AnythingBLOCK
Open-source, self-hosted MCP gateway: turn any REST/OpenAPI, SOAP, GraphQL, OData or SQL API into MCP tools for Claude, ChatGPT & Copilot. 299 connectors incl. SAP S/4HANA & Business One, ERP, e-commerce.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AnythingMCP: self-hosted MCP gateway
English · Deutsch · 简体中文 · 日本語
AnythingMCP is an open-source, self-hosted MCP gateway that turns any REST/OpenAPI, SOAP, GraphQL, OData or SQL system into MCP tools for Claude, ChatGPT and Copilot, without writing an MCP server. It ships 299 ready connectors, among them SAP, Etsy, weclapp and Amazon Seller, and 16 of them need no API key.
<
c47dbd1c4effOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add weclapp-mcp-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env AUTH_NEUTRAL_FLOOR_MS=${AUTH_NEUTRAL_FLOOR_MS} --env CLOCKIFY_API_KEY=${CLOCKIFY_API_KEY} -- npx -y weclapp-mcp-server{
"mcpServers": {
"weclapp-mcp-server": {
"command": "npx",
"args": [
"-y",
"weclapp-mcp-server"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"API_KEY": "${API_KEY}",
"AUTH_NEUTRAL_FLOOR_MS": "${AUTH_NEUTRAL_FLOOR_MS}",
"CLOCKIFY_API_KEY": "${CLOCKIFY_API_KEY}"
}
}
}
}Exposed tools (60)
52 read · 8 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
BuchhaltungsButler | read | BuchhaltungsButler — German automated bookkeeping: postings, receipts, bank transactions, customers and suppliers. |
Database | read | Connect to PostgreSQL, MySQL, MariaDB, MSSQL, Oracle, SAP HANA, MongoDB, or SQLite. Supports read-only or read-write mode. |
Good | read | A valid adapter |
GraphQL | read | Connect to GraphQL APIs with schema introspection. |
Group | read | Group |
OData | read | Connect to OData V2/V4 services, including SAP S/4HANA and SAP Gateway. Services, fields and labels are read from $metadata. |
Read-only | read | |
User | read | User Account |
Viewer | read | Read only |
X-API-Key | read | Key from the Lumen Logistics dashboard. |
__type | read | Internal |
a_gone | read | old |
a_read | read | old |
a_write | write | old |
active | read | |
anythingmcp_connect_client | read | |
anythingmcp_get_started | read | |
anythingmcp_list_connectors | read | |
anythingmcp_overview | read | |
count | read | |
country_by_code | read | Look up a country by ISO 3166-1 alpha-2 code. |
createUser | write | Create a user |
crm_get_customer | read | Get a <customer> & more |
etsy_get_authenticated_user | read | whoami |
find_user_by_name | read | Find a user row by exact name match. Bound via prepared statement. |
get_database_schema | read | Retrieve the full database schema: all tables, columns, data types, nullable flags, and primary keys. |
get_example_queries | read | Returns example SQL query patterns for this ${dbType} database. |
good_get_post | write | x |
good_lookup | read | x |
good_nrql | read | x |
gr_search_stations | read | Find Georgian Railway stations by name and return their station_code, which every other tool needs. |
id | read | User ID |
ids | read | |
items | read | |
jph_get_post | write | Fetch a single post from JSONPlaceholder by id. |
kpi_dso | read | DSO |
label | read | |
list_devices | read | List devices |
name | read | |
number_to_words | read | Convert an unsigned integer to its English word form. |
ok | read | |
other | read | short |
price | read | |
sap_guide | read | Guide |
server-instructions | read | The instructions this MCP server gives the model on connect: the server |
setup_find_connectors | read | Search the AnythingMCP catalog (265 ready connectors: ERPs, online shops, accounting, CRM, messaging, data APIs) for an app the user wants to connect. Returns each connector id, what setting it up involves, and which non-secret settings may be passed when installing. |
setup_get_status | read | Which connectors of the workspace are ready and which still need the user, each with a fresh link to finish it. While the workspace is on its free trial, also the days left and, for an administrator, the page where a plan is chosen. Call it after the user says they completed a setup link. |
setup_install_connector | write | Install a catalog connector in the user |
smoke-write | write | Write-mode MySQL smoke test |
splunk_run_query | write | what this server version says |
splunk_tool_from_a_newer_server | read | new upstream tool |
t | read | d |
test | read | |
test_tool | read | A test tool |
uid | read | |
user | read | Get user by id |
users | read | Get users |
weclapp_my_custom_report | read | mine |
weclapp_unknown_tool | read | x |
whatsapp_send_message | write | Send a WhatsApp message |
Trust audit
BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (9 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
* `-----BEGIN PRIVATE KEY-----MIIEv...-----END PRIVATE KEY-----`. Some tools
'the private key is not a PEM key (expected "-----BEGIN PRIVATE KEY-----" ... "-----END PRIVATE KEY-----")',
bound-payload.ts
return yaml.load(input);
amcp-cloud-backend node -e "eval(Buffer.from(process.env.SRC,'base64').toString())"`;
manifest() { node -e 'const m=require("./satellite.json");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))' "$1"; }json() { node -e 'let s="";process.stdin.on("data",d=>s+=d).on("end",()=>{const j=JSON.parse(s||"{}");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))})' "$1"; }manifest() { node -e 'const m=require("./satellite.json");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))' "$1"; }json() { node -e 'let s="";process.stdin.on("data",d=>s+=d).on("end",()=>{const j=JSON.parse(s||"{}");const v=eval(process.argv[1]);process.stdout.write(v==null?"":String(v))})' "$1"; }const insecure = { ...opts, rejectUnauthorized: false } as ConnectArgs[1];return new UnblockerProxyAgent(proxyUrl, { rejectUnauthorized: false });.catch((err) => this.logger.warn(`Password reset email failed: ${err?.message ?? err}`));this.logger.warn(`Password login refused for SSO-only account: ${email}`);this.logger.debug(`OAuth2 (${grant}): token near expiry, proactive refresh...`);this.logger.debug(`OAuth2 (${grant}): token refreshed successfully`);this.logger.warn(`SSO token exchange failed: ${e?.message}`);json=$(docker exec "$CADDY_CONTAINER" wget -qO- http://127.0.0.1:2019/reverse_proxy/upstreams 2>/dev/null) || return 0
PREVIEW_URL="http://127.0.0.1:${port}"if out=$(docker exec "$BACKEND_NAME" wget -qO- --post-data= "http://127.0.0.1:${BACKEND_PORT}/internal/registry/catch-up" 2>&1); thenDATABASE_URL: postgresql://amcp:testpassword@localhost:5432/anythingmcp_test
-e DATABASE_URL=postgresql://amcp:amcp@amcp-ci-db:5432/anythingmcp \
"baseUrl": "mongodb+srv://reader:[email protected]/analytics",
DATABASE_URL=postgresql://amcp:your-local-password@localhost:5433/anythingmcp
validateBaseUrl('mysql://bz-spjk:[email protected]:3306/bz-spjk', db),authConfig: { token: 'bogus-token-for-test' },Gates applied: critical_finding, no_behavioural_pass.
c47dbd1c4efffull audit observations/trust-audit/mcp-server/helpcode-ai__anything.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | c47dbd1c4eff | BLOCK | F | 37 | first audit |
Questions
What is the Anything MCP server?
Open-source, self-hosted MCP gateway: turn any REST/OpenAPI, SOAP, GraphQL, OData or SQL API into MCP tools for Claude, ChatGPT & Copilot. 299 connectors incl. SAP S/4HANA & Business One, ERP, e-commerce.
What tools does Anything expose?
60 in total: 52 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Anything safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (37/100) and found 11 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Anything need?
It reads ANTHROPIC_API_KEY, API_KEY, AUTH_NEUTRAL_FLOOR_MS, CLOCKIFY_API_KEY, CRON_SECRET, DESTATIS_PASSWORD, DESTATIS_USERNAME_OR_TOKEN, DIRECTUS_TOKEN, ENCRYPTION_KEY, ENTRA_SSO_CLIENT_SECRET, ENTRA_SSO_CLIENT_SECRET_EXPIRY_DATE and FIRMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Anything run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as weclapp-mcp-server.
How current is this page?
The grade is for one exact copy of the source (c47dbd1c4eff), read on 2026-10-06. The repository is watched and re-audited when it changes.