by agentfront
TypeScript-first framework for the Model Context Protocol (MCP). You write clean, typed code; FrontMCP handles the protocol, transport, DI, session/auth, and execution flow.
# Add to your Claude Code skills
git clone https://github.com/agentfront/frontmcpGuides for using mcp servers skills like frontmcp.
Last scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T16:12:00.585Z",
"npmAuditRan": false,
"pipAuditRan": true
}frontmcp is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by agentfront. TypeScript-first framework for the Model Context Protocol (MCP). You write clean, typed code; FrontMCP handles the protocol, transport, DI, session/auth, and execution flow. It has 147 GitHub stars.
Yes. frontmcp passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/agentfront/frontmcp" and add it to your Claude Code skills directory (see the Installation section above).
frontmcp is primarily written in TypeScript. It is open-source under agentfront on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh frontmcp against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The production-grade, TypeScript-first framework for building MCP servers — decorators, DI, auth, and Streamable HTTP, batteries included.
Docs • Quickstart • API Reference • Discord
FrontMCP turns the Model Context Protocol into a
typed, declarative framework. You write clean @Tool, @Resource, and @App
classes; FrontMCP handles the protocol, transport, dependency injection, sessions,
auth, and execution flow — and the same server runs locally and ships to
production unchanged.
import 'reflect-metadata';
import { FrontMcp, LogLevel } from '@frontmcp/sdk';
import HelloApp from './hello.app';
@FrontMcp({
info: { name: 'Demo', version: '0.1.0' },
apps: [HelloApp],
http: { port: 3000 },
logging: { level: LogLevel.Info },
})
export default class Server {}
Node.js 24+ required.
# New project (recommended)
npx frontmcp create my-app
# Existing project
npm i -D frontmcp @types/node@^24
npx frontmcp init
Full setup guide: Installation · Quickstart
Build — decorator-configured @FrontMcp server and @App
domains; typed @Tool, @Resource, and
@Prompt primitives; @Agent multi-step chains; and
scoped [Providers / DI][docs-providers].
Secure — [Remote & Local OAuth, JWKS, DCR, per-app auth][docs-auth] with stateful / stateless sessions (JWT or UUID transport IDs).
Connect & operate — [Streamable HTTP + SSE transport][docs-transport],
every [MCP protocol revision][docs-protocol] from 2024-11-05 through
2026-07-28 on one endpoint, capability [discovery][docs-discovery],
elicitation, [hooks][docs-hooks], HTTP-discoverable
[skills][docs-skills], [tool UI / MCP Apps][docs-ext-apps], an in-process
[Direct Client][docs-direct] (connectOpenAI / connectClaude), and
first-class [deployment][docs-deploy].
Extend & tooling — official [plugins][docs-plugins] (Cache, Remember, CodeCall,
Dashboard), the [OpenAPI adapter][docs-adapters], a [UI library][docs-ui] (HTML/React
widgets, SSR, MCP Bridge), an [E2E testing framework][docs-testing], and a
CLI (create, init, dev, build, inspect, doctor).
→ Full reference: docs.agentfront.dev/frontmcp
You install frontmcp (the CLI) and @frontmcp/sdk. Everything else is either
pulled in for you or opt-in.
| Package | Description |
|---|---|
frontmcp |
The CLI — create, init, dev, build, inspect, doctor |
@frontmcp/sdk |
Core framework — decorators, DI, flows, transport, MCP protocol |
@frontmcp/auth |
Authentication, OAuth, JWKS, DCR/CIMD, credential vault |
@frontmcp/testing |
E2E test framework with fixtures and matchers |
| Package | Description |
|---|---|
@frontmcp/plugins |
Plugin authoring toolkit + official plugin re-exports |
@frontmcp/adapters |
OpenAPI adapter — generate tools from an OpenAPI spec |
@frontmcp/skills |
Curated SKILL.md catalog for scaffolding and skills install |
@frontmcp/guard |
Policy/guard rules for tool inputs and outputs |
@frontmcp/observability |
Structured logging, metrics, and tracing helpers |
| Package | Description |
|---|---|
@frontmcp/react |
React hooks + client for talking to a FrontMCP server |
@frontmcp/ui |
React components, SSR renderers, MCP Bridge |
@frontmcp/uipack |
React-free themes, build tools, platform adapters |
| Package | Description |
|---|---|
@frontmcp/edge |
Run a server on Cloudflare Workers / V8 isolates from a config |
@frontmcp/storage-sqlite |
SQLite-backed session, task, and elicitation stores |
@frontmcp/nx |
Nx generators and executors for FrontMCP workspaces |
Published so the packages above resolve, but not intended for direct use:
| Package | Description |
|---|---|
@frontmcp/protocol |
The single boundary to the upstream MCP SDK — protocol types |
@frontmcp/di |
Dependency injection container |
@frontmcp/utils |
Shared utilities — naming, URI, crypto, FS |
@frontmcp/lazy-zod |
Lazily-loaded Zod wrapper that keeps cold starts small |
| Package | Description |
|---|---|
@frontmcp/plugin-cache |
Cache tool results with a TTL |
@frontmcp/plugin-remember |
Per-session memory (this.remember) |
@frontmcp/plugin-approval |
Human approval gates before a tool runs |
@frontmcp/plugin-codecall |
Let the model compose tool calls as code |
@frontmcp/plugin-dashboard |
Built-in web dashboard |
@frontmcp/plugin-feature-flags |
Toggle tools and apps at runtime |
@frontmcp/plugin-skilled-openapi |
OpenAPI → skills + meta-tools for large APIs |
Keep all @frontmcp/* packages on the same version. A clear "version mismatch" error is thrown at boot if versions drift. ([Production Build][docs-production])
PRs welcome! See CONTRIBUTING.md for workflow, coding standards, and the PR checklist.