Atlas / MCP servers / chatmol / Molecule

MoleculeSAFE

mcp/chatmol/molecule

A model-context-protocol server for molecules.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
29 15r · 14w · 0d
Transport
—
License
MIT
Stars
97
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Molecule-MCP: A model-context-protocol server for molecules. Molecule-MCP connects molecule science releated tools to Claude AI through the Model Context Protocol (MCP), allowing Claude to directly interact with and control these tools and act as a co-scientist. This integration enables prompt assisted molecule modeling.

Installation

⚠️ Note: Molecule-MCP requires Claude Desktop to be installed and running.

  1. Go to Claude > Settings > Developer > Edit Config > claudedesktopconfig.json to include the following:
{
"mcpServers": {
"pymol": {
"command": "/path/to/mcp",
"args": [
"run",
"/path/to/molecule-mcp/pymol_server.py"
]
},
"chimerax": {
"command": "/path/to/mcp",
"args": [
"run",
"/path/to/molecule-mcp/ChimeraX_server.py"
]
},
"gromacs_copilot": {
"command": "/path/to/mcp",
"args": [
"run",
"/path/to/molecule-mcp/mcp_server.py"
]
}
}
}
  1. Install mcp and get the script
pip install "mcp[cli]" chatmol
pip install git+https://github.com/ChatMol/gromacs_copilot.git # optional, for running gromacs_copilot
which mcp

the path to mcp will be displayed. Copy this path for the next step and replace /path/to/mcp with the path to mcp.

git clone https://github.com/ChatMol/molecule-mcp.git
cd molecule-mcp
pwd

the path to molecule-mcp will be displayed. Copy this path for the next step and replace /path/to/molecule-mcp with the path to molecule-mcp.

Disclaimer

Molecule-MCP is provided "as is" without warranty of any kind, express or implied. The authors and contributors disclaim all warranties including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose. Users employ this software at their own risk.

The authors bear no responsibility for any consequences arising from the use, misuse, or mi

Read from source at commit 57fe67d7ed5bOBSERVED · 2026-10-07
02

Exposed tools (29)

15 read · 14 write · 0 destructive.

ToolRiskDescription
add_ionswrite
analyze_gyrationread
analyze_ligand_rmsdread
analyze_protein_ligand_contactsread
analyze_rmsdread
analyze_rmsfread
check_for_ligandsread
check_gromacs_installationread
create_mdp_filewrite
create_mmpbsa_index_filewrite
define_simulation_boxread
generate_topologyread
get_workspace_inforead
init_gromacs_copilotread
open_chimeraxreadopen chimerax with remote control enabled
open_pymolreadopen pymol
run_chimerax_commandwriterun chimerax command
run_energy_minimizationwrite
run_npt_equilibrationwrite
run_nvt_equilibrationwrite
run_production_mdwrite
run_pymol_commandwriterun pymol command
run_shell_commandwrite
save_imgaewritesave current view of pymol session to a file, perferably .png
set_ligandwrite
set_protein_filewrite
set_simulation_stagewrite
solvate_systemread
switch_agent_protocolread
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
chimerax_server.py:10
s = ServerProxy(uri="http://127.0.0.1:%d/RPC2" % xmlrpc_port)
INFOInventory / provenance · inv.oversize · CWE-1104
assets/chimerax.jpg
assets/chimerax.jpg
Why it matters. 1621805 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 57fe67d7ed5bfull audit observations/trust-audit/mcp-server/chatmol__molecule.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0757fe67d7ed5bSAFEB89first audit
05

Questions

What is the Molecule MCP server?

A model-context-protocol server for molecules.

What tools does Molecule expose?

29 in total: 15 read-only, 14 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Molecule safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Molecule need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (57fe67d7ed5b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement