Atlas / MCP servers / livetennisapi / Live Tennis API

Live Tennis APIBLOCK

mcp/livetennisapi/live-tennis-api

MCP server for the Live Tennis API — give Claude, Cursor and other LLM agents real-time tennis scores, odds and model win-probability

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
24 24r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
152
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP server for the [Live Tennis API](https://livetennisapi.com).

Give Claude, Cursor, Zed or any MCP client live tennis scores, players and fixtures — for ATP, WTA, Challenger, ITF and juniors. Odds, rankings, match statistics, charting and model win-probability tools are included, and require the PRO and ULTRA plans.

[](https://github.com/livetennisapi/livetennisapi-mcp/actions/workflows/ci.yml) [](https://www.npmjs.com/package/livetennisapi-mcp) [](LICENSE)

**Documentation** · **Get a free API key**

Setup

Claude Code

claude mcp add livetennis -e LIVETENNISAPI_KEY=twjp_... -- npx -y livetennisapi-mcp

Claude Desktop — add to claude_desktop_config.json:

{
"mcpServers": {
"livetennis": {
"command": "npx",
"args": ["-y", "livetennisapi-mcp"],
"env": { "LIVETENNISAPI_KEY": "twjp_..." }
}
}
}

Cursor / Zed / others — same command, same env var. No install step; npx fetches it on demand.

Get a free key (no card) at livetennisapi.com, or a paid plan at pricing.

Try it

"What tennis matches are live right now?" "Who's winning the Alcaraz match, and what does the model give him?" "Show me Sinner's ranking and recent results." "What are the current odds on match 18953?" "What's the all-time head-to-head between Borg and McEnroe?" "List Navratilova's Grand Slam finals from the archive." *"Who was ATP #1 the week Al
Read from source at commit 914b1cf2ace5OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add livetennisapi-mcp --env LIVETENNISAPI_KEY=${LIVETENNISAPI_KEY} -- npx -y [email protected]
03

Exposed tools (24)

24 read · 0 write · 0 destructive.

ToolRiskDescription
check_api_statusread
get_archive_careerread
get_archive_matchread
get_charting_matchread
get_charting_playerread
get_fixturesread
get_h2hread
get_live_matchesread
get_matchread
get_match_analysisread
get_match_eventsread
get_match_oddsread
get_match_scoreread
get_match_statisticsread
get_playerread
get_player_rankingsread
get_rankingsread
get_recent_resultsread
get_tournamentread
get_upcoming_matchesread
search_archive_matchesread
search_archive_playersread
search_playersread
search_tournamentsread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
deploy/install-http.sh:22
[[ $EUID -eq 0 ]] || die "must be run as root (sudo)"
Why it matters. asks for elevated privileges
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
deploy/install-http.sh:64
systemctl enable "$UNIT_NAME" >/dev/null
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
deploy/install-http.sh:17
UNIT_DST="/etc/systemd/system/$UNIT_NAME"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/install-http.sh:69
if curl -fsS --max-time 2 "http://127.0.0.1:$PORT/health" >/dev/null 2>&1; then break; fi
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/install-http.sh:73
health=$(curl -fsS --max-time 5 "http://127.0.0.1:$PORT/health" 2>/dev/null) \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/install-http.sh:88
anon=$(curl -fsS --max-time 10 -X POST "http://127.0.0.1:$PORT/mcp" \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/install-http.sh:104
tools=$(curl -fsS --max-time 10 -X POST "http://127.0.0.1:$PORT/mcp" \
MEDIUMPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/http-isolation.mjs:27
const URL = `http://127.0.0.1:${PORT}/mcp`;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, express, express-rate-limit, livetennisapi, zod, @types/express, @types/node, esbuild
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 914b1cf2ace5full audit observations/trust-audit/mcp-server/livetennisapi__live-tennis-api.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06914b1cf2ace5BLOCKD69first audit
06

Questions

What is the Live Tennis API MCP server?

MCP server for the Live Tennis API — give Claude, Cursor and other LLM agents real-time tennis scores, odds and model win-probability

What tools does Live Tennis API expose?

24 in total: 24 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Live Tennis API safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Live Tennis API need?

It reads LIVETENNISAPI_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Live Tennis API run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as livetennisapi-mcp at 1.5.0.

How current is this page?

The grade is for one exact copy of the source (914b1cf2ace5), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement