Atlas / MCP servers / grll / Mcpadapt

McpadaptBLOCK

mcp/grll/mcpadapt

Unlock 650+ MCP servers tools in your favorite agentic framework.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
18 18r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
426
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

For more context, guides and API references visit our new documentation.

Unlock 650+ MCP servers tools in your favorite agentic framework.

Model Context Protocol is an open-source protocol introduced by Anthropic which allows anyone to simply and quickly make tools and resources available as "MCP Servers".

Since its release more than 650 MCP servers have been created giving access to many data & tools to supported "MCP Client".

This project makes calling any MCP servers tools seemless from any agentic framework. Virtually providing your agentic worfklow access to 650+ MCP servers tools.

Look at glama.ai or smithery.ai to give you an idea of what your agent could access.

Installation Instructions

Smolagents

Smolagents 1.4.1 and above directly ships with mcpadapt integrated in their tool collections object. It means you can directly use it from smolagents:

uv add smolagents[mcp]

Other Frameworks

Each agent framework has its own set of optional dependencies to not clutter with useless dependencies. You choose the flavor you want by adding your framework in brackets in the installation command.

# with uv
uv add mcpadapt[langchain]

# or with pip
pip install mcpadapt[langchain]

Framework supported at the moment: smolagents, langchain, crewAI, google-genai.

You can also add multi

Read from source at commit 23d82025f966OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcpadapt --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env HF_TOKEN=${HF_TOKEN} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx mcpadapt
claude-desktop
{
  "mcpServers": {
    "mcpadapt": {
      "command": "uvx",
      "args": [
        "mcpadapt"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "HF_TOKEN": "${HF_TOKEN}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (18)

18 read · 0 write · 0 destructive.

ToolRiskDescription
custom_toolreadpass
defreadEcho the input text
dict_toolreadReturns a dictionary
echo-toolreadEcho the input text
echo_toolreadEcho the input text
echo_tool_default_valuereadEcho the input text, default to
echo_tool_optionalreadEcho the input text, or return a default message if no text is provided
echo_tool_union_nonereadEcho the input text, but None is not specified by default.
get_product_inforeadGet detailed information about a product
invalid_toolreadTool that returns invalid JSON when dict is expected.
list_toolreadReturns a list
multi_type_toolreadTest tool with a parameter that accepts multiple types using array notation
multiple_content_toolreadA tool that returns multiple content items
problematic_toolreadTool with empty union after null filtering
strict_toolreadA tool that expects only string values
string_toolreadReturns a string
test_audioreadpath = os.path.join(
test_imagereadpath = os.path.join(
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (15)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/mcpadapt/langchain_adapter.py:164
exec(generate_class_template(True), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/mcpadapt/langchain_adapter.py:167
exec(generate_class_template(False), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.binary · CWE-1104
tests/data/white_noise.wav
white_noise.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/quickstart.md:72
"url": "http://127.0.0.1:8000/sse",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/sse_usage.py:33
{"url": "http://127.0.0.1:8000/sse"},
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_core.py:110
yield {"url": f"http://127.0.0.1:{port}/sse"}
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_core.py:144
yield {"url": f"http://127.0.0.1:{port}/mcp", "transport": "streamable-http"}
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_crewai_adapter.py:163
yield {"url": f"http://127.0.0.1:{port}/sse"}
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/mcpadapt/smolagents_adapter.py:212
image_data = base64.b64decode(content_item.data)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/mcpadapt/smolagents_adapter.py:225
audio_data = base64.b64decode(content_item.data)
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/guide/crewai.md:94
# Load environment variables
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/guide/langchain.md:99
# Load environment variables
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/logo.png
docs/assets/logo.png
Why it matters. 1165453 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/logo_dark.png
docs/assets/logo_dark.png
Why it matters. 1357783 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 23d82025f966full audit observations/trust-audit/mcp-server/grll__mcpadapt.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0123d82025f966BLOCKD69first audit
06

Questions

What is the Mcpadapt MCP server?

Unlock 650+ MCP servers tools in your favorite agentic framework.

What tools does Mcpadapt expose?

18 in total: 18 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mcpadapt safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Mcpadapt need?

It reads ANTHROPIC_API_KEY, GEMINI_API_KEY, HF_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcpadapt run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcpadapt.

How current is this page?

The grade is for one exact copy of the source (23d82025f966), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement