Atlas / MCP servers / nitansde / Nitan

NitanBLOCK

mcp/nitansde/nitan

MCP client and Skill for US Card Forum

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
15 14r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
123
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Nitan MCP

Project Homepage: https://nitan.ai/mcp

论坛开发讨论贴

This is a heavy modified version of Discourse MCP. It will be a dedicated MCP client for https://www.uscardforum.com/

Quick Installation

Prerequisites:

  • Node.js 18 or higher (required)
  • Python 3.7+ (required for Cloudflare bypass)
  • pip (used via local .venv Python)

Simplified setup by platform

macOS

npm install
python3 -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt

npm install will also auto-install playwright and the Chromium runtime on macOS for browser fallback.

Linux

npm install
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

On non-macOS platforms, Playwright is not auto-installed.

Windows (PowerShell)

npm install
py -3 -m venv .venv
.\.venv\Scripts\Activate.ps1
pip install -r requirements.txt

On non-macOS platforms, Playwright is not auto-installed.

Run health check:

node dist/index.js doctor

Check your Node.js version:

node --version  # Should be v18.0.0 or higher

If you need to upgrade Node.js:

# Using nvm (recommended)
nvm install 18
nvm use 18

# Or download from https://nodejs.org/

Using npx (recommended):

npx -y @nitansde/mcp@latest

What happens automatically:

  1. ✅ Downloads and caches the package
  2. ✅ Installs Node.js dependencies
  3. ✅ Runs postinstall script to check/install Python dependencies
  4. ✅ On macOS, auto-installs playwright package and Chromium runtime for browser fallback
  5. ✅ Checks Python dependencies at runtime and shows helpful warnings if missing

If Python dependencies aren't installed automatically:

.venv/bin/python -m pip install cloudscraper curl-cffi
# Or install from requirements.txt (recommended)
.venv/bin/python -m pip install 
Read from source at commit 79b3ac5f89b8OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp --env DISCOURSE_2FA_TOKEN=${DISCOURSE_2FA_TOKEN} --env NITAN_PASSWORD=${NITAN_PASSWORD} -- npx -y @nitansde/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@nitansde/[email protected]"
      ],
      "env": {
        "DISCOURSE_2FA_TOKEN": "${DISCOURSE_2FA_TOKEN}",
        "NITAN_PASSWORD": "${NITAN_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (15)

14 read · 1 write · 0 destructive.

ToolRiskDescription
discourse_filter_topicsread
discourse_get_trust_level_progressread
discourse_get_userread
discourse_get_user_activityread
discourse_list_categoriesread
discourse_list_excellent_topicsread
discourse_list_funny_topicsread
discourse_list_hot_topicsread
discourse_list_notificationsread
discourse_list_tagsread
discourse_list_top_topicsread
discourse_read_postwrite
discourse_read_topicread
discourse_searchread
discourse_select_siteread
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/http/browser_fallback.ts:194
const dynamicImport = new Function("m", "return import(m)") as (m: string) => Promise<any>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/http/browser_fallback.ts:778
const dynamicImport = new Function("m", "return import(m)") as (m: string) => Promise<any>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/index.ts:360
const dynamicImport = new Function("m", "return import(m)") as (m: string) => Promise<any>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
scripts/check-python-deps.mjs:48
console.warn('  • On Linux: sudo apt-get install python3 python3-pip');
Why it matters. asks for elevated privileges
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/nitan/SKILL.md:97
Use this path when the user prefers login-based access instead of API key setup.
Why it matters. asks the agent to read credentials
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/http/curl_cffi_wrapper.py:95
print(f"[DEBUG] Obtained CSRF token: {token[:20]}...", file=sys.stderr)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/http/browser_fallback.ts:726
return this.options.openClawRelayCdpUrl || process.env.OPENCLAW_CHROME_RELAY_CDP_URL || "http://127.0.0.1:18792";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.versionrc.json
.versionrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/index_cli.test.ts:16
const proc = spawn('node', [path.resolve(__dirname, '../../dist/index.js'), ...args], {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/tools.test.ts:86
const p = path.resolve(__dirname, '../../fixtures/try', name);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/transport.test.ts:73
const indexPath = path.resolve(__dirname, '../../dist/index.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/transport.test.ts:87
const indexPath = path.resolve(__dirname, '../../dist/index.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/test/transport.test.ts:115
const indexPath = path.resolve(__dirname, '../../dist/index.js');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, standard-version, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
cloudscraper, brotli, curl-cffi
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
skills/nitan/SKILL.md:201
- Do not include install steps that execute remote scripts (`curl | bash`, encoded payloads, etc.).
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 79b3ac5f89b8full audit observations/trust-audit/mcp-server/nitansde__nitan.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0779b3ac5f89b8BLOCKF55first audit
06

Questions

What is the Nitan MCP server?

MCP client and Skill for US Card Forum

What tools does Nitan expose?

15 in total: 14 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Nitan safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Nitan need?

It reads DISCOURSE_2FA_TOKEN and NITAN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Nitan run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @nitansde/mcp at 2.1.1.

How current is this page?

The grade is for one exact copy of the source (79b3ac5f89b8), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement