ConciergeBLOCK
🚀 Universal SDK for building next-gen MCP servers
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The fabric for reliable MCP servers and AI applications.
[](https://docs.getconcierge.app) [](https://discord.gg/Y3ayRa33Pg) [](https://pypi.org/project/concierge-sdk) [](https://pypi.org/project/concierge-sdk)
The Model Context Protocol (MCP) is a standardized way to connect AI agents to tools. Instead of exposing a flat list of every tool on every request, Concierge progressively discloses only what's relevant. Concierge guarantees deterministic results and reliable tool invocation.
Getting Started
[!NOTE] Concierge requires Python 3.9+. We recommend installing with uv for faster dependency resolution, but pip works just as well.
pip install concierge-sdk
Scaffold a new project:
concierge init my-store # Generate a ready to run project cd my-store # Enter project python main.py # Start the MCP server
Or wrap an existing MCP server two lines, nothing else changes:
# Before
from mcp.server.fastmcp import FastMCP
app = FastMCP("my-server")
# After: just wrap it
from concierge import Concierge
app = Concierge(FastMCP("my-server"))[!TIP] Concierge works at the MCP protocol level. It dynamically changes which tools are returned by tools/list based on the current workflow step. The agent and client don't need to know Concierge exists, they just see fewer, more relevant tools at each point.from concie
a3e5b7db5c55OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add pizza-widgets --env CONCIERGE_AUTH_TOKEN=${CONCIERGE_AUTH_TOKEN} -- npx -y pizza-widgets{
"mcpServers": {
"pizza-widgets": {
"command": "npx",
"args": [
"-y",
"pizza-widgets"
],
"env": {
"CONCIERGE_AUTH_TOKEN": "${CONCIERGE_AUTH_TOKEN}"
}
}
}
}Exposed tools (17)
10 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_to_cart | write | Add a product to the shopping cart. |
apply_migration | write | Execute the SQL migration script against the database. |
call_tool | write | Execute a tool returned by search_tools with provided arguments. |
checkout | read | Complete the checkout process. |
create_backup | write | Create a full logical backup (mysqldump) of the target database. |
drain_connections | read | Gracefully drain all active MySQL connections before migration. |
finalize_migration | read | Mark the migration as complete and clean up temporary artifacts. |
my_tool | read | return { |
notify_stakeholders | write | Send a notification to the team about migration status. |
preflight_check | read | Check MySQL cluster health, replication lag, and disk space. |
run_smoke_tests | write | Run post-migration smoke tests against key tables and queries. |
search_items | read | return { |
search_products | read | Search for products in the catalog. |
search_tools | read | Semantic search over available tools; returns the best matches. |
undrain_connections | write | Re-enable new client connections to the MySQL cluster. |
validate_backup | read | Validate the integrity of a MySQL backup by restoring to a scratch instance. |
view_cart | read | View the current shopping cart. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
exec(compiled, namespace)
Server runs at http://0.0.0.0:8000/mcp
concierge-sdk
concierge-sdk
concierge-sdk
@openai/apps-sdk-ui, clsx, embla-carousel, embla-carousel-react, framer-motion, lucide-react, mapbox-gl, react
concierge-sdk, uvicorn, starlette
# Stateful — tools share state via get_state/set_state, required for staged workflows: The stateful nature support tool dependency and shared state in multi-turn conversations. With session id, the se
assets/concierge-banner.png
Gates applied: no_behavioural_pass.
a3e5b7db5c55full audit observations/trust-audit/mcp-server/concierge-hq__concierge-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | a3e5b7db5c55 | BLOCK | D | 69 | first audit |
Questions
What is the Concierge MCP server?
🚀 Universal SDK for building next-gen MCP servers
What tools does Concierge expose?
17 in total: 10 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Concierge safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Concierge need?
It reads CONCIERGE_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Concierge run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as pizza-widgets.
How current is this page?
The grade is for one exact copy of the source (a3e5b7db5c55), read on 2026-09-29. The repository is watched and re-audited when it changes.