DingoBLOCK
Dingo: A Comprehensive AI Data, Model and Application Quality Evaluation Tool
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
b9fc3edadab0OBSERVED · 2026-10-07Exposed tools (6)
4 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_llm_details | read | Get detailed information about a specific Dingo LLM. |
get_prompt_details | read | Get detailed information about an LLM |
get_rule_details | read | Get detailed information about a specific Dingo rule. |
list_dingo_components | read | Lists available Dingo rule groups, registered LLM model identifiers, and prompt definitions. |
run_dingo_evaluation | write | Runs a Dingo evaluation (rule-based or LLM-based) on a file. |
run_quick_evaluation | write | Run a simplified Dingo evaluation based on a high-level goal. |
Trust audit
BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (25)
bboxs = eval(input_data.content)
help="Path to JSONL query file for standalone open eval (no MTEB corpus needed)",
# Search Result Effectiveness Executor Usage
# Search Result Quality 三指标评测说明
SKILL.md
importlib.import_module(module_name)
importlib.import_module(module_name)
module = importlib.import_module(module_name)
importlib.import_module(mod_name)
api_url: str = "http://127.0.0.1:8080",
dingo_gui.png.old
test.wav
test_local_excel.xlsx
test_local_parquet.parquet
.owners.yml
.pre-commit-config.yaml
md5 = hashlib.md5()
refer_path=['../../test/data/overlap_visual_image'], # 用户保存图片路径
refer_path=['../../test/data/label_visual_image'], # 用户保存图片路径
TEST_DATA_DIR = os.path.join(os.path.dirname(__file__), "../../data")
$env:OPENAI_BASE_URL="http://35.220.164.252:3888/v1/"
image_bytes = base64.b64decode(data)
dingo/model/rule/scibase/assets/journal_name_mapping_execute_20260512.csv
docs/assets/bad_case.png
docs/assets/mcp_demo.mp4
Gates applied: no_behavioural_pass.
b9fc3edadab0full audit observations/trust-audit/mcp-server/dataeval__dingo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b9fc3edadab0 | BLOCK | F | 49 | first audit |
Questions
What is the Dingo MCP server?
Dingo: A Comprehensive AI Data, Model and Application Quality Evaluation Tool
What tools does Dingo expose?
6 in total: 4 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Dingo safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (49/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Dingo need?
It reads ANTHROPIC_API_KEY, GOOGLE_API_KEY, GOOGLE_SCHOLAR_API_KEY, OPENAI_API_KEY, OPENAI_KEY, OPENALEX_API_KEY, PERSPECTIVE_API_KEY, S2_API_KEY, S3_ACCESS_KEY, S3_SECRET_KEY, SCIVERSE_API_TOKEN and SERPAPI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Dingo run?
It speaks sse and stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (b9fc3edadab0), read on 2026-10-07. The repository is watched and re-audited when it changes.