Atlas / MCP servers / jalpp / ChessAgine

ChessAgineCAUTION

mcp/jalpp/chessagine

ChessAgine MCP is a MCP server that gives AI agents access to chess domain knowledge.

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
38 32r · 6w · 0d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Is a MCP server that gives AI agents access to chess domain knowledge.

Installation

Read the install.md guide on how to set up mcp server on local or connect to the remote server.

License

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0).

You may copy, modify, and distribute this software under the terms of the AGPL-3.0 license.

Network Use (SaaS)

If you modify this software and run it as a service accessible over a network, you must make the complete corresponding source code of your modified version available to users of that service, as required by the AGPL-3.0.

Disclaimer

This program is distributed WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the AGPL-3.0 for more details.

ChessAgine MCP does not guarantee tool success for third-party APIs including Chessboardmagic, Lichess, ChessDojo, ChessDB, Posira. Functionality and availability of these integrations depend on the stability and policies of these external services. Users are responsible for understanding and complying with the terms of service of any third-party APIs they access through this tool.

No Warranty: This software comes with no warranty of any kind, expressed or implied, regarding functionality, reliability, or fitness for a particular purpose.

See the LICENSE file for additional details.

Authors

ChessAgine MCP by @jalpp

Read from source at commit 774c01b94c29OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add chessagine-mcp --env DOJO_PAT_TOKEN=${DOJO_PAT_TOKEN} --env LICHESS_API_TOKEN=${LICHESS_API_TOKEN} --env POSIRA_API_KEY=${POSIRA_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "chessagine-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DOJO_PAT_TOKEN": "${DOJO_PAT_TOKEN}",
        "LICHESS_API_TOKEN": "${LICHESS_API_TOKEN}",
        "POSIRA_API_KEY": "${POSIRA_API_KEY}"
      }
    }
  }
}
03

Exposed tools (38)

32 read · 6 write · 0 destructive.

ToolRiskDescription
fen-openingbook-lookupreadLook up a fen in 12k positions of opening book to get name, moves information for fen
fetch-chess-puzzlereadFetch a random chess puzzle from the Lichess-backed puzzle service. Can filter by themes and rating range. Use this to start a puzzle session with the user.
fetch-lichess-gamereadFetch a specific Lichess game in PGN format by game ID.
fetch-lichess-gamesreadFetch recent games for a Lichess user in a simple text-friendly format.
fetch-lichess-studiesreadFetch all studies for a given Lichess user. Returns a list of studies with their IDs, names, and timestamps.
fetch-lichess-study-pgnreadFetch a specific Lichess study in PGN format. Returns all chapters of the study as PGN.
get-chess-knowledgereadGet the curated chess knowledge base as a JSON object.
get-chessboardmagic-corr-gamesreadFetch correspondence chess games that reached a specific chess position
get-chessboardmagic-corr-statsreadFetch correspondence chess statistics for a specific chess position
get-chessboardmagic-game-detailsreadFetch user
get-chessboardmagic-gamesreadFetch user
get-chessboardmagic-repertoire-detailsreadFetch user
get-chessboardmagic-repertoiresreadFetch user
get-chessboardmagic-tcec-gamesreadFetch actual TCEC (Top Chess Engine Championship) games that reached a specific position, or games played by a specific engine. Returns complete game records from the strongest engine matches. Results are paginated and can be sorted by rating or date. Provide at least one of
get-chessboardmagic-tcec-statsreadFetch TCEC (Top Chess Engine Championship) statistics for a specific chess position
get-chessdb-analysisreadFetch position analysis and candidate moves from ChessDB
get-chessdb-expand-queuereadExpand a ChessDB position tree using breadth-first search and queue up to 20 positions via tree search
get-chessdb-pvreadFetch the principal variation (best line) for a position from ChessDB
get-dojo-pat-userreadFetch the ChessDojo training plan user tied to the caller
get-dojo-requirementsreadFetch ChessDojo training plan requirements for a given cohort.
get-fen-map-lookupwriteLookup fens for mapped SAN move, for given game PGN
get-leela-analysisreadAnalyze chess position using Leela Chess Zero neural network. Provides strong tactical analysis with neural network evaluation and candidate moves, and estimated converted stockfish like centi-pawn eval. Uses T1-256x10 neural net, trained on self played games
get-lichess-gamereadFetch a specific Lichess game in PGN format by game ID.
get-lichess-gamesreadFetch Lichess user games and opening statistics for a given position
get-lichess-master-gamesreadFetch master-level games and opening statistics from Lichess for a given position
get-lichess-studiesreadFetch all studies for a given Lichess user. Returns a list of studies with their IDs, names, and timestamps.
get-lichess-study-pgnreadFetch a specific Lichess study in PGN format. Returns all chapters of the study as PGN.
get-maia3-analysisreadAnalyze chess position using Maia3 neural network trained on human games at specific rating levels. Provides human-like move suggestions and evaluations, and estimated human eval HEE, tailored to player strength (600-2600 rating).
get-maia3-batch-analysisreadAnalyze chess position using Maia3 neural network across all rating levels (600-2600). Returns analyses for all 21 Maia3 rating models in a single batch request.
get-puzzle-themesreadGet a list of all available puzzle themes that can be used to filter puzzles
get-stockfish-analysisreadAnalyze a chess position using Stockfish 18 Multi-threated Lite WASM engine
get-stockfish-batch-analysisreadAnalyze multiple chess positions in batch using Stockfish 18 Multi-threated Lite WASM engine
get-stockfish-best-movewriteFind the best move in a chess position using Stockfish 18 Multi-threated Lite WASM engine
get-stockfish-multipv-analysiswriteAnalyze a chess position and get multiple best move candidates with Stockfish 18 Multi-threated Lite WASM engine
is-legal-movewriteCheck if a given move is legal for the provided FEN position
parse-pgn-into-move-fenswriteParses a PGN into a move list object containing move information like before, after FEN, move notation, and move numbers
queue-chessdb-analysisreadQueue a single chess position for background analysis on ChessDB
update-dojo-progresswriteUpdate the caller
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (10)

MEDIUMInventory / provenance · inv.binary · CWE-1104
chessagine-skill/chessagine-mcp-v070.skill
chessagine-mcp-v070.skill
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
api/mcp.ts:17
token: "chessagine-remote-passthrough",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/runner/remote.ts:43
token: "chessagine-remote-passthrough",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/remote/registerCbmContract.remote.ts:12
} from "../../runner/schema.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/remote/registerCbmContract.remote.ts:13
import { SERVICE_CONFIG_BASE_URL_MAP } from "../../services/config.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/remote/registerDojoContract.remote.ts:12
} from "../../runner/schema.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/remote/registerDojoContract.remote.ts:13
import { SERVICE_CONFIG_BASE_URL_MAP } from "../../services/config.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/remote/registerLichessContract.remote.ts:2
import { fenSchema, puzzleThemesArraySchema, tokenSchema } from "../../runner/schema.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@jalpp/mcp-adapter, @modelcontextprotocol/express, @modelcontextprotocol/ext-apps, @modelcontextprotocol/inspector, @modelcontextprotocol/node, @modelcontextprotocol/server, axios, chess.js
Why it matters. 29 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 774c01b94c29full audit observations/trust-audit/mcp-server/jalpp__chessagine.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08774c01b94c29CAUTIONB86first audit
06

Questions

What is the ChessAgine MCP server?

ChessAgine MCP is a MCP server that gives AI agents access to chess domain knowledge.

What tools does ChessAgine expose?

38 in total: 32 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ChessAgine safe to connect to an agent?

With care. The audit graded it B (86/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does ChessAgine need?

It reads DOJO_PAT_TOKEN, LICHESS_API_TOKEN and POSIRA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ChessAgine run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as chessagine-mcp at 0.8.1.

How current is this page?

The grade is for one exact copy of the source (774c01b94c29), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement