AnylistCAUTION
Unofficial MCP Server for Anylist
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server that integrates with AnyList — shopping lists, recipes, and meal planning — exposed via the Model Context Protocol. Works with Claude Desktop, Claude Code, Claude Web/Mobile, or any MCP-compatible client like Home Assistant.
Two deployment modes:
- Local (stdio) — runs on your machine alongside Claude Desktop or Claude Code. Fastest setup, no server required.
- HTTP server — runs in Docker behind a Cloudflare Tunnel. Required for Claude Web, Claude Mobile, or home assistant and useful for sharing access across devices or users.
Tools Overview
The MCP server provides 5 domain-grouped tools rather than 18+ individual ones:
- shopping — Manage shopping lists and items: add, check off, delete, organize by category and store, and browse favorites
- recipes — Browse, create, and import recipes from URLs; includes ingredient and step parsing
- meal_plan — Schedule meals on a calendar with optional links to recipes
- recipe_collections — Organize recipes into curated named collections
- health_check — Verify your connection to AnyList and access to target lists
These tools work together to enable typical workflows: browse or create recipes → plan meals → add ingredients to your shopping list. See docs/tools.md for the complete reference including all actions and parameters.
Installation: Claude Desktop
The fastest way to get started is to download the latest anylist-mcp.mcpb from the releases page.
- Open Claude Desktop → Settings → Extensions
- Drag and drop the
.mcpbfile, or click "Advanced settings" → Install extension - Enter your configuration when prompted:
- AnyList Email — your AnyList account email
- AnyList Password — your AnyList account password
- Default Shopping List — optional, defaults to "Groceries"
Installation: Claude Code / Claude Desktop (from source)
###
1c1351b2ec76OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add anylist-mcp --env ANYLIST_PASSWORD=${ANYLIST_PASSWORD} --env SERVER_SECRET_KEY=${SERVER_SECRET_KEY} --env SESSION_SECRET=${SESSION_SECRET} -- npx -y [email protected]{
"mcpServers": {
"anylist-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANYLIST_PASSWORD": "${ANYLIST_PASSWORD}",
"SERVER_SECRET_KEY": "${SERVER_SECRET_KEY}",
"SESSION_SECRET": "${SESSION_SECRET}"
}
}
}
}Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
health_check | read | |
meal_plan | read | |
recipe_collections | read | |
recipes | read | |
shopping | read |
Trust audit
CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (16)
console.log(`[oauth] token request grant_type=${grant_type} client_id=${client_id ? client_id.slice(0, 8) + "..." : "none"} fields=${bodyKeys.join(",")}`);console.log(`[oauth] ANOMALOUS token request: unknown grant_type=${grant_type} ip=${req.ip} fields=${bodyKeys.join(",")}`);console.log(`[oauth] client_credentials secret mismatch: client_id=${client_id.slice(0, 8)}...`);console.log(`[oauth] client_credentials token issued for client_id=${client_id.slice(0, 8)}... user_id=${client.user_id}`);console.log(`[oauth] ANOMALOUS unknown bearer token ip=${req.ip}`);.env.http.example
.gitmodules
.mcpbignore
.releaserc.json
import { getUserByGoogleSub, getUserByEmail, createUser, isEmailAllowed } from "../../db.js";import { getUserByEmail, createUser, isEmailAllowed } from "../../db.js";import AnyListClient from '../../src/anylist-client.js';
import AnyListClient from '../../src/anylist-client.js';
const noEnv = new (await import('../../src/anylist-client.js')).default();@anthropic-ai/mcpb, @modelcontextprotocol/sdk, anylist, bcrypt, better-sqlite3, dotenv, express, express-session
Gates applied: no_behavioural_pass, no_license.
1c1351b2ec76full audit observations/trust-audit/mcp-server/bobby060__anylist.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 1c1351b2ec76 | CAUTION | B | 80 | first audit |
Questions
What is the Anylist MCP server?
Unofficial MCP Server for Anylist
What tools does Anylist expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Anylist safe to connect to an agent?
With care. The audit graded it B (80/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Anylist need?
It reads ANYLIST_PASSWORD, SERVER_SECRET_KEY and SESSION_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Anylist run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as anylist-mcp at 1.9.0.
How current is this page?
The grade is for one exact copy of the source (1c1351b2ec76), read on 2026-10-09. The repository is watched and re-audited when it changes.