Atlas / MCP servers / helpcode-ai / Anything

AnythingBLOCK

mcp/helpcode-ai/anything

Open-source, self-hosted MCP gateway: turn any REST/OpenAPI, SOAP, GraphQL, OData or SQL API into MCP tools for Claude, ChatGPT & Copilot. 299 connectors incl. SAP S/4HANA & Business One, ERP, e-commerce.

Verdict
BLOCK
Grade
F
Trust score
37 /100
Exposed tools
60 52r · 8w · 0d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
964
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AnythingMCP: self-hosted MCP gateway

English · Deutsch · 简体中文 · 日本語

AnythingMCP is an open-source, self-hosted MCP gateway that turns any REST/OpenAPI, SOAP, GraphQL, OData or SQL system into MCP tools for Claude, ChatGPT and Copilot, without writing an MCP server. It ships 299 ready connectors, among them SAP, Etsy, weclapp and Amazon Seller, and 16 of them need no API key.

<

Read from source at commit c47dbd1c4effOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add weclapp-mcp-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env AUTH_NEUTRAL_FLOOR_MS=${AUTH_NEUTRAL_FLOOR_MS} --env CLOCKIFY_API_KEY=${CLOCKIFY_API_KEY} -- npx -y weclapp-mcp-server
claude-desktop
{
  "mcpServers": {
    "weclapp-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "weclapp-mcp-server"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "API_KEY": "${API_KEY}",
        "AUTH_NEUTRAL_FLOOR_MS": "${AUTH_NEUTRAL_FLOOR_MS}",
        "CLOCKIFY_API_KEY": "${CLOCKIFY_API_KEY}"
      }
    }
  }
}
03

Exposed tools (60)

52 read · 8 write · 0 destructive.

ToolRiskDescription
BuchhaltungsButlerreadBuchhaltungsButler — German automated bookkeeping: postings, receipts, bank transactions, customers and suppliers.
DatabasereadConnect to PostgreSQL, MySQL, MariaDB, MSSQL, Oracle, SAP HANA, MongoDB, or SQLite. Supports read-only or read-write mode.
GoodreadA valid adapter
GraphQLreadConnect to GraphQL APIs with schema introspection.
GroupreadGroup
ODatareadConnect to OData V2/V4 services, including SAP S/4HANA and SAP Gateway. Services, fields and labels are read from $metadata.
Read-onlyread
UserreadUser Account
ViewerreadRead only
X-API-KeyreadKey from the Lumen Logistics dashboard.
__typereadInternal
a_gonereadold
a_readreadold
a_writewriteold
activeread
anythingmcp_connect_clientread
anythingmcp_get_startedread
anythingmcp_list_connectorsread
anythingmcp_overviewread
countread
country_by_codereadLook up a country by ISO 3166-1 alpha-2 code.
createUserwriteCreate a user
crm_get_customerreadGet a <customer> & more
etsy_get_authenticated_userreadwhoami
find_user_by_namereadFind a user row by exact name match. Bound via prepared statement.
get_database_schemareadRetrieve the full database schema: all tables, columns, data types, nullable flags, and primary keys.
get_example_queriesreadReturns example SQL query patterns for this ${dbType} database.
good_get_postwritex
good_lookupreadx
good_nrqlreadx
gr_search_stationsreadFind Georgian Railway stations by name and return their station_code, which every other tool needs.
idreadUser ID
idsread
itemsread
jph_get_postwriteFetch a single post from JSONPlaceholder by id.
kpi_dsoreadDSO
labelread
list_devicesreadList devices
nameread
number_to_wordsreadConvert an unsigned integer to its English word form.
okread
otherreadshort
priceread
sap_guidereadGuide
server-instructionsreadThe instructions this MCP server gives the model on connect: the server
setup_find_connectorsreadSearch the AnythingMCP catalog (265 ready connectors: ERPs, online shops, accounting, CRM, messaging, data APIs) for an app the user wants to connect. Returns each connector id, what setting it up involves, and which non-secret settings may be passed when installing.
setup_get_statusreadWhich connectors of the workspace are ready and which still need the user, each with a fresh link to finish it. While the workspace is on its free trial, also the days left and, for an administrator, the page where a plan is chosen. Call it after the user says they completed a setup link.
setup_install_connectorwriteInstall a catalog connector in the user
smoke-writewriteWrite-mode MySQL smoke test
splunk_run_querywritewhat this server version says
splunk_tool_from_a_newer_serverreadnew upstream tool
treadd
testread
test_toolreadA test tool
uidread
userreadGet user by id
usersreadGet users
weclapp_my_custom_reportreadmine
weclapp_unknown_toolreadx
whatsapp_send_messagewriteSend a WhatsApp message
04

Trust audit

BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (9 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/backend/src/connectors/engines/client-assertion.util.ts:119
* `-----BEGIN PRIVATE KEY-----MIIEv...-----END PRIVATE KEY-----`. Some tools
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/backend/src/connectors/engines/client-assertion.util.ts:137
'the private key is not a PEM key (expected "-----BEGIN PRIVATE KEY-----" ... "-----END PRIVATE KEY-----")',
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
packages/backend/src/audit/bound-payload.ts
bound-payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/backend/src/connectors/parsers/openapi.parser.ts:173
return yaml.load(input);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/ops/verify-adapter-with-connector.mjs:94
amcp-cloud-backend node -e "eval(Buffer.from(process.env.SRC,'base64').toString())"`;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/satellites/__snapshots__/odoo-mcp-server/scripts/install.sh:16
manifest() { node -e 'const m=require("./satellite.json");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))' "$1"; }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/satellites/__snapshots__/odoo-mcp-server/scripts/install.sh:17
json() { node -e 'let s="";process.stdin.on("data",d=>s+=d).on("end",()=>{const j=JSON.parse(s||"{}");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))})' "$1"; }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/satellites/__snapshots__/soap-to-mcp/scripts/install.sh:16
manifest() { node -e 'const m=require("./satellite.json");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))' "$1"; }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/satellites/__snapshots__/soap-to-mcp/scripts/install.sh:17
json() { node -e 'let s="";process.stdin.on("data",d=>s+=d).on("end",()=>{const j=JSON.parse(s||"{}");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))})' "$1"; }
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/backend/src/connectors/engines/unblocker-proxy-agent.ts:27
const insecure = { ...opts, rejectUnauthorized: false } as ConnectArgs[1];
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/backend/src/connectors/engines/unblocker-proxy-agent.ts:40
return new UnblockerProxyAgent(proxyUrl, { rejectUnauthorized: false });
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/backend/src/auth/auth.controller.ts:1078
.catch((err) => this.logger.warn(`Password reset email failed: ${err?.message ?? err}`));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/backend/src/auth/login.controller.ts:242
this.logger.warn(`Password login refused for SSO-only account: ${email}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/backend/src/connectors/engines/oauth2-token.service.ts:110
this.logger.debug(`OAuth2 (${grant}): token near expiry, proactive refresh...`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/backend/src/connectors/engines/oauth2-token.service.ts:342
this.logger.debug(`OAuth2 (${grant}): token refreshed successfully`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/backend/src/identity-providers/sso.service.ts:362
this.logger.warn(`SSO token exchange failed: ${e?.message}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/release.sh:328
json=$(docker exec "$CADDY_CONTAINER" wget -qO- http://127.0.0.1:2019/reverse_proxy/upstreams 2>/dev/null) || return 0
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/release.sh:366
PREVIEW_URL="http://127.0.0.1:${port}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/release.sh:552
if out=$(docker exec "$BACKEND_NAME" wget -qO- --post-data= "http://127.0.0.1:${BACKEND_PORT}/internal/registry/catch-up" 2>&1); then
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:31
DATABASE_URL: postgresql://amcp:testpassword@localhost:5432/anythingmcp_test
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/ci.yml:223
-e DATABASE_URL=postgresql://amcp:amcp@amcp-ci-db:5432/anythingmcp \
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/connectors/database.md:63
"baseUrl": "mongodb+srv://reader:[email protected]/analytics",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/deployment.md:103
DATABASE_URL=postgresql://amcp:your-local-password@localhost:5433/anythingmcp
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/backend/src/connectors/base-url.util.spec.ts:95
validateBaseUrl('mysql://bz-spjk:[email protected]:3306/bz-spjk', db),
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/backend/src/adapters/de/easybill.live.spec.ts:73
authConfig: { token: 'bogus-token-for-test' },

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha c47dbd1c4efffull audit observations/trust-audit/mcp-server/helpcode-ai__anything.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06c47dbd1c4effBLOCKF37first audit
06

Questions

What is the Anything MCP server?

Open-source, self-hosted MCP gateway: turn any REST/OpenAPI, SOAP, GraphQL, OData or SQL API into MCP tools for Claude, ChatGPT & Copilot. 299 connectors incl. SAP S/4HANA & Business One, ERP, e-commerce.

What tools does Anything expose?

60 in total: 52 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Anything safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (37/100) and found 11 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Anything need?

It reads ANTHROPIC_API_KEY, API_KEY, AUTH_NEUTRAL_FLOOR_MS, CLOCKIFY_API_KEY, CRON_SECRET, DESTATIS_PASSWORD, DESTATIS_USERNAME_OR_TOKEN, DIRECTUS_TOKEN, ENCRYPTION_KEY, ENTRA_SSO_CLIENT_SECRET, ENTRA_SSO_CLIENT_SECRET_EXPIRY_DATE and FIRMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Anything run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as weclapp-mcp-server.

How current is this page?

The grade is for one exact copy of the source (c47dbd1c4eff), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement