Consider containerization for additional security
- Review commands for dangerous operations

See the Security section for detailed security guidance.

---

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.