Atlas / MCP servers / ralfbecher / OrionBelt Semantic Layer

OrionBelt Semantic LayerBLOCK

mcp/ralfbecher/orionbelt-semantic-layer

Source-available semantic and context layer, rule engine, and semantic sidecar for agentic AI and governed analytics. Compiles declarative YAML models into optimized SQL, KPIs, and semantic context across 8 SQL dialects.

Verdict
BLOCK
Grade
F
Trust score
45 /100
Exposed tools
112 84r · 18w · 10d
Transport
—
License
NOASSERTION
Stars
99
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

OrionBelt® Semantic and Context Layer, Rule Engine, and Semantic Sidecar

Define your metrics once in YAML. Let agents and BI tools query them without ever touching your schema.

A semantic sidecar: it rides alongside the systems you already run instead of replacing them.

Ask an LLM to write SQL against a raw star schema and sooner or later it joins two fact tables and hands you a revenue number inflated by a factor of eight. It looks right. Nobody catches it.

OrionBelt is a semantic and context layer with a rule engine, and it runs as a **[semanti

Read from source at commit f38e74b5a47aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add orionbelt-semantic-layer --env API_KEY_HEADER=${API_KEY_HEADER} --env CLICKHOUSE_PASSWORD=${CLICKHOUSE_PASSWORD} --env DATABRICKS_ACCESS_TOKEN=${DATABRICKS_ACCESS_TOKEN} --env DATABRICKS_TOKEN=${DATABRICKS_TOKEN} -- uvx orionbelt-semantic-layer
claude-desktop
{
  "mcpServers": {
    "orionbelt-semantic-layer": {
      "command": "uvx",
      "args": [
        "orionbelt-semantic-layer"
      ],
      "env": {
        "API_KEY_HEADER": "${API_KEY_HEADER}",
        "CLICKHOUSE_PASSWORD": "${CLICKHOUSE_PASSWORD}",
        "DATABRICKS_ACCESS_TOKEN": "${DATABRICKS_ACCESS_TOKEN}",
        "DATABRICKS_TOKEN": "${DATABRICKS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (112)

84 read · 18 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addCursorAbovewriteAdd cursor above
addCursorAboveSkipCurrentwriteAdd cursor above (skip current)
addCursorBelowwriteAdd cursor below
addCursorBelowSkipCurrentwriteAdd cursor below (skip current)
addLineAfterwriteAdd new line after the current line
addLineBeforewriteAdd new line before the current line
alignCursorsreadAlign cursors
autoindentreadAuto Indent
backspacereadBackspace
blockindentreadBlock indent
blockoutdentreadBlock outdent
blurTextInputwriteSet focus to the editor content div to allow tabbing through the page
centerselectionreadCenter selection
copyreadCopy
copylinesdownreadCopy lines down
copylinesupreadCopy lines up
cutreadCut
cut_or_deletedestructiveCut or delete
deldestructiveDelete
duplicateSelectionreadDuplicate selection
expandToMatchingreadExpand to matching
expandtolinereadExpand to line
findreadFind
findAllreadFind all
findnextreadFind next
findpreviousreadFind previous
foldAllCommentsreadFold all comments
foldOtherreadFold other
foldallreadFold all
goToNextErrorreadGo to next error
goToPreviousErrorreadGo to previous error
golinedownreadGo line down
golineupreadGo line up
gotoendreadGo to end
gotoleftreadGo to left
gotolinereadGo to line...
gotolineendreadGo to line end
gotolinestartwriteGo to line start
gotopagedownreadGo to page down
gotopageupreadGo to page up
gotorightreadGo to right
gotostartwriteGo to start
gotowordleftreadGo to word left
gotowordrightreadGo to word right
indentreadIndent
insertstringwriteInsert string
inserttextwriteInsert text
invertSelectionreadInvert selection
joinlinesreadJoin lines
jumptomatchingreadJump to matching
modeSelectreadChange language mode...
modifyNumberDownwriteModify number down
modifyNumberUpwriteModify number up
movelinesdownwriteMove lines down
movelinesupwriteMove lines up
openCommandPalettereadOpen command palette
outdentreadOutdent
overwritedestructiveOverwrite
pagedownreadPage down
pageupreadPage up
passKeysToBrowserreadPass keys to browser
pastereadPaste
redoreadRedo
removelinedestructiveRemove line
removetolineenddestructiveRemove to line end
removetolineendharddestructiveRemove to line end hard
removetolinestartdestructiveRemove to line start
removetolinestartharddestructiveRemove to line start hard
removewordleftdestructiveRemove word left
removewordrightdestructiveRemove word right
replacereadReplace
replaymacroreadReplay macro
scrolldownreadScroll down
scrollupreadScroll up
selectMoreAfterreadSelect more after
selectMoreBeforereadSelect more before
selectNextAfterreadSelect next after
selectNextBeforereadSelect next before
selectOrFindNextreadSelect or find next
selectOrFindPreviousreadSelect or find previous
selectallreadSelect all
selectdownreadSelect down
selectleftreadSelect left
selectlineendreadSelect line end
selectlinestartwriteSelect line start
selectpagedownreadSelect page down
selectpageupreadSelect page up
selectrightreadSelect right
selecttoendreadSelect to end
selecttolineendreadSelect to line end
selecttolinestartwriteSelect to line start
selecttomatchingreadSelect to matching
selecttostartwriteSelect to start
selectupreadSelect up
selectwordleftreadSelect word left
selectwordrightreadSelect word right
showSettingsMenureadShow settings menu
singleSelectionreadSingle selection
sortlinesreadSort lines
splitSelectionIntoLinesreadSplit into lines
splitlinereadSplit line
toggleBlockCommentreadToggle block comment
toggleFoldWidgetreadToggle fold widget
toggleParentFoldWidgetreadToggle parent fold widget
toggleSplitSelectionIntoLinesreadSplit selection into lines
togglecommentreadToggle comment
togglerecordingreadToggle recording
tolowercasereadTo lowercase
touppercasereadTo uppercase
transposelettersreadTranspose letters
undoreadUndo
unfoldallreadUnfold all
04

Trust audit

BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (6 observation(s))
Shell
declared (4 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
demo/dremio/build_assets.py:76
data = yaml.load(SOURCE_MODEL.read_text())
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/orionbelt/ui/static/vis-network.min.js:26
!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?e(exports):"function"==typeof define&&define.amd?define(["exports"],e):e((t="undefined"!=typeof globalThis?globalThis:t||self).vis=t
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/orionbelt/obsql_reference.py:230
| **pgwire** (v2.5.0+) | ``postgresql://obsl:KEY@host:5432/sales`` — the URL ``database=`` slot |
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
Dockerfile:97
CMD python -c "import urllib.request; urllib.request.urlopen(f'http://localhost:{__import__(\"os\").environ[\"PORT\"]}/health')"
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
drivers/ob-flight-extension/src/ob_flight/db_router.py:242
module = importlib.import_module(VENDOR_MAP[dialect])
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
demo/dremio/bootstrap.py:406
print(_promote_dataset(client, token, table))
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/orionbelt/ui/app.py:138
_LOGO_DARK_URI = "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAvgAAACgCAYAAAB5YBhQAAAACXBIWXMAAAsTAAALEwEAmpwYAAAb10lEQVR4nO3dT04cS7bH8bDledIrMB7k2Fh6b/DexLAC4xXYrMCwgnSuAHsF4BUYrwAY9FNL3ZK54xoY74Bc
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
src/orionbelt/ui/app.py:139
_LOGO_LIGHT_URI = "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAvgAAACgCAYAAAB5YBhQAAAACXBIWXMAAAsTAAALEwEAmpwYAAAYtklEQVR4nO3dUW5bOZbGcSbIe6tXEHkFUYCZh56XyCsoZwWxVxB7BXFWYGcFdlYQZQVRHnrQwAwQ1QqiWsG
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/guide/authentication.md:172
psql "postgresql://obsl:$KEY@localhost:5432/__default__"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/guide/semantic-ql.md:188
postgresql://obsl:KEY@host:5432/sales
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/integration/test_adbc_postgres.py:7
Default URI is ``postgresql://postgres:postgres@localhost:5432/postgres``.
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/orionbelt/ui/static/ace-sparql.min.js:24
ace.define("ace/mode/sparql_highlight_rules",["require","exports","module","ace/lib/oop","ace/mode/text_highlight_rules"],function(e,t,n){"use strict";var r=e("../lib/oop"),i=e("./text_highlight_rules
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/integration/test_adbc_auth.py:50
API_KEY = "obsl_pat_a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_pgwire_auth.py:49
result = authenticate(startup=STARTUP, password="nope-wrong-key-123456")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cut_or_delete, del, overwrite, removeline, removetolineend, removetolineendhard, removetolinestart, removetolinestarthard, removewordleft, removewordright
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/commerce/acctbal.parquet
acctbal.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/commerce/banks.parquet
banks.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/commerce/calendar.parquet
calendar.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/commerce/channels.parquet
channels.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/commerce/clientcomplaints.parquet
clientcomplaints.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/unit/test_integration_examples_resolve.py:107
else yaml.load(path.read_text())
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
examples/notebook_setup.py:31
__import__(pkg)
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/test_adbc_docs_claims.py:305
exec(compile(block, f"{self.GUIDE}#block{index}", "exec"), {"conn": conn})
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
examples/notebook_setup.py:441
uid = "m" + hashlib.md5(mermaid_src.encode()).hexdigest()[:8]

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f38e74b5a47afull audit observations/trust-audit/mcp-server/ralfbecher__orionbelt-semantic-layer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f38e74b5a47aBLOCKF45first audit
06

Questions

What is the OrionBelt Semantic Layer MCP server?

Source-available semantic and context layer, rule engine, and semantic sidecar for agentic AI and governed analytics. Compiles declarative YAML models into optimized SQL, KPIs, and semantic context across 8 SQL dialects.

What tools does OrionBelt Semantic Layer expose?

112 in total: 84 read-only, 18 that write, and 10 that can delete or overwrite (cut_or_delete, del, overwrite, removeline, removetolineend). Every one is listed on this page with its risk.

Is OrionBelt Semantic Layer safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (45/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OrionBelt Semantic Layer need?

It reads API_KEY_HEADER, CLICKHOUSE_PASSWORD, DATABRICKS_ACCESS_TOKEN, DATABRICKS_TOKEN, FLIGHT_API_TOKEN, FLIGHT_AUTH_MODE, MOTHERDUCK_ACCESS_TOKEN, MOTHERDUCK_TOKEN, MYSQL_PASSWORD, OBSL_API_KEY, POSTGRES_PASSWORD and SNOWFLAKE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (f38e74b5a47a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement