CalculatorBLOCK
Xiaozhi MCP sample program
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A powerful interface for extending AI capabilities through remote control, calculations, email operations, knowledge search, and more.
一个强大的接口,用于通过远程控制、计算、邮件操作、知识搜索等方式扩展AI能力。
Overview | 概述
MCP (Model Context Protocol) is a protocol that allows servers to expose tools that can be invoked by language models. Tools enable models to interact with external systems, such as querying databases, calling APIs, or performing computations. Each tool is uniquely identified by a name and includes metadata describing its schema.
MCP(模型上下文协议)是一个允许服务器向语言模型暴露可调用工具的协议。这些工具使模型能够与外部系统交互,例如查询数据库、调用API或执行计算。每个工具都由一个唯一的名称标识,并包含描述其模式的元数据。
Features | 特性
- 🔌 Bidirectional communication between AI and external tools | AI与外部工具之间的双向通信
- 🔄 Automatic reconnection with exponential backoff | 具有指数退避的自动重连机制
- 📊 Real-time data streaming | 实时数据流传输
- 🛠️ Easy-to-use tool creation interface | 简单易用的工具创建接口
- 🔒 Secure WebSocket communication | 安全的WebSocket通信
- ⚙️ Multiple transport types support (stdio/sse/http) | 支持多种传输类型(stdio/sse/http)
Quick Start | 快速开始
- Install dependencies | 安装依赖:
pip install -r requirements.txt
- Set up environment variables | 设置环境变量:
export MCP_ENDPOINT=
- Run the calculator example | 运行计算器示例:
python mcp_pipe.py calculator.py
Or run all configured servers | 或运行所有配置的服务:
python mcp_pipe.py
Requires `mcp_config.json` configuration file with server definitions (supports stdio/sse/http transport types)
需要 `mcp_config.json` 配置文件定义服务器(支持 stdio/sse/http 传输类型)
Project Structure | 项目结构
mcp_pipe.py: Main communication pipe that handles WebSocket connections and process management | 处理WebSocket连接和进程管理的主通信管道calculator.py: Example MCP tool implementation for mathematical calculations | 用于数学计算的MCP工具示例实现requirements.txt: Project dependencies | 项目依赖
Config-driven Servers | 通过配置驱动的服务
编辑 mcp_config.json 文件来配置服务器列表(也可设置 MCP_CONFIG 环境变量指向其他配置文件)。
配
096241df41b6OBSERVED · 2026-10-01Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
calculator | read | For mathamatical calculation, always use this tool to calculate the result of a python expression. You can use |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
result = eval(python_expression, {"math": math, "random": random})python-dotenv, websockets, mcp, pydantic, mcp-proxy, fastmcp
Gates applied: no_behavioural_pass, no_license.
096241df41b6full audit observations/trust-audit/mcp-server/78__calculator-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | 096241df41b6 | BLOCK | D | 69 | first audit |
Questions
What is the Calculator MCP server?
Xiaozhi MCP sample program
What tools does Calculator expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Calculator safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Calculator need?
No credential environment variables were found in its source, so it appears to need none.
How does Calculator run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (096241df41b6), read on 2026-10-01. The repository is watched and re-audited when it changes.