Skip to content
View buildwithabid's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report buildwithabid

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
buildwithabid/README.md

Hi, I'm Abid πŸ‘‹

I build production MCP servers β€” the kind where every write is previewed before it happens, confirmed when it matters, and recorded in a chain you can verify.

Not as a demo. I run one over live invoices, client prices and statutory filing deadlines every working day, which is how I learned most of what's below the hard way.


The worked example

🏠 housewarden β€” a guarded household-operations MCP server

31 tools. Reads are free; every mutating tool goes through one guard β€” a dry-run preview of exactly what will change, a human ask when the action is risky, execute-exactly-once, then an append to a hash-chained audit log. The web console uses the same path, so an assistant can never reach a weaker one than a person can.

npm run e2e drives it with a real MCP client and prints a pass/fail table, so you don't have to take my word for any of it. Streamable HTTP Β· self-hosted Β· MIT

Three-minute demo β€” real console, real MCP client, nothing mocked.


The tooling I built around MCP

Because running these in production surfaces problems nobody has tools for yet.

πŸ›‘οΈ mcp-shield Security scanner for MCP servers β€” finds what your tool surface exposes before someone else does
πŸ§ͺ mcp-testkit Testing framework for MCP servers Β· npm
πŸšͺ mcpgate Open-source MCP gateway β€” reverse proxy for MCP servers
πŸ”Ž mcp-audit Python security scanner for MCP servers
πŸ›’ shopify-mcp MCP server for the Shopify Admin API

Something I got wrong, written up

Every 21 minutes: my self-healing monitor took my business phone line down for two days

A repair loop that couldn't tell broken from a human is part-way through fixing it, a monitor that trusted its own cache over the service, and active (running) answering a question I wasn't asking. Four bugs, one shape: a system confidently answering something slightly different from what was asked.


Available for MCP work

Tool surface reviews, production builds, and keeping them running afterwards.

Scope and fixed prices: The Write Path

πŸ“¬ support@bizfilo.com


Also built

LLM developer tooling β€” llm-cost-profiler (spend visibility in two lines, pip install llm-spend-profiler), llm-bench (race providers in the terminal), ai-stability (measure output consistency, pipx install ai-stability).

Python TypeScript MCP Claude Code Anthropic API OpenAI API CLI tooling

Pinned Loading

  1. mcp-shield mcp-shield Public

    Security scanner for MCP (Model Context Protocol) servers. Detect prompt injection, secrets leaks, supply chain attacks, and vulnerabilities in MCP servers. CLI + MCP server mode.

    TypeScript 2

  2. mcp-testkit mcp-testkit Public

    Testing framework for MCP (Model Context Protocol) servers. Custom matchers, schema validation, fuzz testing, and snapshot support for vitest and jest.

    TypeScript 1

  3. mcpgate mcpgate Public

    Open-source MCP gateway β€” reverse proxy for Model Context Protocol servers with auth, rate limiting, access control, and observability

    TypeScript 1

  4. shopify-mcp shopify-mcp Public

    MCP server for Shopify Admin API - search orders, check inventory, lookup customers, get sales summaries

    TypeScript 1

  5. housewarden housewarden Public

    Household-operations MCP server: every mutating tool is dry-run, confirmed and audited. Streamable HTTP, MCP spec 2026-07-28. Built for Alexa+.

    TypeScript

  6. mcp-audit mcp-audit Public

    Python security scanner for Model Context Protocol (MCP) servers β€” find prompt injection, over-broad permissions, weak input validation, and credential leaks before your AI agent does.

    Python