NitanBLOCK
MCP client and Skill for US Card Forum
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Nitan MCP
Project Homepage: https://nitan.ai/mcp
This is a heavy modified version of Discourse MCP. It will be a dedicated MCP client for https://www.uscardforum.com/
Quick Installation
Prerequisites:
- Node.js 18 or higher (required)
- Python 3.7+ (required for Cloudflare bypass)
- pip (used via local
.venvPython)
Simplified setup by platform
macOS
npm install python3 -m venv .venv . .venv/bin/activate pip install -r requirements.txt
npm install will also auto-install playwright and the Chromium runtime on macOS for browser fallback.
Linux
npm install python3 -m venv .venv source .venv/bin/activate pip install -r requirements.txt
On non-macOS platforms, Playwright is not auto-installed.
Windows (PowerShell)
npm install py -3 -m venv .venv .\.venv\Scripts\Activate.ps1 pip install -r requirements.txt
On non-macOS platforms, Playwright is not auto-installed.
Run health check:
node dist/index.js doctor
Check your Node.js version:
node --version # Should be v18.0.0 or higher
If you need to upgrade Node.js:
# Using nvm (recommended) nvm install 18 nvm use 18 # Or download from https://nodejs.org/
Using npx (recommended):
npx -y @nitansde/mcp@latest
What happens automatically:
- ✅ Downloads and caches the package
- ✅ Installs Node.js dependencies
- ✅ Runs
postinstallscript to check/install Python dependencies - ✅ On macOS, auto-installs
playwrightpackage and Chromium runtime for browser fallback - ✅ Checks Python dependencies at runtime and shows helpful warnings if missing
If Python dependencies aren't installed automatically:
.venv/bin/python -m pip install cloudscraper curl-cffi # Or install from requirements.txt (recommended) .venv/bin/python -m pip install
79b3ac5f89b8OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp --env DISCOURSE_2FA_TOKEN=${DISCOURSE_2FA_TOKEN} --env NITAN_PASSWORD=${NITAN_PASSWORD} -- npx -y @nitansde/[email protected]{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@nitansde/[email protected]"
],
"env": {
"DISCOURSE_2FA_TOKEN": "${DISCOURSE_2FA_TOKEN}",
"NITAN_PASSWORD": "${NITAN_PASSWORD}"
}
}
}
}Exposed tools (15)
14 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
discourse_filter_topics | read | |
discourse_get_trust_level_progress | read | |
discourse_get_user | read | |
discourse_get_user_activity | read | |
discourse_list_categories | read | |
discourse_list_excellent_topics | read | |
discourse_list_funny_topics | read | |
discourse_list_hot_topics | read | |
discourse_list_notifications | read | |
discourse_list_tags | read | |
discourse_list_top_topics | read | |
discourse_read_post | write | |
discourse_read_topic | read | |
discourse_search | read | |
discourse_select_site | read |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
const dynamicImport = new Function("m", "return import(m)") as (m: string) => Promise<any>;const dynamicImport = new Function("m", "return import(m)") as (m: string) => Promise<any>;const dynamicImport = new Function("m", "return import(m)") as (m: string) => Promise<any>;console.warn(' • On Linux: sudo apt-get install python3 python3-pip');Use this path when the user prefers login-based access instead of API key setup.
print(f"[DEBUG] Obtained CSRF token: {token[:20]}...", file=sys.stderr)return this.options.openClawRelayCdpUrl || process.env.OPENCLAW_CHROME_RELAY_CDP_URL || "http://127.0.0.1:18792";
.gitmodules
.versionrc.json
const proc = spawn('node', [path.resolve(__dirname, '../../dist/index.js'), ...args], {const p = path.resolve(__dirname, '../../fixtures/try', name);
const indexPath = path.resolve(__dirname, '../../dist/index.js');
const indexPath = path.resolve(__dirname, '../../dist/index.js');
const indexPath = path.resolve(__dirname, '../../dist/index.js');
@modelcontextprotocol/sdk, zod, @types/node, standard-version, typescript
cloudscraper, brotli, curl-cffi
- Do not include install steps that execute remote scripts (`curl | bash`, encoded payloads, etc.).
system use found in code, not declared in the description
Gates applied: no_behavioural_pass.
79b3ac5f89b8full audit observations/trust-audit/mcp-server/nitansde__nitan.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 79b3ac5f89b8 | BLOCK | F | 55 | first audit |
Questions
What is the Nitan MCP server?
MCP client and Skill for US Card Forum
What tools does Nitan expose?
15 in total: 14 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Nitan safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Nitan need?
It reads DISCOURSE_2FA_TOKEN and NITAN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Nitan run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @nitansde/mcp at 2.1.1.
How current is this page?
The grade is for one exact copy of the source (79b3ac5f89b8), read on 2026-10-07. The repository is watched and re-audited when it changes.