Quick-Start AutoSAFE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 한국어
Introduction
Quick-start Auto MCP is a tool that helps you easily and quickly register Anthropic's Model Context Protocol (MCP) in Claude Desktop and Cursor.
Key advantages:
- Quick Setup: Add MCP functionality to Claude Desktop and Cursor simply by running a tool and copying/pasting the generated JSON file.
- Various Tools Provided: We continuously update useful MCP tools. Stay up to date with your personalized toolkit by starring and following us. :)
Table of Contents
- Features
- Project Structure
- Requirements
- Installation
- Configuration
- Usage
- Troubleshooting
- License
- Contributing
- Contact
- Author
Features
- RAG (Retrieval Augmented Generation) - Keyword, semantic, and hybrid search functionality for PDF documents
- Dify External Knowledge API - Document search functionality via Dify's external knowledge API
- Dify Workflow - Execute and retrieve results from Dify Workflow
- Web Search - Real-time web search using Tavily API
- Automatic JSON Generation - Automatically generate MCP JSON files needed for Claude Desktop and Cursor
Project Structure
. ├── case1 # RAG example ├── case2 # Dify External Knowledge API example ├── case3 # Dify Workflow example ├── case4 # Web Search example ├── data # Example data files ├── docs # Documentation folder │ ├── case1.md # case1 description 🚨 Includes tips for optimized tool invocation │ ├── case2.md # case2 description │ ├── case3.md # case3 description │ ├── case4.md # case4 description │ └── installation.md
559e55ac6666OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-usecases --env DIFY_API_KEY=${DIFY_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env TAVILY_API_KEY=${TAVILY_API_KEY} -- uvx mcp-usecases{
"mcpServers": {
"mcp-usecases": {
"command": "uvx",
"args": [
"mcp-usecases"
],
"env": {
"DIFY_API_KEY": "${DIFY_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"TAVILY_API_KEY": "${TAVILY_API_KEY}"
}
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
dify_ek_search | read | |
dify_workflow | read | |
hybrid_search | read | |
keyword_search | read | |
search_web | read | |
semantic_search | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (4)
API_KEY = "dify-external-knowledge-api-key"
1. Load environment variables
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
559e55ac6666full audit observations/trust-audit/mcp-server/teddynote-lab__quick-start-auto.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 559e55ac6666 | SAFE | B | 89 | first audit |
Questions
What tools does Quick-Start Auto expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Quick-Start Auto safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Quick-Start Auto need?
It reads DIFY_API_KEY, OPENAI_API_KEY and TAVILY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (559e55ac6666), read on 2026-10-06. The repository is watched and re-audited when it changes.