Omni-LPRSAFE
A multi-interface (REST and MCP) server for automatic license plate recognition 🚗
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Omni-LPR
[](https://github.com/habedi/omni-lpr/actions/workflows/tests.yml) [](https://codecov.io/gh/habedi/omni-lpr) [](https://www.codefactor.io/repository/github/habedi/omni-lpr) [](https://github.com/habedi/omni-lpr) [](https://pypi.org/project/omni-lpr/) [](https://github.com/habedi/omni-lpr/blob/main/LICENSE)
[](https://github.com/habedi/omni-lpr/tree/main/docs) [](https://github.com/habedi/omni-lpr/tree/main/examples) [](https://github.com/habedi/omni-lpr/pkgs/container/omni-lpr-cpu) [](https://github.com/habedi/omni-lpr/pkgs/container/omni-lpr-openvino) [](https
3c38ec86917eOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add omni-lpr -- None omni-lpr==0.3.5
Trust audit
SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (10)
streamable-http
.pre-commit-config.yaml
By default, the server will be listening on `http://127.0.0.1:8000`.
curl http://127.0.0.1:8000/api/health
http://127.0.0.1:8000/api/v1/tools/detect_and_recognize_plate_from_path/invoke
at http://127.0.0.1:8000/api/v1/apidoc/swagger.
http://127.0.0.1:8000/mcp/, via streamable HTTP.
base64.b64decode(v)
image_bytes = base64.b64decode(image_base64)
Gates applied: no_behavioural_pass.
3c38ec86917efull audit observations/trust-audit/mcp-server/habedi__omni-lpr.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 3c38ec86917e | SAFE | B | 88 | first audit |
Questions
What is the Omni-LPR MCP server?
A multi-interface (REST and MCP) server for automatic license plate recognition 🚗
Is Omni-LPR safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Omni-LPR need?
No credential environment variables were found in its source, so it appears to need none.
How does Omni-LPR run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as omni-lpr.
How current is this page?
The grade is for one exact copy of the source (3c38ec86917e), read on 2026-10-09. The repository is watched and re-audited when it changes.