Atlas / MCP servers / genaiunplugged14 / mcp-masterclass

mcp-masterclassSAFE

mcp/genaiunplugged14/mcp-masterclass

Code and checkpoints for the MCP Masterclass: 4 modules, 30 video lessons, one server (Scribe) built end to end on the MCP Python SDK v2.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
14 10r · 4w · 0d
Transport
stdio
License
MIT
Stars
1
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Code and checkpoints for the MCP Masterclass, a free video course in 4 modules and 30 lessons on the Model Context Protocol. You build one server, called Scribe, end to end on the MCP Python SDK v2: it starts by reading a draft out of Google Drive, learns to edit the real document, gets a guard and a memory, and ends up deployed off your laptop where other people can install it. The whole course runs on the free Claude Desktop plan.

Course hub: genaiunplugged.com/courses/mcp

Watch

The whole course is one video: the full course video, all 30 lessons in 2.5 hours with a chapter per lesson. The lesson pages on the course site carry the video cued to the lesson, the full transcript, every code block, and the downloads.

Playlist: MCP Masterclass

Lessons

Module 1: The Whole Idea

Checkpoint: checkpoints/module-1/ or scribe-checkpoint-m1.zip

Read from source at commit b1a254e6f137OBSERVED · 2026-10-08
02

Exposed tools (14)

10 read · 4 write · 0 destructive.

ToolRiskDescription
edit_docwriteReplace some text inside one draft in the Scribe folder.
find_notereadFind every note that mentions one word.
get_learning_insightsreadSay which approach has worked best for a task so far, and how sure we are.
read_docreadRead one draft from the Scribe folder in Google Drive.
read_memoryreadRead everything that has been remembered so far.
read_notereadRead one note from the notes folder. Give the file name, like ideas.txt.
read_researchreadRead the research findings that were saved earlier.
recallreadEvery note Scribe remembers, oldest first.
record_experiencereadRecord how one approach to a task turned out. Say whether it worked.
rememberreadKeep one note for every future chat. A rule, or a choice.
save_draftwriteSave a finished draft that was written from the research.
save_memorywriteRemember one insight about a topic, so a later chat can use it.
save_researchwriteSave research findings so another agent can read them later.
search_memoryreadFind remembered insights that mention a word.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
checkpoints/module-4/README.txt:98
Open http://127.0.0.1:8765/ in a browser. You should see
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
archive/2025-article-course/lesson-05/requirements.txt
mcp
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
archive/2025-article-course/lesson-06/requirements.txt
mcp
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
archive/2025-article-course/lesson-07/requirements.txt
mcp
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
archive/2025-article-course/lesson-08/tools/requirements.txt
mcp
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
checkpoints/module-1/requirements.txt
mcp, google-api-python-client, google-auth
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha b1a254e6f137full audit observations/trust-audit/mcp-server/genaiunplugged14__mcp-masterclass.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08b1a254e6f137SAFEB89first audit
05

Questions

What is the mcp-masterclass MCP server?

Code and checkpoints for the MCP Masterclass: 4 modules, 30 video lessons, one server (Scribe) built end to end on the MCP Python SDK v2.

What tools does mcp-masterclass expose?

14 in total: 10 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is mcp-masterclass safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does mcp-masterclass need?

It reads SCRIBE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does mcp-masterclass run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (b1a254e6f137), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement