OrionBelt Semantic LayerBLOCK
Source-available semantic and context layer, rule engine, and semantic sidecar for agentic AI and governed analytics. Compiles declarative YAML models into optimized SQL, KPIs, and semantic context across 8 SQL dialects.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
OrionBelt® Semantic and Context Layer, Rule Engine, and Semantic Sidecar
Define your metrics once in YAML. Let agents and BI tools query them without ever touching your schema.
A semantic sidecar: it rides alongside the systems you already run instead of replacing them.
Ask an LLM to write SQL against a raw star schema and sooner or later it joins two fact tables and hands you a revenue number inflated by a factor of eight. It looks right. Nobody catches it.
OrionBelt is a semantic and context layer with a rule engine, and it runs as a **[semanti
f38e74b5a47aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add orionbelt-semantic-layer --env API_KEY_HEADER=${API_KEY_HEADER} --env CLICKHOUSE_PASSWORD=${CLICKHOUSE_PASSWORD} --env DATABRICKS_ACCESS_TOKEN=${DATABRICKS_ACCESS_TOKEN} --env DATABRICKS_TOKEN=${DATABRICKS_TOKEN} -- uvx orionbelt-semantic-layer{
"mcpServers": {
"orionbelt-semantic-layer": {
"command": "uvx",
"args": [
"orionbelt-semantic-layer"
],
"env": {
"API_KEY_HEADER": "${API_KEY_HEADER}",
"CLICKHOUSE_PASSWORD": "${CLICKHOUSE_PASSWORD}",
"DATABRICKS_ACCESS_TOKEN": "${DATABRICKS_ACCESS_TOKEN}",
"DATABRICKS_TOKEN": "${DATABRICKS_TOKEN}"
}
}
}
}Exposed tools (112)
84 read · 18 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
addCursorAbove | write | Add cursor above |
addCursorAboveSkipCurrent | write | Add cursor above (skip current) |
addCursorBelow | write | Add cursor below |
addCursorBelowSkipCurrent | write | Add cursor below (skip current) |
addLineAfter | write | Add new line after the current line |
addLineBefore | write | Add new line before the current line |
alignCursors | read | Align cursors |
autoindent | read | Auto Indent |
backspace | read | Backspace |
blockindent | read | Block indent |
blockoutdent | read | Block outdent |
blurTextInput | write | Set focus to the editor content div to allow tabbing through the page |
centerselection | read | Center selection |
copy | read | Copy |
copylinesdown | read | Copy lines down |
copylinesup | read | Copy lines up |
cut | read | Cut |
cut_or_delete | destructive | Cut or delete |
del | destructive | Delete |
duplicateSelection | read | Duplicate selection |
expandToMatching | read | Expand to matching |
expandtoline | read | Expand to line |
find | read | Find |
findAll | read | Find all |
findnext | read | Find next |
findprevious | read | Find previous |
foldAllComments | read | Fold all comments |
foldOther | read | Fold other |
foldall | read | Fold all |
goToNextError | read | Go to next error |
goToPreviousError | read | Go to previous error |
golinedown | read | Go line down |
golineup | read | Go line up |
gotoend | read | Go to end |
gotoleft | read | Go to left |
gotoline | read | Go to line... |
gotolineend | read | Go to line end |
gotolinestart | write | Go to line start |
gotopagedown | read | Go to page down |
gotopageup | read | Go to page up |
gotoright | read | Go to right |
gotostart | write | Go to start |
gotowordleft | read | Go to word left |
gotowordright | read | Go to word right |
indent | read | Indent |
insertstring | write | Insert string |
inserttext | write | Insert text |
invertSelection | read | Invert selection |
joinlines | read | Join lines |
jumptomatching | read | Jump to matching |
modeSelect | read | Change language mode... |
modifyNumberDown | write | Modify number down |
modifyNumberUp | write | Modify number up |
movelinesdown | write | Move lines down |
movelinesup | write | Move lines up |
openCommandPalette | read | Open command palette |
outdent | read | Outdent |
overwrite | destructive | Overwrite |
pagedown | read | Page down |
pageup | read | Page up |
passKeysToBrowser | read | Pass keys to browser |
paste | read | Paste |
redo | read | Redo |
removeline | destructive | Remove line |
removetolineend | destructive | Remove to line end |
removetolineendhard | destructive | Remove to line end hard |
removetolinestart | destructive | Remove to line start |
removetolinestarthard | destructive | Remove to line start hard |
removewordleft | destructive | Remove word left |
removewordright | destructive | Remove word right |
replace | read | Replace |
replaymacro | read | Replay macro |
scrolldown | read | Scroll down |
scrollup | read | Scroll up |
selectMoreAfter | read | Select more after |
selectMoreBefore | read | Select more before |
selectNextAfter | read | Select next after |
selectNextBefore | read | Select next before |
selectOrFindNext | read | Select or find next |
selectOrFindPrevious | read | Select or find previous |
selectall | read | Select all |
selectdown | read | Select down |
selectleft | read | Select left |
selectlineend | read | Select line end |
selectlinestart | write | Select line start |
selectpagedown | read | Select page down |
selectpageup | read | Select page up |
selectright | read | Select right |
selecttoend | read | Select to end |
selecttolineend | read | Select to line end |
selecttolinestart | write | Select to line start |
selecttomatching | read | Select to matching |
selecttostart | write | Select to start |
selectup | read | Select up |
selectwordleft | read | Select word left |
selectwordright | read | Select word right |
showSettingsMenu | read | Show settings menu |
singleSelection | read | Single selection |
sortlines | read | Sort lines |
splitSelectionIntoLines | read | Split into lines |
splitline | read | Split line |
toggleBlockComment | read | Toggle block comment |
toggleFoldWidget | read | Toggle fold widget |
toggleParentFoldWidget | read | Toggle parent fold widget |
toggleSplitSelectionIntoLines | read | Split selection into lines |
togglecomment | read | Toggle comment |
togglerecording | read | Toggle recording |
tolowercase | read | To lowercase |
touppercase | read | To uppercase |
transposeletters | read | Transpose letters |
undo | read | Undo |
unfoldall | read | Unfold all |
Trust audit
BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
data = yaml.load(SOURCE_MODEL.read_text())
!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?e(exports):"function"==typeof define&&define.amd?define(["exports"],e):e((t="undefined"!=typeof globalThis?globalThis:t||self).vis=t| **pgwire** (v2.5.0+) | ``postgresql://obsl:KEY@host:5432/sales`` — the URL ``database=`` slot |
CMD python -c "import urllib.request; urllib.request.urlopen(f'http://localhost:{__import__(\"os\").environ[\"PORT\"]}/health')"module = importlib.import_module(VENDOR_MAP[dialect])
print(_promote_dataset(client, token, table))
_LOGO_DARK_URI = "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAvgAAACgCAYAAAB5YBhQAAAACXBIWXMAAAsTAAALEwEAmpwYAAAb10lEQVR4nO3dT04cS7bH8bDledIrMB7k2Fh6b/DexLAC4xXYrMCwgnSuAHsF4BUYrwAY9FNL3ZK54xoY74Bc
_LOGO_LIGHT_URI = "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAvgAAACgCAYAAAB5YBhQAAAACXBIWXMAAAsTAAALEwEAmpwYAAAYtklEQVR4nO3dUW5bOZbGcSbIe6tXEHkFUYCZh56XyCsoZwWxVxB7BXFWYGcFdlYQZQVRHnrQwAwQ1QqiWsG
psql "postgresql://obsl:$KEY@localhost:5432/__default__"
postgresql://obsl:KEY@host:5432/sales
Default URI is ``postgresql://postgres:postgres@localhost:5432/postgres``.
ace.define("ace/mode/sparql_highlight_rules",["require","exports","module","ace/lib/oop","ace/mode/text_highlight_rules"],function(e,t,n){"use strict";var r=e("../lib/oop"),i=e("./text_highlight_rulesAPI_KEY = "obsl_pat_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c"
result = authenticate(startup=STARTUP, password="nope-wrong-key-123456")
cut_or_delete, del, overwrite, removeline, removetolineend, removetolineendhard, removetolinestart, removetolinestarthard, removewordleft, removewordright
acctbal.parquet
banks.parquet
calendar.parquet
channels.parquet
clientcomplaints.parquet
.env.template
else yaml.load(path.read_text())
__import__(pkg)
exec(compile(block, f"{self.GUIDE}#block{index}", "exec"), {"conn": conn})uid = "m" + hashlib.md5(mermaid_src.encode()).hexdigest()[:8]
Gates applied: no_behavioural_pass.
f38e74b5a47afull audit observations/trust-audit/mcp-server/ralfbecher__orionbelt-semantic-layer.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f38e74b5a47a | BLOCK | F | 45 | first audit |
Questions
What is the OrionBelt Semantic Layer MCP server?
Source-available semantic and context layer, rule engine, and semantic sidecar for agentic AI and governed analytics. Compiles declarative YAML models into optimized SQL, KPIs, and semantic context across 8 SQL dialects.
What tools does OrionBelt Semantic Layer expose?
112 in total: 84 read-only, 18 that write, and 10 that can delete or overwrite (cut_or_delete, del, overwrite, removeline, removetolineend). Every one is listed on this page with its risk.
Is OrionBelt Semantic Layer safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (45/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does OrionBelt Semantic Layer need?
It reads API_KEY_HEADER, CLICKHOUSE_PASSWORD, DATABRICKS_ACCESS_TOKEN, DATABRICKS_TOKEN, FLIGHT_API_TOKEN, FLIGHT_AUTH_MODE, MOTHERDUCK_ACCESS_TOKEN, MOTHERDUCK_TOKEN, MYSQL_PASSWORD, OBSL_API_KEY, POSTGRES_PASSWORD and SNOWFLAKE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (f38e74b5a47a), read on 2026-10-08. The repository is watched and re-audited when it changes.