Atlas / MCP servers / 78 / Calculator

CalculatorBLOCK

mcp/78/calculator-5

Xiaozhi MCP sample program

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
—
Stars
447
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful interface for extending AI capabilities through remote control, calculations, email operations, knowledge search, and more.

一个强大的接口,用于通过远程控制、计算、邮件操作、知识搜索等方式扩展AI能力。

Overview | 概述

MCP (Model Context Protocol) is a protocol that allows servers to expose tools that can be invoked by language models. Tools enable models to interact with external systems, such as querying databases, calling APIs, or performing computations. Each tool is uniquely identified by a name and includes metadata describing its schema.

MCP(模型上下文协议)是一个允许服务器向语言模型暴露可调用工具的协议。这些工具使模型能够与外部系统交互,例如查询数据库、调用API或执行计算。每个工具都由一个唯一的名称标识,并包含描述其模式的元数据。

Features | 特性

  • 🔌 Bidirectional communication between AI and external tools | AI与外部工具之间的双向通信
  • 🔄 Automatic reconnection with exponential backoff | 具有指数退避的自动重连机制
  • 📊 Real-time data streaming | 实时数据流传输
  • 🛠️ Easy-to-use tool creation interface | 简单易用的工具创建接口
  • 🔒 Secure WebSocket communication | 安全的WebSocket通信
  • ⚙️ Multiple transport types support (stdio/sse/http) | 支持多种传输类型(stdio/sse/http)

Quick Start | 快速开始

  1. Install dependencies | 安装依赖:
pip install -r requirements.txt
  1. Set up environment variables | 设置环境变量:
export MCP_ENDPOINT=
  1. Run the calculator example | 运行计算器示例:
python mcp_pipe.py calculator.py

Or run all configured servers | 或运行所有配置的服务:

python mcp_pipe.py

Requires `mcp_config.json` configuration file with server definitions (supports stdio/sse/http transport types)

需要 `mcp_config.json` 配置文件定义服务器(支持 stdio/sse/http 传输类型)

Project Structure | 项目结构

  • mcp_pipe.py: Main communication pipe that handles WebSocket connections and process management | 处理WebSocket连接和进程管理的主通信管道
  • calculator.py: Example MCP tool implementation for mathematical calculations | 用于数学计算的MCP工具示例实现
  • requirements.txt: Project dependencies | 项目依赖

Config-driven Servers | 通过配置驱动的服务

编辑 mcp_config.json 文件来配置服务器列表(也可设置 MCP_CONFIG 环境变量指向其他配置文件)。

配

Read from source at commit 096241df41b6OBSERVED · 2026-10-01
02

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
calculatorreadFor mathamatical calculation, always use this tool to calculate the result of a python expression. You can use
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
calculator.py:23
result = eval(python_expression, {"math": math, "random": random})
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
python-dotenv, websockets, mcp, pydantic, mcp-proxy, fastmcp
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-01 · audit v0.4.1 · source sha 096241df41b6full audit observations/trust-audit/mcp-server/78__calculator-5.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01096241df41b6BLOCKD69first audit
05

Questions

What is the Calculator MCP server?

Xiaozhi MCP sample program

What tools does Calculator expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Calculator safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Calculator need?

No credential environment variables were found in its source, so it appears to need none.

How does Calculator run?

It speaks stdio and streamable-http, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (096241df41b6), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement