Kitsune MCP Server

The shape-shifting MCP hub — shapeshift() into 130,000+ MCP servers at runtime. One entry point, no restarts, 7 registries.

Remote serverstreamable-httpPython

What is the Kitsune MCP MCP server?

The shape-shifting MCP hub — shapeshift into 130,000+ MCP servers at runtime. One entry point, no restarts, 7 registries. Exposed over MCP by the kitsune mcp mcp server, that capability becomes something an assistant can invoke while it works, not something you go and do afterwards.

What it actually does

🦊 Kitsune MCP The agent harness for MCP.

  • Docker ≠ kernel boundary. — Hardened flags blunt escalation / fork bombs / FS tampering; not a guarantee against container escape. No default non-root / --network none (most servers need egress)
  • TOFU ≠ digest pin. — Pins a version, not a content hash. github: / git+ / hand-written connect commands aren't pinned. High assurance: pin by digest or vendor
  • Tools first. — Resource/prompt proxying is narrower (URI templates skipped; HTTP path differs). "Any server" means tool execution

Its toolset

Everything the assistant can do here goes through one of these:

  • Try-before-you-trust — confirm=True + Docker cage on by default + TOFU pins
  • Client — Config file
  • Source — Transport
  • PyPI — uvx (local; optional Docker sandbox)
  • GitHub — npx github:user/repo or uvx --from git+…
  • WebSocket — ws:// / wss://
  • Registry — Auth
  • Tier — Sources
  • High — official
  • Medium — mcpregistry, glama, smithery
  • Community — npm, pypi, github, local connect
  • Transport — Cold start

Adding it to your client

Being a remote server, there is no local install. You register the endpoint with your client, authorise it once, and the tools appear.

Configuration

You will need 3 environment variables: KITSUNE_TOOLS, SMITHERY_API_KEY, BRAVE_API_KEY. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

When to reach for it

Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Kitsune MCP's toolset — Try-before-you-trust, Client, Source and 11 more — is a fair guide to whether it matches your workflow. It is maintained by kaiser-data; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against Kitsune MCP's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Caveats

  • Your data travels to the provider's service, so the usual questions apply about what you send and what they retain.
  • With 14 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Kitsune MCP.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the kitsune mcp mcp server does with a few real requests.

Available tools

ToolWhat it does
Try-before-you-trustconfirm=True + Docker cage on by default + TOFU pins
ClientConfig file
SourceTransport
PyPIuvx <package> (local; optional Docker sandbox)
GitHubnpx github:user/repo or uvx --from git+…
WebSocketws:// / wss://
RegistryAuth
TierSources
Highofficial
Mediummcpregistry, glama, smithery
Communitynpm, pypi, github, local connect()
TransportCold start
ServerAlways-on
mcp-server-time261

How to install the Kitsune MCP MCP server

{
  "mcpServers": {
    "kitsune": {
      "command": "npx",
      "args": ["-y", "kitsune-mcp"],
      "env": {
        "KITSUNE_TOOLS": "your-value",
        "SMITHERY_API_KEY": "your-value",
        "BRAVE_API_KEY": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

VariableDescriptionRequired
KITSUNE_TOOLSConfiguration value read at startup.Optional
SMITHERY_API_KEYCredential the server authenticates with.Yes
BRAVE_API_KEYCredential the server authenticates with.Yes

Example prompts to try

  • Use Kitsune MCP to Try-before-you-trust.
  • Use Kitsune MCP to Client.
  • Use Kitsune MCP to Source.

Frequently asked questions

It connects Kitsune MCP to MCP-compatible AI assistants such as Claude and Cursor, exposing 14 tools (Try-before-you-trust, Client, Source, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Kitsune MCP directly.