Back to Browse

Builtwithjon MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Read-only tools for finding where a small business leaks deals, time, and cash.

About

Read-only tools for finding where a small business leaks deals, time, and cash.

Remote endpoints: streamable-http: https://builtwithjon.com/mcp

Security Report

4.8
Use Caution4.8High Risk

This is a well-structured MCP server for a business consulting site with strong security practices. Authentication is appropriately scoped through environment variables, input validation is comprehensive, and the server only exposes read-only public content. Minor code quality observations around error handling and logging do not materially impact security. Supply chain analysis found 6 known vulnerabilities in dependencies (0 critical, 2 high severity).

4 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

builtwithjon.com

Personal site for Jonathan Malkin. AI builder, solo founder.

Built with Astro v6. Hosted on Cloudflare Workers as jonathanmalkin-site. Zero JavaScript by default.

Local Preview

From this repo:

npm run build
npm run preview

Deploy

Live deploys require both steps:

git push origin main
npm run build
find dist -name .DS_Store -delete
wrangler deploy

Do not pass --assets or --name. wrangler.jsonc owns the Worker and asset routing, including run_worker_first for the MCP endpoint. CLI asset flags can replace that configuration and cause static assets to intercept POST /mcp.

In the broader Active-Work workspace, use Scripts/deploy-website.sh to run the push, build, cleanup, and Wrangler deploy sequence.

GitHub push alone does not publish the live site.

IndexNow

After a deploy that changes one or more canonical, indexable pages, notify IndexNow with only those URLs:

npm run indexnow:submit -- https://builtwithjon.com/articles/example/

The script verifies that the deployed key file is live before it submits. Preview the exact bounded payload without any network call with:

npm run indexnow:submit -- --dry-run https://builtwithjon.com/articles/example/

It rejects other origins, query strings/fragments, and noindex/private routes. HTTP 200 means IndexNow received the notification; HTTP 202 means it received it and key validation is pending. Neither response guarantees that a search engine will index the URL.

See Also

Reviews

No reviews yet

Be the first to review this server!