Atlas / MCP servers / isdaniel / Weather

WeatherCAUTION

mcp/isdaniel/weather-3

A Model Context Protocol (MCP) server that provides weather information using the Open-Meteo API.

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
—
Transport
stdio · streamable-http
License
Apache-2.0
Stars
61
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://lightnow.ai/servers/io.github.isdaniel/mcpweatherserver) [](https://pypi.org/project/mcp-weather-server/) [](https://pypi.org/project/mcp-weather-server/) [](https://pepy.tech/projects/mcp-weather-server) [](https://hub.docker.com/r/dog830228/mcpweatherserver)

mcp-name: io.github.isdaniel/mcpweatherserver

A Model Context Protocol (MCP) server that provides weather information using the Open-Meteo API. This server supports multiple transport modes: standard stdio, HTTP Server-Sent Events (SSE), and the new Streamable HTTP protocol for web-based integration.

Features

Weather & Air Quality

  • Get current weather information with comprehensive metrics:
  • Temperature, humidity, dew point
  • Wind speed, direction, and gusts
  • Precipitation (rain/snow) and probability
  • Atmospheric pressure and cloud cover
  • UV index and visibility
  • "Feels like" temperature
  • Sunrise and sunset times (local time at the location)
  • Get weather data for a date range with hourly details and daily sunrise/sunset times
  • Get air quality information including:
  • PM2.5 and PM10 particulate matter
  • Ozone, nitrogen dioxide, carbon monoxide
  • Sulfur dioxide, ammonia, dust
  • Aerosol optical depth
  • Health advisories and recommendations

Time & Timezone

  • Get current date/time in any time
Read from source at commit 4b56ace09908OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add mcp-weather-server -- None mcp-weather-server==0.6.1
03

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/mcp_weather_server/tools/air_quality_service.py:126
response_parts.append(f"PM2.5: {pm25:.1f} μg/m3 ({pm25_level})")
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/mcp_weather_server/tools/air_quality_service.py:132
response_parts.append(f"PM10: {pm10:.1f} μg/m3 ({pm10_level})")
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/mcp_weather_server/tools/air_quality_service.py:137
response_parts.append(f"Ozone (O3): {ozone:.1f} μg/m3")
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/mcp_weather_server/tools/air_quality_service.py:142
response_parts.append(f"Nitrogen Dioxide (NO2): {no2:.1f} μg/m3")
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/mcp_weather_server/tools/air_quality_service.py:147
response_parts.append(f"Carbon Monoxide (CO): {co:.1f} μg/m3")
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
httpx, mcp, python-dateutil, starlette, uvicorn, tzdata
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/agents/weather-assistant.md:8
You are a weather assistant powered by the MCP Weather Server. You have access to 8 tools that fetch real-time weather, air quality, and timezone data via the Open-Meteo API (free, no API key required
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4b56ace09908full audit observations/trust-audit/mcp-server/isdaniel__weather-3.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084b56ace09908CAUTIONB87first audit
05

Questions

What is the Weather MCP server?

A Model Context Protocol (MCP) server that provides weather information using the Open-Meteo API.

Is Weather safe to connect to an agent?

With care. The audit graded it B (87/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Weather need?

No credential environment variables were found in its source, so it appears to need none.

How does Weather run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp_weather_server.

How current is this page?

The grade is for one exact copy of the source (4b56ace09908), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement