Atlas / MCP servers / concierge-hq / Concierge

ConciergeBLOCK

mcp/concierge-hq/concierge-1

🚀 Universal SDK for building next-gen MCP servers

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
17 10r · 7w · 0d
Transport
streamable-http
License
NOASSERTION
Stars
530
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The fabric for reliable MCP servers and AI applications.

[](https://docs.getconcierge.app) [](https://discord.gg/Y3ayRa33Pg) [](https://pypi.org/project/concierge-sdk) [](https://pypi.org/project/concierge-sdk)

The Model Context Protocol (MCP) is a standardized way to connect AI agents to tools. Instead of exposing a flat list of every tool on every request, Concierge progressively discloses only what's relevant. Concierge guarantees deterministic results and reliable tool invocation.

Getting Started

[!NOTE] Concierge requires Python 3.9+. We recommend installing with uv for faster dependency resolution, but pip works just as well.
pip install concierge-sdk

Scaffold a new project:

concierge init my-store    # Generate a ready to run project
cd my-store                # Enter project
python main.py             # Start the MCP server

Or wrap an existing MCP server two lines, nothing else changes:

# Before
from mcp.server.fastmcp import FastMCP
app = FastMCP("my-server")

# After: just wrap it
from concierge import Concierge
app = Concierge(FastMCP("my-server"))
[!TIP] Concierge works at the MCP protocol level. It dynamically changes which tools are returned by tools/list based on the current workflow step. The agent and client don't need to know Concierge exists, they just see fewer, more relevant tools at each point.
from concie
Read from source at commit a3e5b7db5c55OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add pizza-widgets --env CONCIERGE_AUTH_TOKEN=${CONCIERGE_AUTH_TOKEN} -- npx -y pizza-widgets
claude-desktop
{
  "mcpServers": {
    "pizza-widgets": {
      "command": "npx",
      "args": [
        "-y",
        "pizza-widgets"
      ],
      "env": {
        "CONCIERGE_AUTH_TOKEN": "${CONCIERGE_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (17)

10 read · 7 write · 0 destructive.

ToolRiskDescription
add_to_cartwriteAdd a product to the shopping cart.
apply_migrationwriteExecute the SQL migration script against the database.
call_toolwriteExecute a tool returned by search_tools with provided arguments.
checkoutreadComplete the checkout process.
create_backupwriteCreate a full logical backup (mysqldump) of the target database.
drain_connectionsreadGracefully drain all active MySQL connections before migration.
finalize_migrationreadMark the migration as complete and clean up temporary artifacts.
my_toolreadreturn {
notify_stakeholderswriteSend a notification to the team about migration status.
preflight_checkreadCheck MySQL cluster health, replication lag, and disk space.
run_smoke_testswriteRun post-migration smoke tests against key tables and queries.
search_itemsreadreturn {
search_productsreadSearch for products in the catalog.
search_toolsreadSemantic search over available tools; returns the best matches.
undrain_connectionswriteRe-enable new client connections to the MySQL cluster.
validate_backupreadValidate the integrity of a MySQL backup by restoring to a scratch instance.
view_cartreadView the current shopping cart.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
backends/code_backend.py:442
exec(compiled, namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
templates/chatgpt/README.md:25
Server runs at http://0.0.0.0:8000/mcp
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/mysql_migration/flat/requirements.txt
concierge-sdk
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/mysql_migration/plan/requirements.txt
concierge-sdk
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/mysql_migration/staged/requirements.txt
concierge-sdk
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
templates/chatgpt/assets/package.json
@openai/apps-sdk-ui, clsx, embla-carousel, embla-carousel-react, framer-motion, lucide-react, mapbox-gl, react
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
templates/chatgpt/requirements.txt
concierge-sdk, uvicorn, starlette
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
skills.md:35
# Stateful — tools share state via get_state/set_state, required for staged workflows: The stateful nature support tool dependency and shared state in multi-turn conversations. With session id, the se
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
assets/concierge-banner.png
assets/concierge-banner.png
Why it matters. 4107936 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha a3e5b7db5c55full audit observations/trust-audit/mcp-server/concierge-hq__concierge-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-29a3e5b7db5c55BLOCKD69first audit
06

Questions

What is the Concierge MCP server?

🚀 Universal SDK for building next-gen MCP servers

What tools does Concierge expose?

17 in total: 10 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Concierge safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Concierge need?

It reads CONCIERGE_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Concierge run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as pizza-widgets.

How current is this page?

The grade is for one exact copy of the source (a3e5b7db5c55), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement