mcpbeat Sign in

middleBrick MCP Server

by middlebrick Your server? Claim it
local only

middleBrick runs on your own machine — the client starts it, so there is no endpoint to ping. 24 installs a week from npm. Last commit 3 Apr 2026.

Scan APIs for OWASP Top 10, LLM, and GraphQL security vulnerabilities.

Installs per day peak 13 · avg 5 · -21% w/w
a month agotoday
24
Installs / week
npm · @middlebrick/mcp-server
0
Stars
0 open issues
3 Apr 2026
Last commit
0 releases in 90 days
Apache-2.0
License
TypeScript

Nothing serious here today

Today is the operative word: we check middleBrick every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add mcp-server -- npx -y @middlebrick/mcp-server
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp-server": {
      "args": [
        "-y",
        "@middlebrick/mcp-server"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.mcp-server]
command = "npx"
args = ["-y", "@middlebrick/mcp-server"]
.cursor/mcp.json
{
  "mcpServers": {
    "mcp-server": {
      "args": [
        "-y",
        "@middlebrick/mcp-server"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "mcp-server": {
      "args": [
        "-y",
        "@middlebrick/mcp-server"
      ],
      "command": "npx"
    }
  }
}

This one needs environment variables set before it will start: MIDDLEBRICK_API_KEY (Your middleBrick API key (get one at middlebrick.com)). The author declared them in the registry entry; get the values from the project itself.

Alternatives to middleBrick

same job, measured the same way
SecurityScan
by apisecurityscan

Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

8 tools answering
MCP Server Security Audit
by joepangallo

Scan websites for security vulnerabilities, headers, TLS, and email security.

35 installs/wk local only
ScanLabsAI Security Scanner
by scanlabsai

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

93 installs/wk 8 tools answering
Synapse Audit
by digidenone

AI-Powered Security Scanner for LLMs. Detects vulnerabilities and syncs with SynapseAudit.

28 installs/wk local only
Bug Detector
by madhavi-opsera

Analyzes code for bugs, security vulnerabilities, and code smells

local only
FinishKit
by finishkit

FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality

61 installs/wk local only
Scannd
by scannd

Trigger security scans and read reports/vulnerabilities via the hosted Scannd API. Free: 2 scans/mo.

54 installs/wk local only
I
Agent Security Scanner
by mikehzp

Scan AI agents for tool-calling vulnerabilities: prompt leaks, hijacking, injections, and more.

113 installs/wk local only

middleBrick — questions

Answers built from our own checks of this server.

Why is there no uptime for middleBrick?
middleBrick runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package @middlebrick/mcp-server was installed 24 times last week.
How do I connect middleBrick?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls @middlebrick/mcp-server straight from npm; nothing to host, nothing to sign up for.
How many people use middleBrick?
The npm package @middlebrick/mcp-server was installed 24 times in the last week. Week over week that is -21%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is middleBrick open source?
Yes — it is published under the Apache-2.0 licence, written in TypeScript and 0 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.