Atlas / MCP servers / gongrzhe / YOLO

YOLOSAFE

mcp/gongrzhe/yolo
Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
15 13r · 2w · 0d
Transport
stdio
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful YOLO (You Only Look Once) computer vision service that integrates with Claude AI through Model Context Protocol (MCP). This service enables Claude to perform object detection, segmentation, classification, and real-time camera analysis using state-of-the-art YOLO models.

Features

  • Object detection, segmentation, classification, and pose estimation
  • Real-time camera integration for live object detection
  • Support for model training, validation, and export
  • Comprehensive image analysis combining multiple models
  • Support for both file paths and base64-encoded images
  • Seamless integration with Claude AI

Setup Instructions

Prerequisites

  • Python 3.10 or higher
  • Git (optional, for cloning the repository)

Environment Setup

  1. Create a directory for the project and navigate to it:
mkdir yolo-mcp-service
cd yolo-mcp-service
  1. Download the project files or clone from repository:
# If you have the files, copy them to this directory
# If using git:
git clone https://github.com/GongRzhe/YOLO-MCP-Server.git .
  1. Create a virtual environment:
# On Windows
python -m venv .venv

# On macOS/Linux
python3 -m venv .venv
  1. Activate the virtual environment:
# On Windows
.venv\Scripts\activate

# On macOS/Linux
source .venv/bin/activate
  1. Run the setup script:
python setup.py

The setup script will:

  • Check your Python version
  • Create a virtual environment (if not already created)
  • Install required dependencies
  • Generate an MCP configuration file (mcp-config.json)
  • Output configuration information for different MCP clients including Claude
  1. Note the output from the setup script, which will look similar to:
MCP configuration has been written to: /path/to/mcp-config.json

MCP configuration for 
Read from source at commit e53b46b797e6OBSERVED · 2026-10-08
02

Exposed tools (15)

13 read · 2 write · 0 destructive.

ToolRiskDescription
analyze_image_from_pathread
classify_imageread
comprehensive_image_analysisread
detect_objectsread
export_modelread
get_camera_detectionsread
get_model_directoriesreadGet information about configured model directories and available models
list_available_modelsreadList available YOLO models that actually exist on disk in any configured directory
segment_objectsread
start_camera_detectionwrite
stop_camera_detectionwrite
test_connectionread
track_objectsread
train_modelread
validate_modelread
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server.py:99
image_bytes = base64.b64decode(image_source)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server.py:408
image_bytes = base64.b64decode(image_data)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server_cli.py:89
image_bytes = base64.b64decode(image_source)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server_cli.py:180
image_data = base64.b64decode(base64_data)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
server_combine_terminal.py:64
image_bytes = base64.b64decode(image_source)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, ultralytics, opencv-python, numpy, pillow
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e53b46b797e6full audit observations/trust-audit/mcp-server/gongrzhe__yolo.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e53b46b797e6SAFEB89first audit
05

Questions

What tools does YOLO expose?

15 in total: 13 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is YOLO safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does YOLO need?

No credential environment variables were found in its source, so it appears to need none.

How does YOLO run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (e53b46b797e6), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement