Pokemon DemoSAFE
A quick pokemon demo to showcase MCP server, client, and host
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A demo project showcasing the Model Context Protocol (MCP) integration with Pokemon data. This project includes:
- An MCP server that provides Pokemon data and attack capabilities
- An MCP client that interacts with the server
- An HTTP server that allows LLMs to use Pokemon tools via OpenRouter
Installation
bun install
Running the Project
MCP Server and Client Demo
Run the client which automatically launches the MCP server:
bun mcp_client.ts
HTTP Server with LLM Integration
Set your OpenRouter API key and run the HTTP server:
export OPENROUTER_API_KEY=your_api_key_here bun http_server.ts
Then access the server at http://localhost:3005:
/tools- List available tools/attack- Execute a random Pokemon attack using LLM
This project uses Bun as its JavaScript runtime.
d4079abaeb9aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add server -- npx -y server
{
"mcpServers": {
"server": {
"command": "npx",
"args": [
"-y",
"server"
]
}
}
}Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
attack | write | You can use this to execute a pokemon attack. Your moveName and pokemonName should be input as lowercase. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
bun.lockb
@modelcontextprotocol/sdk, ofetch, openai, zod, @types/bun
Gates applied: no_behavioural_pass, no_license.
d4079abaeb9afull audit observations/trust-audit/mcp-server/danwritecode__pokemon-demo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d4079abaeb9a | SAFE | B | 89 | first audit |
Questions
What is the Pokemon Demo MCP server?
A quick pokemon demo to showcase MCP server, client, and host
What tools does Pokemon Demo expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pokemon Demo safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Pokemon Demo need?
No credential environment variables were found in its source, so it appears to need none.
How does Pokemon Demo run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as server.
How current is this page?
The grade is for one exact copy of the source (d4079abaeb9a), read on 2026-10-08. The repository is watched and re-audited when it changes.