Search / io.github.Abhishekkumar2021/http
HTTP
L0 · runs locallyHTTP/REST client with saved collections, env secrets, and SSRF-safe host allowlisting.
v0.1.0 · active · repository · website · descriptor JSON · versions
Search / io.github.Abhishekkumar2021/http
HTTP/REST client with saved collections, env secrets, and SSRF-safe host allowlisting.
v0.1.0 · active · repository · website · descriptor JSON · versions
{
"mcpServers": {
"http": {
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"HTTP_ALLOW_HOSTS": "${HTTP_ALLOW_HOSTS}"
}
}
}
}claude mcp add http -e "HTTP_ALLOW_HOSTS=${HTTP_ALLOW_HOSTS}" -- npx -y @abhishekmcp/[email protected][mcp_servers.http]
command = "npx"
args = ["-y", "@abhishekmcp/[email protected]"]
env = { "HTTP_ALLOW_HOSTS" = "${HTTP_ALLOW_HOSTS}" }
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"http": {
"type": "local",
"command": [
"npx",
"-y",
"@abhishekmcp/[email protected]"
],
"enabled": true,
"environment": {
"HTTP_ALLOW_HOSTS": "{env:HTTP_ALLOW_HOSTS}"
}
}
}
}{
"mcpServers": {
"http": {
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"HTTP_ALLOW_HOSTS": "${HTTP_ALLOW_HOSTS}"
}
}
},
"deeplink": "cursor://anysphere.cursor-deeplink/mcp/install?name=http&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBhYmhpc2hla21jcC9odHRwQDAuMS4wIl0sImVudiI6eyJIVFRQX0FMTE9XX0hPU1RTIjoiJHtIVFRQX0FMTE9XX0hPU1RTfSJ9fQ%3D%3D"
}{
"servers": {
"http": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"HTTP_ALLOW_HOSTS": "${HTTP_ALLOW_HOSTS}"
}
}
}
}{
"mcpServers": {
"http": {
"command": "npx",
"args": [
"-y",
"@abhishekmcp/[email protected]"
],
"env": {
"HTTP_ALLOW_HOSTS": "${HTTP_ALLOW_HOSTS}"
}
}
}
}extensions:
"http":
enabled: true
name: "http"
type: stdio
cmd: "npx"
args:
- "-y"
- "@abhishekmcp/[email protected]"
envs:
"HTTP_ALLOW_HOSTS": "${HTTP_ALLOW_HOSTS}"
timeout: 300
This is a local package: the command runs on your machine.
Not scored: fewer than three checks apply, usually because no remote answered a credential-free probe or the server is a local package.
protocol.modern, protocol.stateless, protocol.transport, protocol.list_ttlno remote answered a protocol handshake (not probed yet, unreachable, or local-only)auth.prm, auth.as_metadata, auth.cimdno remote uses OAuthauth.secret_in_urlno templated URLtools.descriptions, tools.description_length, tools.schemas, tools.annotations, tools.directory_hints, tools.token_cost, tools.api_dumptool list unknown (behind auth, not probed, or empty)stability.changes, stability.rug_pulltool list unknowndeps.known_vulnsno known advisory in 98 resolved packagesdeps.mcp_sdk_version@modelcontextprotocol/sdk 1.30.1 has 1 known advisory (GHSA-6qxp-vccf-f47h); update @modelcontextprotocol/sdk to 1.31.0 or laterdeps.resolvable@abhishekmcp/[email protected] resolved: 98 packagesNo tool definition changes recorded. A server's first observation is its baseline; later probes record what changes.
Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed. How it is computed.
+repository +namespace-matches-repo +website ~liveness-unmeasured ~updated-97d-ago -duplicate-repo(6 names)
Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed. How it is computed.
@abhishekmcp/[email protected] npm97 dependencies, resolved · MCP SDK @modelcontextprotocol/sdk 1.30.1 · advisories checked 2026-10-09
| advisory | severity | package | fixed in |
|---|---|---|---|
| GHSA-6qxp-vccf-f47hMCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server | high | @modelcontextprotocol/[email protected]MCP SDK, direct | fixed in 1.31.0 |
Dependency graphs from deps.dev; advisories from OSV.dev, including the GitHub Advisory Database and the PyPI Advisory Database; all CC BY 4.0. The graph is what a clean install of this version resolves today; nothing was installed or run. How it is checked.
| package | registry | version | runtime | secrets |
|---|---|---|---|---|
@abhishekmcp/http | npm | 0.1.0 | npx |
No tools observed. Local packages are never executed by the registry.
Schemas: list_tools.
5 other active names share this repository: io.github.Abhishekkumar2021/files, io.github.Abhishekkumar2021/git, io.github.Abhishekkumar2021/github, io.github.Abhishekkumar2021/notes, io.github.Abhishekkumar2021/sql
{
"name": "io.github.Abhishekkumar2021/http",
"title": "HTTP",
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"version": "0.1.0",
"packages": [
{
"version": "0.1.0",
"transport": {
"type": "stdio"
},
"identifier": "@abhishekmcp/http",
"runtimeHint": "npx",
"registryType": "npm",
"environmentVariables": [
{
"name": "HTTP_ALLOW_HOSTS",
"format": "string",
"isRequired": true,
"description": "Comma-separated allowed hosts (exact or *.example.com). Required — the server refuses to start without it."
},
{
"name": "HTTP_WRITABLE",
"format": "string",
"description": "Set to 1 or true to allow mutating methods (POST/PUT/PATCH/DELETE)."
}
]
}
],
"repository": {
"url": "https://github.com/Abhishekkumar2021/mcp-suite",
"source": "github"
},
"websiteUrl": "https://github.com/Abhishekkumar2021/mcp-suite/tree/main/servers/http#readme",
"description": "HTTP/REST client with saved collections, env secrets, and SSRF-safe host allowlisting."
}