Atlas / MCP servers / teddynote-lab / Quick-Start Auto

Quick-Start AutoSAFE

mcp/teddynote-lab/quick-start-auto
Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 6r · 0w · 0d
Transport
—
License
MIT
Stars
185
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 한국어

Introduction

Quick-start Auto MCP is a tool that helps you easily and quickly register Anthropic's Model Context Protocol (MCP) in Claude Desktop and Cursor.

Key advantages:

  1. Quick Setup: Add MCP functionality to Claude Desktop and Cursor simply by running a tool and copying/pasting the generated JSON file.
  2. Various Tools Provided: We continuously update useful MCP tools. Stay up to date with your personalized toolkit by starring and following us. :)

Table of Contents

  • Features
  • Project Structure
  • Requirements
  • Installation
  • Configuration
  • Usage
  • Troubleshooting
  • License
  • Contributing
  • Contact
  • Author

Features

  • RAG (Retrieval Augmented Generation) - Keyword, semantic, and hybrid search functionality for PDF documents
  • Dify External Knowledge API - Document search functionality via Dify's external knowledge API
  • Dify Workflow - Execute and retrieve results from Dify Workflow
  • Web Search - Real-time web search using Tavily API
  • Automatic JSON Generation - Automatically generate MCP JSON files needed for Claude Desktop and Cursor

Project Structure

.
├── case1                     # RAG example
├── case2                     # Dify External Knowledge API example
├── case3                     # Dify Workflow example
├── case4                     # Web Search example
├── data                      # Example data files
├── docs                      # Documentation folder
│   ├── case1.md           # case1 description 🚨 Includes tips for optimized tool invocation
│   ├── case2.md           # case2 description
│   ├── case3.md           # case3 description
│   ├── case4.md           # case4 description
│   └── installation.md   
Read from source at commit 559e55ac6666OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-usecases --env DIFY_API_KEY=${DIFY_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env TAVILY_API_KEY=${TAVILY_API_KEY} -- uvx mcp-usecases
claude-desktop
{
  "mcpServers": {
    "mcp-usecases": {
      "command": "uvx",
      "args": [
        "mcp-usecases"
      ],
      "env": {
        "DIFY_API_KEY": "${DIFY_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "TAVILY_API_KEY": "${TAVILY_API_KEY}"
      }
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
dify_ek_searchread
dify_workflowread
hybrid_searchread
keyword_searchread
search_webread
semantic_searchread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (4)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
case2/dify_ek_server.py:28
API_KEY = "dify-external-knowledge-api-key"
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/case3.md:139
1. Load environment variables
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/installation.md:36
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/installation.md:139
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 559e55ac6666full audit observations/trust-audit/mcp-server/teddynote-lab__quick-start-auto.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06559e55ac6666SAFEB89first audit
06

Questions

What tools does Quick-Start Auto expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Quick-Start Auto safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Quick-Start Auto need?

It reads DIFY_API_KEY, OPENAI_API_KEY and TAVILY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (559e55ac6666), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement