Review AnalyzerSAFE
Review Analyzer — agent-native VOC for e-commerce. 6 MCP tools, ASIN or CSV input, black-gold dashboard. Backed by Shulex VOC OpenAPI (10 markets).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Review Analyzer
Agent-native voice-of-customer for e-commerce. Drop in an ASIN or a CSV — get sentiment, pain points, copy-ready listing improvements, and a black-gold HTML dashboard. 6 MCP tools. Backed by the most stable Amazon review data layer.
↑ Sample dashboard: B08N5WRWNW · 100 reviews · sentiment + pain points + listing improvements, generated by render_dashboard.
TL;DR
Two inputs, six tools, three outputs.
┌─────────────┐ ┌──────────────┐ │ ASIN │──┐ ┌─│ Markdown │ └─────────────┘ │ ┌─────────────────────────┐ │ │ report │ ├──────▶ 6 agent-calla
7794107f5699OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add voc-amazon-reviews-mcp --env VOC_API_KEY=${VOC_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- None voc-amazon-reviews-mcp==0.1.1Exposed tools (6)
4 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_csv | read | Analyze any review CSV / Excel — not just Amazon. |
analyze_reviews | write | Run AI analysis on reviews you already have. |
extract_listing_improvements | read | Differentiator tool — derive specific, copyable listing improvements |
fetch_reviews | read | Fetch raw Amazon reviews for an ASIN via the Shulex VOC API. |
render_dashboard | read | Render a VOC report as a standalone black-gold HTML dashboard. |
voc_full | write | One-shot: fetch reviews AND run AI analysis. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
pytest, pytest-mock
mcp, anthropic, pydantic, pandas, openpyxl, PyYAML
mcp, anthropic, pydantic, httpx, pandas, openpyxl, PyYAML
<div>open source · BYO API key</div>
Gates applied: no_behavioural_pass, no_license.
7794107f5699full audit observations/trust-audit/mcp-server/mguozhen__review-analyzer.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7794107f5699 | SAFE | B | 89 | first audit |
Questions
What is the Review Analyzer MCP server?
Review Analyzer — agent-native VOC for e-commerce. 6 MCP tools, ASIN or CSV input, black-gold dashboard. Backed by Shulex VOC OpenAPI (10 markets).
What tools does Review Analyzer expose?
6 in total: 4 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Review Analyzer safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Review Analyzer need?
It reads ANTHROPIC_API_KEY and VOC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Review Analyzer run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as voc-amazon-reviews-mcp.
How current is this page?
The grade is for one exact copy of the source (7794107f5699), read on 2026-10-08. The repository is watched and re-audited when it changes.