Atlas / MCP servers / clemensv / Avrotize

AvrotizeBLOCK

mcp/clemensv/avrotize

Avrotize is a command-line tool for converting data structure definitions between different schema formats, using Apache Avro Schema as the integration schema model.

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
4 2r · 2w · 0d
Transport
stdio
License
Apache-2.0
Stars
131
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

mcp-name: io.github.clemensv/avrotize

[](https://pypi.org/project/avrotize/) [](https://pypi.org/project/avrotize/) [](https://github.com/clemensv/avrotize/actions/workflows/build_deploy.yml) [](https://opensource.org/licenses/MIT) [](https://pypi.org/project/avrotize/)

[📚 Documentation & Examples](https://clemensv.github.io/avrotize/) | [🎨 Conversion Gallery](https://clemensv.github.io/avrotize/gallery/)

Avrotize is a "Rosetta Stone" for data structure definitions, allowing you to convert between numerous data and database schema formats and to generate code for different programming languages.

It is, for instance, a well-documented and predictable converter and code generator for data structures originally defined in JSON Schema (of arbitrary complexity).

The tool leans on the Apache Avro-derived Avrotize Schema as its schema model.

  • Programming languages: Python, C#, Java, TypeScript, JavaScript, Rust, Go, C++
  • SQL Databases: MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, BigQuery, Snowflake, Redshift, DB2
  • Other databases: KQL/Kusto, SurrealDB, MongoDB, Cassandra, Redis, Elasticsearch, DynamoDB, CosmosDB
  • Data schema formats: Avro, JSON Schema, JSON Structure, XML Schema (XSD), Protocol Buffers 2 and 3, ASN.1, Apache Parquet, JSON Type Definition (JTD), CDDL, CUE, FlatBuffers, Apache Thrift IDL, Smithy IDL, Cap'n Proto, RAML 1.0 Data Types, and OpenAPI 3.x

Installation

You can install Avrotize from PyPI, having installed Python 3.10 or later:

pip insta
Read from source at commit 21ab7fd3ea7eOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add avrotize -- uvx avrotize==3.5.1 mcp
03

Exposed tools (4)

2 read · 2 write · 0 destructive.

ToolRiskDescription
describe_capabilitieswriteDescribe when this server should be used and how to invoke it.
get_conversionreadGet metadata for a specific conversion command.
list_conversionsreadList available Avrotize conversion commands.
run_conversionwriteRun a conversion command and return conversion output information.
04

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (3 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
avrotize/ramltoavro.py:57
data = yaml.load(raml_file, Loader=_RamlLoader)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
avrotize/avrotize.py:31
'type': eval(arg['type']),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
vscode/avrotize/src/extension.ts:218
const process = exec(cmd, (error, stdout, stderr) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
vscode/avrotize/src/extension.ts:246
exec(commandToRun, (error, stdout, stderr) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
avrotize/__init__.py:14
self._modules[module_name] = importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
avrotize/avrotize.py:64
mod = __import__(module, fromlist=[func])
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/test_java_xml.py:210
String secret = "XXE_SECRET_MUST_NOT_BE_READ";
LOWInventory / provenance · inv.binary · CWE-1104
test/parquet/address.parquet
address.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/struct/basic-types.struct-ref.iceberg
basic-types.struct-ref.iceberg
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/struct/choice-types.struct-ref.iceberg
choice-types.struct-ref.iceberg
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/struct/collections.struct-ref.iceberg
collections.struct-ref.iceberg
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/struct/complex-scenario.struct-ref.iceberg
complex-scenario.struct-ref.iceberg
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
vscode/avrotize/.vscode-test.mjs
.vscode-test.mjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
vscode/avrotize/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
test/test_governance_workflows.py:53
return yaml.load(
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
test/test_governance_workflows.py:69
yaml.load("jobs: {}\njobs: {}\n", Loader=UniqueKeyLoader)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
test/test_governance_workflows.py:74
document = yaml.load(
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
test/test_python_xml_adversarial.py:86
module = importlib.import_module(f"{package}.adversarial.secureenvelope")
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
test/test_structuretopython.py:1040
return importlib.import_module(module_name)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
avrotize/avrotools.py:106
md5_hash = hashlib.md5(pcf.encode('utf-8')).digest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/test_governance_repro.py:163
"../../outside",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
vscode/avrotize/esbuild.js:45
from: ["../../avrotize/commands.json"],
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
test/test_structuretopython.py:1984
assert "base64.b64decode(" in source and "validate=True" in source, source
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
avrotize/dependencies/python/py312/requirements.txt
avro, fastavro, confluent-kafka, dataclasses-json, pytest, mypy, pylint
Why it matters. 7 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 21ab7fd3ea7efull audit observations/trust-audit/mcp-server/clemensv__avrotize.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0721ab7fd3ea7eBLOCKD61first audit
06

Questions

What is the Avrotize MCP server?

Avrotize is a command-line tool for converting data structure definitions between different schema formats, using Apache Avro Schema as the integration schema model.

What tools does Avrotize expose?

4 in total: 2 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Avrotize safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Avrotize need?

No credential environment variables were found in its source, so it appears to need none.

How does Avrotize run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as avrotize at 2.1.3.

How current is this page?

The grade is for one exact copy of the source (21ab7fd3ea7e), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement