Back to Browse

Frasma MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Read-only Frasma MCP: profile, knowledge search, diagnostic handoff. No email.

About

Read-only Frasma MCP: profile, knowledge search, diagnostic handoff. No email.

Remote endpoints: streamable-http: https://www.frasma.org/api/mcp

Security Report

4.2
Use Caution4.2High Risk

This is a Next.js web application with MCP server capabilities for process diagnostics and service discovery. The codebase demonstrates reasonable security practices with proper environment variable handling for credentials, no hardcoded secrets in visible code, and appropriate permission scoping. Minor code quality issues and one informational finding about broad exception handling do not significantly impact the overall security posture. Permissions align well with the stated purpose of a diagnostic chatbot and service discovery tool. Supply chain analysis found 11 known vulnerabilities in dependencies (0 critical, 3 high severity).

4 files analyzed · 14 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

smithery badge

Frasma on Smithery

This is a Next.js project bootstrapped with create-next-app.

Getting Started

First, run the development server:

npm run dev
# or
yarn dev

Open http://localhost:3000 with your browser to see the result.

You can start editing the page by modifying pages/index.tsx. The page auto-updates as you edit the file.

API routes can be accessed on http://localhost:3000/api/hello. This endpoint can be edited in pages/api/hello.ts.

The pages/api directory is mapped to /api/*. Files in this directory are treated as API routes instead of React pages.

Process brief (quote request)

The landing form and the chat widget both submit a process brief to POST /api/request-process-assessment. Francesco uses that brief to prepare a quote.

Fields: name, work email, optional company and role, process (required), optional current tools and volume.

When MONGODB_URI is set, the same endpoint upserts users, inserts leads, and logs project_brief_submitted.

Required environment variables

Create a .env.local file in the project root with:

# Destination email (defaults to francemazzi@gmail.com)
MEETING_NOTIFICATION_EMAIL=francemazzi@gmail.com

# Sender identity (defaults to SMTP_USER if using SMTP)
MEETING_FROM_EMAIL=francemazzi@gmail.com

# Sender display name (defaults to "Frasma")
MEETING_FROM_NAME=Frasma

# --- Option A (recommended): Gmail SMTP via App Password ---
SMTP_HOST=smtp.gmail.com
SMTP_PORT=465
SMTP_SECURE=true
SMTP_USER=francemazzi@gmail.com
SMTP_PASS=your_gmail_app_password

# --- Option B: Resend ---
# RESEND_API_KEY=your_resend_api_key

Notes:

  • In production you should set these variables in your hosting provider (e.g. Vercel).
  • If neither SMTP nor Resend is configured, the API returns an error and the popup shows it to the user.

Diagnostic chat agent

The website chat is a process-diagnostic assistant. It uses the bilingual, versioned knowledge base in lib/knowledge/ to:

  • identify operational bottlenecks;
  • collect workflow, systems, volumes, baseline metrics, data, and constraints;
  • map the need to Frasma capabilities;
  • prepare an editable process brief;
  • submit that brief to POST /api/request-process-assessment only after explicit user review.

If the assistant times out, the widget shows the same process brief form, prefilled from the conversation history (no extra LLM call).

Each browser session stores a conversationId in localStorage. Messages are persisted server-side in MongoDB Atlas through the official Node.js driver. On reopen, the widget restores the conversation via GET /api/conversations/:id. If MongoDB is not configured, the chat keeps working in stateless mode.

Do not add prices, guaranteed savings, customer secrets, credentials, or personal data about third parties to the knowledge base or diagnostic examples.

Required OpenAI environment variable (chat agent + voice dictation on the process assessment form):

OPENAI_API_KEY=your_openai_api_key

# Optional; defaults to gpt-4o-mini
OPENAI_CHAT_MODEL=gpt-4o-mini

# Optional; defaults to whisper-1 (process assessment voice dictation)
OPENAI_WHISPER_MODEL=whisper-1

Chat persistence (MongoDB Atlas)

Persistence is optional but recommended in production. When configured, the API stores:

  • conversation metadata (lang, timezone, pagePath, conversion flags);
  • user and assistant messages;
  • conversion events from the process brief (project_brief_submitted).

Setup:

  1. Create a free M0 cluster on MongoDB Atlas (recommended region: Frankfurt or Ireland).
  2. Create a database user with read/write access.
  3. In Network Access, allow 0.0.0.0/0 (required for Vercel serverless).
  4. Copy the connection string and set these environment variables locally and on Vercel:
MONGODB_URI=mongodb+srv://user:pass@cluster.mongodb.net/frasma_chat?retryWrites=true&w=majority
CHAT_RETENTION_DAYS=90

Indexes and a TTL policy on conversations.expiresAt are created automatically on first use.

Without MONGODB_URI, POST /api/chat and the form APIs continue to work; persistence calls are skipped silently.

Verify the connection:

npm run check:mongodb
curl http://localhost:3000/api/status

Expected when configured correctly:

{
  "persistence": { "configured": true, "connected": true }
}

A successful chat response also includes conversationId.

MongoDB troubleshooting

  1. Network Access on Atlas must include 0.0.0.0/0 for Vercel serverless.
  2. The URI must include the database name: ...mongodb.net/frasma_chat?...
  3. If you reset the Atlas user password, update both .env.local and Vercel, then redeploy.
  4. URL-encode special characters in the password (@, #, %, etc.).
  5. After changing Vercel env vars, trigger a new deployment; env changes are not applied to existing deployments automatically.

AI discovery and public MCP

Public discovery surfaces for agents and humans:

MCP tools (read-only + handoff)

  • get_frasma_profile
  • search_frasma_knowledge
  • get_diagnostic_framework
  • prepare_diagnostic_summary — validates a diagnosis and returns handoff URLs; never sends email
  • prepare_project_brief — validates the process brief used for a quote; never sends email

Example Cursor / Claude Desktop remote config:

{
  "mcpServers": {
    "frasma": {
      "url": "https://www.frasma.org/api/mcp"
    }
  }
}

For stdio-only clients:

{
  "mcpServers": {
    "frasma": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://www.frasma.org/api/mcp"]
    }
  }
}

Directory listing (after production deploy)

  1. Confirm /for-agents, /servizi, /llms.txt, /llms-it.txt, and /api/mcp respond in production.
  2. Smoke: curl -H 'Accept: text/markdown' https://www.frasma.org/ and https://www.frasma.org/servizi/ddt-erp, plus an MCP initialize + tools/list against /api/mcp.
  3. Submit the server to relevant MCP directories with the short description from /for-agents (mention the services hub).
  4. Keep the agent-skills digest in sync when SKILL.md changes (shasum -a 256).

Quality checks:

npm run lint
npm test
npm run build

Learn More

To learn more about Next.js, take a look at the following resources:

You can check out the Next.js GitHub repository - your feedback and contributions are welcome!

Deploy on Vercel

The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.

Check out our Next.js deployment documentation for more details.

Reviews

No reviews yet

Be the first to review this server!