‹ The Index

Helmet

npm

Production middleware for MCP servers. Auto transport, content wrapping, health checks, graceful shutdown, auth, rate limiting, structured request logging. Wraps the official Model Context Protocol SDK.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability

Category: Dev Tools & CI — see all ranked ›

Install (Claude Code):

claude mcp add helmet -- npx -y mcp-helmet

Security audit

scanned 2026-08-12

Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.

No known advisoriesclearchecked against OSV for 0.1.0-alpha.7
No access inferred from declared dependenciesnothing it depends on reaches files, shell or network. This reads declarations only — built-in APIs are invisible to it, so absence of a declaration is not absence of access
No build provenanceno attestation — the published artifact cannot be traced to its source

You searched for one. Check the rest of your stack:

npx tashan-cli doctor

Reads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.

tashan Pro$6/mo

Helmet scores 35 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down — and tells you the day it moves.

Start a 7-day trial › Everything measured on this page stays free.

Show your score

Measured this well? Put the live badge in your README — it updates as the score does.

tashan badge for Helmet
[![tashan](https://tashan.sh/badge/pkg-mcp-helmet.svg)](https://tashan.sh/capability/pkg-mcp-helmet.html)

npm ↗  ·  source ↗  ·  pkg:mcp-helmet

Everything on this page is public evidence and free. What it cannot know is whether you run this — npx tashan-cli doctor reads your own config and names what is wrong in it, also free. tashan Pro tells you the day any of it changes.

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›

Measured 2026-08-14  ·  scorer s5  ·  how  ·  something wrong here?