Atlas / MCP servers / bobby060 / Anylist

AnylistCAUTION

mcp/bobby060/anylist

Unofficial MCP Server for Anylist

Verdict
CAUTION
Grade
B
Trust score
80 /100
Exposed tools
5 5r · 0w · 0d
Transport
sse · stdio · streamable-http
License
—
Stars
32
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server that integrates with AnyList — shopping lists, recipes, and meal planning — exposed via the Model Context Protocol. Works with Claude Desktop, Claude Code, Claude Web/Mobile, or any MCP-compatible client like Home Assistant.

Two deployment modes:

  • Local (stdio) — runs on your machine alongside Claude Desktop or Claude Code. Fastest setup, no server required.
  • HTTP server — runs in Docker behind a Cloudflare Tunnel. Required for Claude Web, Claude Mobile, or home assistant and useful for sharing access across devices or users.

Tools Overview

The MCP server provides 5 domain-grouped tools rather than 18+ individual ones:

  • shopping — Manage shopping lists and items: add, check off, delete, organize by category and store, and browse favorites
  • recipes — Browse, create, and import recipes from URLs; includes ingredient and step parsing
  • meal_plan — Schedule meals on a calendar with optional links to recipes
  • recipe_collections — Organize recipes into curated named collections
  • health_check — Verify your connection to AnyList and access to target lists

These tools work together to enable typical workflows: browse or create recipes → plan meals → add ingredients to your shopping list. See docs/tools.md for the complete reference including all actions and parameters.

Installation: Claude Desktop

The fastest way to get started is to download the latest anylist-mcp.mcpb from the releases page.

  1. Open Claude Desktop → Settings → Extensions
  2. Drag and drop the .mcpb file, or click "Advanced settings" → Install extension
  3. Enter your configuration when prompted:
  4. AnyList Email — your AnyList account email
  5. AnyList Password — your AnyList account password
  6. Default Shopping List — optional, defaults to "Groceries"

Installation: Claude Code / Claude Desktop (from source)

###

Read from source at commit 1c1351b2ec76OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add anylist-mcp --env ANYLIST_PASSWORD=${ANYLIST_PASSWORD} --env SERVER_SECRET_KEY=${SERVER_SECRET_KEY} --env SESSION_SECRET=${SESSION_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "anylist-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANYLIST_PASSWORD": "${ANYLIST_PASSWORD}",
        "SERVER_SECRET_KEY": "${SERVER_SECRET_KEY}",
        "SESSION_SECRET": "${SESSION_SECRET}"
      }
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
health_checkread
meal_planread
recipe_collectionsread
recipesread
shoppingread
04

Trust audit

CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/http/auth/oauth.js:121
console.log(`[oauth] token request grant_type=${grant_type} client_id=${client_id ? client_id.slice(0, 8) + "..." : "none"} fields=${bodyKeys.join(",")}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/http/auth/oauth.js:132
console.log(`[oauth] ANOMALOUS token request: unknown grant_type=${grant_type} ip=${req.ip} fields=${bodyKeys.join(",")}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/http/auth/oauth.js:238
console.log(`[oauth] client_credentials secret mismatch: client_id=${client_id.slice(0, 8)}...`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/http/auth/oauth.js:252
console.log(`[oauth] client_credentials token issued for client_id=${client_id.slice(0, 8)}... user_id=${client.user_id}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/http/auth/oauth.js:396
console.log(`[oauth] ANOMALOUS unknown bearer token ip=${req.ip}`);
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.http.example
.env.http.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/http/auth/providers/google.js:3
import { getUserByGoogleSub, getUserByEmail, createUser, isEmailAllowed } from "../../db.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/http/auth/providers/password.js:3
import { getUserByEmail, createUser, isEmailAllowed } from "../../db.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/anylist-client/helpers.js:1
import AnyListClient from '../../src/anylist-client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/anylist-client/shopping-items.test.js:4
import AnyListClient from '../../src/anylist-client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/anylist-client/shopping-lists.test.js:46
const noEnv = new (await import('../../src/anylist-client.js')).default();
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/mcpb, @modelcontextprotocol/sdk, anylist, bcrypt, better-sqlite3, dotenv, express, express-session
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-09 · audit v0.4.1 · source sha 1c1351b2ec76full audit observations/trust-audit/mcp-server/bobby060__anylist.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-091c1351b2ec76CAUTIONB80first audit
06

Questions

What is the Anylist MCP server?

Unofficial MCP Server for Anylist

What tools does Anylist expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Anylist safe to connect to an agent?

With care. The audit graded it B (80/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Anylist need?

It reads ANYLIST_PASSWORD, SERVER_SECRET_KEY and SESSION_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Anylist run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as anylist-mcp at 1.9.0.

How current is this page?

The grade is for one exact copy of the source (1c1351b2ec76), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement