Atlas / MCP servers / allaboutai-yt / GPT-5

GPT-5SAFE

mcp/allaboutai-yt/gpt-5-1

GPT-5 Local MCP

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
—
Stars
80
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides seamless integration with OpenAI's GPT-5 API through Claude Code. This server enables you to leverage GPT-5's advanced capabilities directly within your Claude Code workflows.

🚀 Features

  • Direct GPT-5 Integration: Call GPT-5 API with simple prompts or structured conversations
  • Two Powerful Tools:
  • gpt5_generate: Simple text generation with prompts
  • gpt5_messages: Structured conversation handling with message arrays
  • Built for Claude Code: Optimized for seamless integration with Anthropic's Claude Code IDE
  • TypeScript Support: Fully typed for better development experience
  • Error Handling: Robust error handling with detailed feedback
  • Usage Tracking: Built-in token usage reporting

📋 Prerequisites

  • Node.js (v18 or higher)
  • OpenAI API key with GPT-5 access
  • Claude Code IDE

🛠 Installation

1. Clone the Repository

git clone https://github.com/AllAboutAI-YT/gpt5mcp.git
cd gpt5mcp

2. Install Dependencies

cd servers/gpt5-server
npm install

3. Build the Server

npm run build

4. Configure Environment Variables

Create a .env file in the servers directory:

# servers/.env
OPENAI_API_KEY=your-openai-api-key-here

🔧 Claude Code Integration

Add the Server to Claude Code

claude mcp add gpt5-server -e OPENAI_API_KEY=your-openai-api-key-here -- node /path/to/gpt5mcp/servers/gpt5-server/build/index.js

Verify Installation

Test the server with a simple query:

Ask GPT-5: "Hello, how are you today?"

📚 Available Tools

gpt5_generate

Generate text using a simple input prompt.

Parameters:

  • input (required): The text prompt for GPT-5
  • model (optional): GPT-5 model variant (default: "gpt-5")
  • instructions (optional): System instructions for the model
  • reasoning_effort (optional): Reasoning level ("low", "medium", "high")
  • `max_toke
Read from source at commit 4aa5e92d10d2OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add gpt5-server --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "gpt5-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
gpt5_generatereadGenerate text using OpenAI GPT-5 API with a simple input prompt
gpt5_messagesreadGenerate text using GPT-5 with structured conversation messages
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
servers/gpt5-server/src/index.ts:21
const envPath = path.join(__dirname, '../../.env');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
servers/gpt5-server/package.json
dotenv, node-fetch, zod, zod-to-json-schema, @types/node, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 4aa5e92d10d2full audit observations/trust-audit/mcp-server/allaboutai-yt__gpt-5-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-074aa5e92d10d2SAFEB89first audit
06

Questions

What is the GPT-5 MCP server?

GPT-5 Local MCP

What tools does GPT-5 expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is GPT-5 safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does GPT-5 need?

It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does GPT-5 run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as gpt5-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (4aa5e92d10d2), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement