dharam-k/erpnext-mcp-server ? reverse-engineered prompt

Reverse engineered prompt

Build me a safe, read only MCP server for investigating an ERPNext or Frappe site.

I want it to connect to an ERPNext instance through the normal HTTP APIs, then help me inspect what is going on without letting it change anything. It should be able to discover the site version, look up DocTypes, fetch and search records, count things, inspect reports and logs, check permissions, analyze tracebacks, and generate an approval plan for anything that might be risky. It should also mask secrets, keep an audit trail, and reject direct SQL, shell access, migrations, and document edits.

If you can, add a simple admin page for viewing redacted settings and audit logs, plus a streamable HTTP mode for remote use with bearer auth. Keep the setup easy to run locally from environment variables, and make sure the code feels security first. If you need to check the latest MCP or Frappe docs while building it, go ahead and look them up online.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab