Atlas / MCP servers / comet-ml / Opik

OpikCAUTION

mcp/comet-ml/opik

Model Context Protocol (MCP) server for Opik, the open-source LLM observability and evaluation platform, built by Comet. Read traces, log scores, and manage prompts from Claude Code, Cursor, or VS Code.

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
219
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The official Model Context Protocol (MCP) server for [Opik](https://github.com/comet-ml/opik), the open-source LLM observability and evaluation platform, built by [Comet](https://www.comet.com). Plug your AI host (Claude Code, Cursor, VS Code Copilot, Codex, opencode, or any MCP client) directly into your Opik workspace: read traces, log scores, and save prompt versions, all from the chat.

Built for LLM engineers who already run Opik and want to drive it from the same AI assistant they code with.

You:    "Which traces in project 'demo' failed today?"
Claude: → list(entity_type="trace", project_name="demo") → "Three traces failed..."

You:    "Score trace 7f2e... 0.9 on helpfulness with reason 'great recovery'."
Claude: → write(score.create) → done

Quick start

One command registers the server with the AI clients on your machine, installs the Opik skill pack, and verifies the connection. It needs `uv` and no Opik SDK:

uvx opik mcp configure

It detects Claude Code, Cursor, VS Code Copilot, Codex and opencode, and sets up the server that fits your Opik:

Clients load MCP servers when a session starts, so start a new session afterwards. Without a terminal, as from a coding agent or a script, name the client: uvx opik mcp configure --ai-client claude-code (or codex, cursor, vscode, opencode). Run that way it needs an existing ~/.opik.config or OPIK_API_KEY in the environment; without either, use the commands below.

Setup guide, troubleshooting and FAQ: [comet.com/doc

Read from source at commit 7f7bde5b6df4OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add opik-mcp --env OPIK_API_KEY=${OPIK_API_KEY} -- uvx opik-mcp==0.0.0
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
helloreadreturn
hireadreturn
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (18)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/capture_bi_listener.py:37
print(f"BI capture listening on http://127.0.0.1:{port}/notify/event/", flush=True)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/opik_mcp/config.py:178
opik_mcp_allowed_origins: str = "http://127.0.0.1:*,http://localhost:*,http://[::1]:*"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/opik_mcp/skills/opik/references/integrations.md:248
OpenAI(base_url="https://api.provider.com/v1", api_key="your-provider-api-key")
LOWInventory / provenance · inv.hidden_file · CWE-1104
helm/opik-mcp/.helmignore
.helmignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/writes/test_errors.py:40
for rebuilt in (pickle.loads(pickle.dumps(error)), copy.copy(error), copy.deepcopy(error)):
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/hermetic/writes/test_dispatch.py:25
cases = importlib.import_module(name).CASES
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/repo/test_install_branch.py:317
@pytest.mark.parametrize("name", ["x/../../..", "../sibling", "Upper", "a b", "-x", "a" * 60])
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/skills/test_catalog.py:249
"opik/../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/skills/test_catalog.py:250
"opik/../../scripts/build_skills_pack.py",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/skills/test_catalog.py:252
"../../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/skills/test_catalog.py:253
"opik://skills/../../../etc/passwd",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/live-e2e/design-doc.md:101
OPIK_URL=http://127.0.0.1:28080 make live
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/live-e2e/design-doc.md:108
OPIK_URL=http://127.0.0.1:28080 uv run python scripts/seed_e2e_backend.py --prefix my-fixture
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/live-e2e/design-doc.md:109
OPIK_URL=http://127.0.0.1:28080 uv run python scripts/seed_e2e_backend.py --prefix my-fixture --wipe
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/opik_mcp/skills/opik-diagnose/references/diagnostics-list.md:10
Each open issue becomes one shortlist item with `signal=diagnostics`: `trace_id` comes from the first `example_trace_ids` entry (read the top few issues to get them) and `trace_url` from `trace_url_te
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/runtime/design-doc.md:64
Open question: a hosted request with an API key and no `Comet-Workspace` falls
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:158
curl -LsSf https://astral.sh/uv/install.sh | sh   # macOS / Linux
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
legacy/typescript/MIGRATION.md:40
curl -LsSf https://astral.sh/uv/install.sh | sh   # macOS / Linux

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 7f7bde5b6df4full audit observations/trust-audit/mcp-server/comet-ml__opik.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-067f7bde5b6df4CAUTIONB85first audit
06

Questions

What is the Opik MCP server?

Model Context Protocol (MCP) server for Opik, the open-source LLM observability and evaluation platform, built by Comet. Read traces, log scores, and manage prompts from Claude Code, Cursor, or VS Code.

What tools does Opik expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Opik safe to connect to an agent?

With care. The audit graded it B (85/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Opik need?

It reads GH_TOKEN, OPENAI_API_KEY and OPIK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Opik run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as opik-verify-eval-gate.

How current is this page?

The grade is for one exact copy of the source (7f7bde5b6df4), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement