Atlas / MCP servers / 001tmf / Blatant Why

Blatant WhyBLOCK

mcp/001tmf/blatant-why

AI-powered biologics design campaign agent — multi-agent orchestration with BoltzGen, PXDesign, Protenix, and 200+ cloud tools. Antibodies, nanobodies, de novo binders, and beyond.

Verdict
BLOCK
Grade
D
Trust score
68 /100
Exposed tools
83 64r · 19w · 0d
Transport
—
License
MIT
Stars
117
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Open-source protein design agent for Claude Code

Commercial platforms wrap open-source tools behind paywalls and call it a revolution. BY gives you direct access through Claude Code. No platform fees. Your tools, your compute, your designs.

Source: trust us bro

Quick Start (5 minutes)

You don't need to be a developer. If you can open a terminal and paste commands, you can run BY.

1. Install prerequisites

2. Create your project

mkdir my-campaign && cd my-campaign
npx blatant-why i
Read from source at commit 8e920143c13bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add blatant-why --env ADAPTYV_API_KEY=${ADAPTYV_API_KEY} --env ADAPTYV_API_TOKEN=${ADAPTYV_API_TOKEN} --env PROTEUS_SSH_KEY=${PROTEUS_SSH_KEY} --env RUNPOD_API_KEY=${RUNPOD_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "blatant-why": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ADAPTYV_API_KEY": "${ADAPTYV_API_KEY}",
        "ADAPTYV_API_TOKEN": "${ADAPTYV_API_TOKEN}",
        "PROTEUS_SSH_KEY": "${PROTEUS_SSH_KEY}",
        "RUNPOD_API_KEY": "${RUNPOD_API_KEY}"
      }
    }
  }
}
03

Exposed tools (83)

64 read · 19 write · 0 destructive.

ToolRiskDescription
adaptyv_confirm_submissionwriteConfirm and submit a previously prepared lab submission.
adaptyv_estimate_costreadEstimate the cost of an Adaptyv Bio experiment.
adaptyv_get_experiment_statusreadCheck the status of an Adaptyv Bio experiment.
adaptyv_get_resultsreadRetrieve results for a completed Adaptyv Bio experiment.
adaptyv_prepare_submissionreadPrepare a lab submission to Adaptyv Bio for review.
campaign_add_roundwriteAdd a new design-screen-rank round to the campaign.
campaign_createwriteCreate a new campaign with directory structure and initial state.
campaign_export_csvreadExport all scored campaign designs as CSV.
campaign_export_fastareadExport campaign design sequences as FASTA.
campaign_generate_visualizationreadGenerate a PyMOL (.pml) or ChimeraX (.cxc) visualization script.
campaign_getreadRead the full campaign state from disk.
campaign_get_cost_estimatereadGet an estimated cost breakdown for a campaign.
campaign_get_decisionsreadRetrieve all decisions from the campaign audit trail.
campaign_get_summaryreadGet an aggregated summary of a campaign.
campaign_log_decisionreadRecord a decision in the campaign audit trail.
campaign_record_scoreswriteRecord design scores for a specific run.
campaign_suggest_next_roundreadSuggest optimised parameters for the next design round using active learning.
campaign_update_roundwriteUpdate a specific run within a campaign round.
campaign_update_statuswriteAdvance the campaign to a new status.
cloud_estimate_costreadEstimate cost and quota impact BEFORE submitting compute jobs.
cloud_get_batch_statusreadGet the status of all jobs in a batch.
cloud_get_resultsreadDownload results from a completed job.
cloud_get_statusreadGet the status of a single compute job.
cloud_list_providersreadList available compute providers with status, quota, and capability details.
cloud_submit_batchwriteSubmit multiple jobs respecting concurrency limits.
cloud_submit_jobwriteSubmit a single compute job to a cloud provider.
cloud_wait_batchreadPoll until all jobs in a batch complete or timeout.
interpret_scoresreadProvide human-readable interpretation of structure/binding scores.
knowledge_consolidatewriteRun a maintenance cycle on the knowledge base.
knowledge_get_recommendationsreadGet pre-campaign parameter recommendations.
knowledge_query_similarreadFind similar past campaigns using keyword search with MMR diversity re-ranking.
knowledge_scaffold_rankingsreadGet best-performing scaffolds for a target class.
knowledge_store_campaignreadStore a completed campaign outcome in the knowledge base.
knowledge_store_failurereadStore a campaign failure for future avoidance queries.
local_detect_gpureadCheck local GPU availability via nvidia-smi.
local_detect_toolsreadCheck which BY tools are installed locally.
local_run_boltzgenwriteRun BoltzGen locally for antibody/nanobody design.
local_run_protenixwriteRun Protenix locally for structure prediction.
local_run_pxdesignwriteRun PXDesign locally for de novo protein binder design.
pdb_downloadreadDownload a PDB structure file.
pdb_fetch_structurereadGet metadata for a PDB entry.
pdb_get_chainsreadList chains (polymer entities) in a PDB structure.
pdb_interface_residuesreadFind interface residues between two chains in a PDB structure.
pdb_searchreadSearch the RCSB Protein Data Bank by text query.
research_analyze_known_bindersreadSearch SAbDab for known antibodies against a target.
research_check_noveltyreadCheck a design sequence for novelty against known SAbDab antibodies.
research_find_similar_targetsreadFind proteins similar to a given UniProt accession.
research_get_target_inforeadGet combined UniProt and PDB information for a target protein.
research_search_prior_artreadSearch PubMed and bioRxiv for prior art on a target.
sabdab_cdr_sequencesreadGet CDR (Complementarity-Determining Region) sequences for an antibody structure.
sabdab_get_structurereadGet antibody structure summary from SAbDab.
sabdab_search_antibodiesreadSearch SAbDab for antibody structures.
sabdab_search_by_antigenreadFind antibodies targeting a specific antigen in SAbDab.
score_ipsaereadCompute ipSAE scores from a Protenix NPZ output file.
score_ipsae_multi_seedreadScore ipSAE across multiple Protenix seed outputs and select the best seed.
screen_align_sequencesreadAlign protein sequences for candidate comparison.
screen_compositewriteRun the full BY screening battery on a design.
screen_cross_validatereadCross-validate designs using dual structure predictor scores.
screen_developabilityreadTAP-inspired developability assessment for an antibody sequence.
screen_diagnose_failuresreadDiagnose why a design campaign has a low hit rate.
screen_diversitywriteAnalyze sequence diversity of a candidate set.
screen_liabilitiesreadScan a protein sequence for PTM liabilities.
screen_naturalnessreadScore antibody sequence naturalness using AbLang2.
screen_net_chargereadEstimate the net charge of a protein sequence at a given pH.
screen_pareto_frontwriteExtract Pareto-optimal designs from a candidate set.
screen_shape_complementarityreadCompute interface shape complementarity metrics from a PDB/CIF structure.
ssh_detect_gpu_remotereadCheck GPU availability on a remote SSH server.
ssh_detect_tools_remotereadCheck which BY tools are installed on a remote SSH server.
ssh_run_jobwriteRun a BY design job on a remote GPU server via SSH.
tamarind_get_jobreadGet a specific Tamarind Bio job by name.
tamarind_list_filesreadList files uploaded to Tamarind Bio.
tamarind_list_jobsreadList all jobs on Tamarind Bio with their status and results.
tamarind_list_toolsreadList all available tools on Tamarind Bio with their settings schemas.
tamarind_screen_developabilityreadScreen an antibody/nanobody sequence for developability.
tamarind_screen_naturalnessreadScreen antibody sequences for naturalness using AbLang2.
tamarind_submit_batchwriteSubmit a batch of jobs to Tamarind Bio (same tool, multiple inputs).
tamarind_submit_jobwriteSubmit a compute job to Tamarind Bio.
tamarind_upload_filewriteUpload a file to Tamarind Bio for use in jobs.
tamarind_wait_for_jobreadPoll a Tamarind Bio job until completion or timeout.
uniprot_fetch_proteinreadFetch full protein record from UniProt by accession.
uniprot_get_domainsreadGet domain and region annotations for a UniProt protein.
uniprot_get_variantsreadGet known variants and mutagenesis annotations for a UniProt protein.
uniprot_searchreadSearch UniProt by text, gene name, or organism.
04

Trust audit

BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
templates/.claude/skills/protenix/scripts/protenix_fold.py:213
_fail("`protenix` binary disappeared between which() and exec()")
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
templates/.claude/agents/by-lab.md:127
- **MUST NOT** bypass any safety gate for any reason, including `bypassPermissions`.
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
templates/.claude/skills/by-hypothesis-debate/SKILL.md:491
- [references/agent-profiles.md](references/agent-profiles.md) — Full directive templates for Conservative, Aggressive, and Diverse hypothesis agents. Includes what each agent is told to weight, what
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
templates/.claude/skills/by-knowledge/SKILL.md:183
Direct file writes bypass the atomic-rename safety, skip validation, and break
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/skill-creator
.claude/skills/skill-creator
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
templates/.claude/skills/by-deploy-compute/scripts/runpod_deploy.py:391
print(f"✓ RUNPOD_API_KEY present (len={len(api_key)})")
MEDIUMObfuscation / stealth · review.concealment · CWE-506, CWE-94
templates/.claude/commands/by/plan-campaign.md
Always use the Agent tool so the raw JSON stays hidden.
Why it matters. The instruction explicitly directs the agent to hide raw MCP tool output from the user by routing it through an intermediary Agent tool call, concealing what the agent is actually doing.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/.gitignore-append
.gitignore-append
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, tsx, typescript, @anthropic-ai/claude-agent-sdk
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
assets/banner.png
assets/banner.png
Why it matters. 1347221 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
templates/.claude/agents/by-environment.md:3
description: Discover available tools, compute providers, GPU access, API keys, and configuration. Produces structured environment.json for use by all other agents.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/LOCAL_GPU_SETUP.md:48
# Add to ~/.bashrc or .env
Why it matters. instructs the agent to persist itself in the user's environment
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
templates/.claude/skills/by-deploy-compute/references/runpod-setup.md:19
# add to ~/.zshrc or ~/.bashrc to persist
Why it matters. instructs the agent to persist itself in the user's environment
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:40
| **uv** | `curl -LsSf https://astral.sh/uv/install.sh \| sh` | `uv --version` |

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 8e920143c13bfull audit observations/trust-audit/mcp-server/001tmf__blatant-why.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078e920143c13bBLOCKD68first audit
06

Questions

What is the Blatant Why MCP server?

AI-powered biologics design campaign agent — multi-agent orchestration with BoltzGen, PXDesign, Protenix, and 200+ cloud tools. Antibodies, nanobodies, de novo binders, and beyond.

What tools does Blatant Why expose?

83 in total: 64 read-only, 19 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Blatant Why safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (68/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Blatant Why need?

It reads ADAPTYV_API_KEY, ADAPTYV_API_TOKEN, PROTEUS_SSH_KEY, RUNPOD_API_KEY and TAMARIND_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (8e920143c13b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement