Atlas / MCP servers / waldzellai / Waldzell

WaldzellBLOCK

mcp/waldzellai/waldzell

Waldzell AI's monorepo of MCP servers. Use in Claude Desktop, Cline, Roo Code, and more!

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
56 49r · 7w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
201
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This repository contains a set of Model Context Protocol (MCP) servers. Each server lives in its own folder under servers/ and can be used independently. The project is intentionally lightweight and does not make use of a complex monorepo toolchain.

Available servers

  • Clear Thought – Sequential thinking tools inspired by James Clear
  • Google Styleguide – Google TypeScript style guide server
  • Stochastic Thinking – Stochastic thinking utilities
  • TypeStyle – TypeScript style guide server

Getting started

Prerequisites

  • Node.js 18 or higher
  • npm (comes with Node.js)

Install dependencies for all servers:

npm install

Build every server:

npm run build --workspaces

Run tests for all servers:

npm test --workspaces

Refer to each server's README for usage instructions and additional scripts.

Publishing

To publish the packages defined in this repository:

npm run build --workspaces && changeset publish

License

All code in this repository is licensed under the MIT License.

Read from source at commit 703d1e4bd314OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add yelp-fusionai --env EXA_MCP_TOKEN=${EXA_MCP_TOKEN} --env PERPLEXITY_MCP_TOKEN=${PERPLEXITY_MCP_TOKEN} --env PRIMARY_MCP_TOKEN=${PRIMARY_MCP_TOKEN} --env YELP_API_KEY=${YELP_API_KEY} -- npx -y @waldzellai/[email protected]
claude-desktop
{
  "mcpServers": {
    "yelp-fusionai": {
      "command": "npx",
      "args": [
        "-y",
        "@waldzellai/[email protected]"
      ],
      "env": {
        "EXA_MCP_TOKEN": "${EXA_MCP_TOKEN}",
        "PERPLEXITY_MCP_TOKEN": "${PERPLEXITY_MCP_TOKEN}",
        "PRIMARY_MCP_TOKEN": "${PRIMARY_MCP_TOKEN}",
        "YELP_API_KEY": "${YELP_API_KEY}"
      }
    }
  }
}
03

Exposed tools (56)

49 read · 7 write · 0 destructive.

ToolRiskDescription
agent-querywriteSend a query to Claude agent and get response
agent-statusreadGet current agent status and capabilities
analogical_mapperreadGenerate analogies from seed domains and suggest prompts
assumption_xrayreadAnalyze a claim to surface assumptions and tests
collaborativereasoningreadFacilitate collaborative reasoning with multiple perspectives and personas
comparative_advantagereadMap tasks to the skill holder with highest capability
concept_mapreadDepict nodes and annotated relationships
creativethinkingreadEngage in creative and lateral thinking approaches
debuggingapproachwriteApply systematic debugging approaches to identify and resolve issues
decisionframeworkwriteApply structured decision-making frameworks
drag_point_auditreadIdentify drag points in a process log
existing_tool_examplereadEcho back provided text
fishbone_diagramreadGroup potential causes of a problem
issue_treereadBreak down a question into hierarchical sub-issues
mentalmodelwriteApply mental models to analyze problems systematically
metacognitivemonitoringreadMonitor and assess thinking processes and knowledge
mind_mapreadOutline branches around a central topic
safe_struggle_designerreadDesign a safe skill improvement plan
scientificmethodwriteApply scientific method for systematic inquiry
sequentialthinkingreadProcess sequential thoughts with branching, revision, and memory management capabilities
session_exportreadExport the entire session state for backup or sharing
session_importwriteImport a previously exported session state
session_inforeadGet information about the current session including statistics and recent activity
seven_seekers_orchestratorwriteOrchestrate a set of seeker tools and combine their results
socraticmethodreadGuide inquiry through systematic questioning
structuredargumentationreadConstruct and analyze structured arguments
swot_analysisreadCategorize strengths, weaknesses, opportunities, threats
systemsthinkingreadAnalyze complex systems and their interactions
value_of_informationreadCalculate the value of information for a decision
visualreasoningreadProcess visual reasoning and diagram operations
yelp_ai_chatreadHave a conversation with Yelp
yelp_ai_chat_streamreadHave a streaming conversation with Yelp
yelp_autocompletereadGet autocomplete suggestions for search terms, businesses, and categories. Useful for building search interfaces or suggesting completions. Returns three types of suggestions: - terms: Search term completions - businesses: Matching business names - categories: Matching category names
yelp_business_detailsreadGet detailed information about a specific business by its Yelp business ID. Returns comprehensive details including hours, photos, reviews, special hours, and more.
yelp_business_insightsreadGet insights data for businesses
yelp_business_matchreadMatch a business to Yelp
yelp_categoriesreadGet all Yelp business categories. Categories are hierarchical and can be used to filter business searches. Returns category aliases and titles that can be used with the yelp_search tool
yelp_category_detailsreadGet details about a specific category including its parent categories and country availability.
yelp_delivery_searchreadSearch for businesses that support food delivery in a location
yelp_engagement_metricsreadGet engagement metrics (impressions, leads, calls, etc.) for businesses
yelp_event_detailsreadGet detailed information about a specific event by its Yelp event ID.
yelp_eventsreadSearch for events on Yelp. Find concerts, festivals, food & drink events, and more happening in a specific area.
yelp_featured_eventreadGet the featured event for a location. Yelp highlights notable upcoming events in each area.
yelp_food_drinks_insightsreadGet popular dishes and drinks insights for a business
yelp_partner_restaurantsreadFind restaurants that support Yelp Waitlist in a location
yelp_phone_searchreadFind a business by its phone number. Useful when you have a phone number and need to look up the business details. The phone number should be in E.164 format (e.g., +14159083801).
yelp_reservation_openingsreadGet available reservation times for a restaurant
yelp_reservation_statusreadGet the status of a reservation
yelp_review_highlightsreadGet highlighted snippets from reviews for a business. These are the most notable and representative excerpts that capture key customer experiences. Useful for quickly understanding what customers commonly mention about a business.
yelp_reviewsreadGet reviews for a specific business. Returns up to 50 reviews with text, rating, and user information. Reviews are a great way to understand customer experiences and sentiment about a business.
yelp_risk_signalsreadGet risk signal insights for a business (potential issues or concerns)
yelp_searchreadSearch for businesses on Yelp by location and search term. Returns a list of businesses matching the search criteria with ratings, reviews, categories, and location information. Use this to find restaurants, shops, services, and other businesses in a specific area. Example queries: -
yelp_service_offeringsreadGet available service offerings for a business (delivery, pickup, etc.)
yelp_visit_detailsreadGet details of a specific waitlist visit
yelp_waitlist_inforeadGet waitlist configuration and operating hours for a business
yelp_waitlist_statusreadGet the current waitlist status and wait estimates for a business
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (4 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
servers/server-typestyle/dist/src/server.js:459
feedback.push("Avoid using eval() for security and performance reasons.");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
servers/server-typestyle/src/server.ts:529
feedback.push("Avoid using eval() for security and performance reasons.");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.hidden_file · CWE-1104
.yarnrc.yml
.yarnrc.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
reynard/packages/agent-reliability-lab/tests/unit/production-source-guard.test.ts:160
'new Function("return 1");\n',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
servers/server-typestyle/dist/src/test/test-harness.js:82
return eval(expression);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
servers/server-typestyle/src/test/test-harness.ts:89
return eval(expression);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
reynard/packages/agent-reliability-lab/tests/helpers/artifact-input.ts:1
import { canonicalJson } from "../../src/canonical-json.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
reynard/packages/agent-reliability-lab/tests/helpers/artifact-input.ts:2
import { compareEvaluations } from "../../src/compare.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
reynard/packages/agent-reliability-lab/tests/helpers/artifact-input.ts:10
} from "../../src/contracts.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
reynard/packages/agent-reliability-lab/tests/helpers/artifact-input.ts:11
import { evaluateExecutions } from "../../src/evaluator.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
reynard/packages/agent-reliability-lab/tests/helpers/artifact-input.ts:12
import { createRunManifest } from "../../src/manifest.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-sidecar-observability/examples/agent-sdk-server/package.json
@anthropic-ai/claude-agent-sdk, fastify, tsx, typescript, @types/node
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-sidecar-observability/package.json
@opentelemetry/api, @opentelemetry/resources, @opentelemetry/sdk-metrics, @opentelemetry/sdk-node, @opentelemetry/exporter-metrics-otlp-http, fastify, ts-node-dev, tsx
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, chalk, @changesets/cli, @types/node, prettier, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
reynard/package.json
@eslint/js, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
servers/server-clear-thought/package.json
@modelcontextprotocol/sdk, @smithery/sdk, express, lodash, zod, zod-to-json-schema, @types/express, @types/lodash
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
servers/server-clear-thought/.smithery/index.cjs
servers/server-clear-thought/.smithery/index.cjs
Why it matters. 9583205 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
llms.txt:3354
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
llms.txt:4743
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 703d1e4bd314full audit observations/trust-audit/mcp-server/waldzellai__waldzell.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06703d1e4bd314BLOCKD69first audit
06

Questions

What is the Waldzell MCP server?

Waldzell AI's monorepo of MCP servers. Use in Claude Desktop, Cline, Roo Code, and more!

What tools does Waldzell expose?

56 in total: 49 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Waldzell safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Waldzell need?

It reads EXA_MCP_TOKEN, PERPLEXITY_MCP_TOKEN, PRIMARY_MCP_TOKEN and YELP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Waldzell run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @waldzellai/yelp-fusionai at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (703d1e4bd314), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement