Atlas / MCP servers / extelligence-ai / bagel

bagelBLOCK

mcp/extelligence-ai/bagel

Query robotics, drone, and IoT data in plain English through an MCP server, with an intelligent edge data reduction pipeline that keeps only the data that matters.

Verdict
BLOCK
Grade
F
Trust score
59 /100
Exposed tools
1 1r · 0w · 0d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
397
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Bits to atoms.Atoms to bits.

If you still have a script called parsebagfinal_v7.py, we need to talk.

Bagel by Extelligence lets you ask questions about robotics, drone, and IoT data in plain English. Every calculation over your message data is DuckDB SQL, not model guesswork, and Bagel shows you the query so you can audit it.

Is my IMU sensor overheating?

Bagel also has an intelligent edge data reduction pipeline: describe an event and Bagel runs the detection on the robot, keeping the windows that matter and dropping the rest. An MCP server puts all of it in your LLM's hands: Claude Code, Gemini, Cursor, or a fully local model.

Bagel was the first MCP server to ship a real

Read from source at commit 80ffcf9ae82dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add ros2-kilted:2.4.3 -- docker run -i --rm ghcr.io/extelligence-ai/bagel/ros2-kilted:2.4.3:None
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
pingreadReply with pong.
04

Trust audit

BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
declared (6 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/sink/buffer.py:314
self._struct = pickle.load(f)  # noqa: S301
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.dockerignore
.dockerignore
Why it matters. link not followed
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
demo.py:197
importlib.import_module(f"{BaseModule.SOURCE_FACTORY.value}.{ds_type.value}")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
server.py:436
importlib.import_module(import_path).register()
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/di/module.py:31
module: Module = importlib.import_module(import_path)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/pipeline/base.py:261
importlib.import_module(config["module"]).register()
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/pipeline/capabilities.py:99
discovered = importlib.import_module(module_name)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packaging/smithery/bundle/server.mjs:8
`http://127.0.0.1:${port}/sse`, '--transport', 'sse-only', '--allow-http'];
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/database-tests.yaml:41
BAGEL_POSTGRES_TEST_URL: postgres://postgres:bagel-ci-test@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
test/adversarial/test_secrets_redaction.py:110
text = "IO Error: could not connect using 'postgresql://alice:s3cr3t@host/db'"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
test/adversarial/test_secrets_redaction.py:130
"postgresql://alice:[email protected]:5432/prod: name resolution failed"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
test/source/test_postgres.py:7
BAGEL_POSTGRES_TEST_URL=postgres://postgres:bagel@localhost:5433/postgres \
LOWInventory / provenance · inv.binary · CWE-1104
data/sample/copper/imu_probe.mcap
imu_probe.mcap
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
data/sample/ros1/sample.bag
sample.bag
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
data/sample/ros2/db3/part_0.db3
part_0.db3
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
data/sample/ros2/db3/part_1.db3
part_1.db3
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
data/sample/ros2/db3/part_2.db3
part_2.db3
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/pipeline/tasks/upload/azure.py:16
digest = hashlib.md5(usedforsecurity=False)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/pipeline/tasks/upload/gcs.py:15
digest = hashlib.md5(usedforsecurity=False)
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
.github/workflows/claude-review.yaml:200
# exfiltration path via ambient env vars the runner injects into
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
AGENTS.md:11
`Uvicorn running on http://0.0.0.0:8000`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:160
INFO:     Uvicorn running on http://0.0.0.0:8000 (Press CTRL+C to quit)

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 80ffcf9ae82dfull audit observations/trust-audit/mcp-server/extelligence-ai__bagel.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0780ffcf9ae82dBLOCKF59first audit
06

Questions

What is the bagel MCP server?

Query robotics, drone, and IoT data in plain English through an MCP server, with an intelligent edge data reduction pipeline that keeps only the data that matters.

What tools does bagel expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is bagel safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (59/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does bagel need?

It reads SMITHERY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does bagel run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as bagel.

How current is this page?

The grade is for one exact copy of the source (80ffcf9ae82d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement