Quick DataSAFE
Prompt focused MCP Server for .json and .csv agentic data analytics for Claude Code
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Purpose: Learn to build Powerful Model Context Protocol (MCP) servers by scaling tools into reusable agentic workflows (ADWs aka Prompts w/tools).
Quick-Data
Quick-Data is a MCP server that gives your agent arbitrary data analysis on .json and .csv files. We use quick-data as a concrete use case to experiment with the MCP Server elements specifically: Prompts > Tools > Resources. See quick-data-mcp for details on the MCP server
Leading Questions
We experiment with three leading questions:
- How can we MAXIMIZE the value of custom built MCP servers by using tools, resources, and prompts TOGETHER?
- What's the BEST codebase architecture for building MCP servers?
- Can we build an agentic workflow (prompt w/tools) that can be used to rapidly build MCP servers?
Understanding MCP Components
MCP servers have three main building blocks that extend what AI models can do:
Tools
What: Functions that AI models can call to perform actions.
When to use: When you want the AI to DO something at a low to mid atomic level based on your domain specific use cases.
Example:
@mcp.tool()
async def create_task(title: str, description: str) -> dict:
"""Create a new task."""
# AI can call this to actually create tasks
return {"id": "123", "title": title, "status": "created"}Resources
What: Data that AI models can read and access.
When to use: When you want the AI to READ information - user profiles, configuration, status, or any data source.
Example:
@mcp.resource("users://{user_id}/profile")
async def get_user_profile(user_id: str) -> dict:
"""Get user profile by ID."""
# AI can read this data to understand users
return {"id": user_id, "name": "John", "role": "developer"}Prompts
What: Pre-built conversation temp
7f76f48a04b2OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add quick-data-mcp --env API_KEY=${API_KEY} -- uvx quick-data-mcp{
"mcpServers": {
"quick-data-mcp": {
"command": "uvx",
"args": [
"quick-data-mcp"
],
"env": {
"API_KEY": "${API_KEY}"
}
}
}
}Exposed tools (32)
27 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_distributions | read | Analyze distribution of any column. |
calculate_feature_importance | read | Calculate feature importance for predictive modeling. |
clear_all_datasets | destructive | Clear all datasets from memory. |
clear_dataset | destructive | Remove dataset from memory. |
compare_datasets | read | Compare multiple datasets. |
create_chart | write | Create generic charts that adapt to any dataset. |
detect_outliers | read | Detect outliers using configurable methods. |
execute_custom_analytics_code | write | |
export_insights | read | Export analysis in multiple formats. |
find_correlations | read | Find correlations between numerical columns. |
generate_dashboard | read | Generate multi-chart dashboards from any data. |
get_dataset_info | read | Get basic info about loaded dataset. |
list_loaded_datasets | read | Show all datasets currently in memory. |
load_dataset | read | Load any JSON/CSV dataset into memory with automatic schema discovery. |
memory_optimization_report | read | Analyze memory usage and suggest optimizations. |
merge_datasets | write | Join datasets on common keys. |
resource_analytics_available_analyses | read | Tool mirror of analytics://available_analyses resource. |
resource_analytics_column_types | read | Tool mirror of analytics://column_types resource. |
resource_analytics_current_dataset | read | Tool mirror of analytics://current_dataset resource. |
resource_analytics_memory_usage | read | Tool mirror of analytics://memory_usage resource. |
resource_analytics_suggested_insights | read | Tool mirror of analytics://suggested_insights resource. |
resource_config_server | read | Tool mirror of config://server resource. |
resource_datasets_loaded | read | Tool mirror of datasets://loaded resource. |
resource_datasets_sample | read | Tool mirror of datasets://{name}/sample resource. |
resource_datasets_schema | read | Tool mirror of datasets://{name}/schema resource. |
resource_datasets_summary | read | Tool mirror of datasets://{name}/summary resource. |
resource_system_status | read | Tool mirror of system://status resource. |
resource_users_profile | read | Tool mirror of users://{user_id}/profile resource. |
segment_by_column | read | Generic segmentation that works on any categorical column. |
suggest_analysis | read | AI recommendations based on data characteristics. |
time_series_analysis | read | Temporal analysis when dates are detected. |
validate_data_quality | read | Comprehensive data quality assessment. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
clear_all_datasets, clear_dataset
.mcp.json.sample
Gates applied: no_behavioural_pass, no_license.
7f76f48a04b2full audit observations/trust-audit/mcp-server/disler__quick-data.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 7f76f48a04b2 | SAFE | B | 89 | first audit |
Questions
What is the Quick Data MCP server?
Prompt focused MCP Server for .json and .csv agentic data analytics for Claude Code
What tools does Quick Data expose?
32 in total: 27 read-only, 3 that write, and 2 that can delete or overwrite (clear_all_datasets, clear_dataset). Every one is listed on this page with its risk.
Is Quick Data safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Quick Data need?
It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (7f76f48a04b2), read on 2026-10-07. The repository is watched and re-audited when it changes.