Atlas / MCP servers / jordanlyall / World Cup 2026 Companion

World Cup 2026 CompanionCAUTION

mcp/jordanlyall/world-cup-2026-companion

AI companion for FIFA World Cup 2026 — 18 tools covering matches, teams, venues, city guides, fan zones, visa info, head-to-head records, and more. Works with Claude, ChatGPT, Cursor, and Telegram.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
18 17r · 1w · 0d
Transport
stdio
License
MIT
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/wc26-mcp) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io)

Ask your AI anything about the 2026 World Cup and get real answers. 18 tools covering matches, teams, venues, city guides, fan zones, head-to-head records, visa info, news, injuries, odds, standings, knockout bracket, and more. All data ships with the package. Zero API keys, zero external dependencies.

Works with Claude Desktop · Claude Code · Cursor · Windsurf · ChatGPT · Telegram · any MCP client

[Website](https://wc26.ai) | [npm](https://www.npmjs.com/package/wc26-mcp) | [ChatGPT GPT](https://chatgpt.com/g/g-698d038f171481919ada44947304a196-world-cup-2026-companion) | [Telegram Bot](https://t.me/wc26ai_bot) | [MCP Registry](https://registry.modelcontextprotocol.io)

Quick Start

Claude Desktop

Add to your claude_desktop_config.json:

{
"mcpServers": {
"wc26": {
"command": "npx",
"args": ["-y", "wc26-mcp"]
}
}
}

Claude Code

claude mcp add wc26 -- npx -y wc26-mcp

Cursor

Add to .cursor/mcp.json:

{
"mcpServers": {
"wc26": {
"command": "npx",
"args": ["-y", "wc26-mcp"]
}
}
}

Windsurf

Add to ~/.codeium/windsurf/mcp_config.json:

{
"mcpServers": {
"wc26": {
"command": "npx",
"args": ["-y", "wc26-mcp"]
}
}
}

ChatGPT

No setup needed — use the GPT directly:

**[Open World Cup 2026 Companion](https://chatgpt.com/g/g-698d038f171481919ada44947304a1

Read from source at commit 217610e9f5c7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add wc26-mcp -- npx -y [email protected]
03

Exposed tools (18)

17 read · 1 write · 0 destructive.

ToolRiskDescription
compare_teamsread
get_bracketread
get_city_guideread
get_fan_zonesread
get_groupsread
get_historical_matchupsread
get_injuriesread
get_matchesread
get_nearby_venuesread
get_newsread
get_oddsread
get_schedulewrite
get_standingsread
get_team_profileread
get_teamsread
get_venuesread
get_visa_inforead
what_to_know_nowread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/data/news.ts:3490
"title": "Lionel Messi called up by Argentina to make farewell appearance in friendly",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/data/news.ts:3494
"summary": "Lionel Messi called up by Argentina to make farewell appearance in friendly",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.claudeignore
.claudeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, @vercel/node, rss-parser, tsx, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 217610e9f5c7full audit observations/trust-audit/mcp-server/jordanlyall__world-cup-2026-companion.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08217610e9f5c7CAUTIONB89first audit
06

Questions

What is the World Cup 2026 Companion MCP server?

AI companion for FIFA World Cup 2026 — 18 tools covering matches, teams, venues, city guides, fan zones, visa info, head-to-head records, and more. Works with Claude, ChatGPT, Cursor, and Telegram.

What tools does World Cup 2026 Companion expose?

18 in total: 17 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is World Cup 2026 Companion safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does World Cup 2026 Companion need?

It reads ANTHROPIC_API_KEY and TELEGRAM_BOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does World Cup 2026 Companion run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as wc26-mcp at 0.3.1.

How current is this page?

The grade is for one exact copy of the source (217610e9f5c7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement