Atlas / MCP servers / withqwerty / Football Docs

Football DocsBLOCK

mcp/withqwerty/football-docs

Searchable football data provider documentation for AI coding agents. Like Context7 for football data.

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
15 11r · 2w · 2d
Transport
stdio
License
—
Stars
194
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Searchable football data provider and tooling documentation for AI coding agents. Like Context7 for football data.

Who it's for: Developers and analysts who use AI coding tools (Claude Code, Cursor, VS Code Copilot) to work with football data. Works with any tool that supports MCP.

What it does: Gives your AI agent a searchable index of documentation for 30 football data providers and tools — event types, qualifier IDs, coordinate systems, API endpoints, data models, identity surfaces, and cross-provider comparisons for the data providers (StatsBomb, Opta, Wyscout, Impect, SkillCorner, Sportradar, TheSportsDB, FMDB Pro, TransferRoom, and more), the open-source libraries people build with (kloppy, mplsoccer, socceraction, soccerdata, floodlight, fast-forward, unravelsports, and more), and the APIs of wearable and sports-science vendors (STATSports, Firstbeat, Hawkin Dynamics, VALD). Your agent looks up the real docs instead of guessing from training data.

Why not just let the AI figure it out? LLMs get football data specifics wrong constantly — Opta qualifier IDs, StatsBomb coordinate ranges, API endpoint URLs, library method signatures. These are mutable facts that change across versions. football-docs gives the agent verified, sourced documentation with provenance tracking so you know where every answer came from.

Strategy

football-docs is intended to be a community-owned, source-transparent Context7 for football data. The public operating contract is in STRATEGY.md: what belongs here, what must stay out, how we handle public-safe provider facts, and how contributors should prove retrieval quality.

Provider identity facts

football-docs is the public source for provider identity-surface facts: access shape, ID schemes, matching fields, provider quirks, and provenance rules. Curated provider identity notes belong here when they can be stated as public facts about the provider. They shoul

Read from source at commit 2b16f5c5de87OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add football-docs -- npx -y [email protected]
03

Exposed tools (15)

11 read · 2 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_local_paperwrite
compare_providersreadCompare what two or more providers offer for a specific data type or concept. For example:
forget_paperdestructiveRemove one paper
get_paperread
get_provider_docsreadRetrieve documentation for a resolved provider, optionally filtered by topic or indexed category. Use after resolve_provider_id when you know which provider to inspect and want provenance-bearing docs.
get_web_sourceread
list_providersreadList all indexed football data providers, their document count, and coverage categories. Use to understand what documentation is available. Call this first to see what providers are indexed before searching.
match_quoteread
purge_cachedestructiveDelete the user
read_paperread
request_updatewriteRequest that a provider
resolve_entityread
resolve_provider_idreadResolve a football data provider name or alias to the canonical football-docs provider key before searching. Use when users mention brands, vendors, products, or aliases such as Stats Perform, Opta F24, Hudl Wyscout, Second Spectrum, FMDB, Transfer Room, FBref, Sofascore, or TheSportsDB.
search_docsreadSearch football data provider documentation. Use for finding event types, qualifier IDs, API endpoints, coordinate systems, data models, and cross-provider mappings. Returns the most relevant documentation chunks. Results that do not contain every query term are marked \
search_papersread
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (8 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/gen_python_truth.py:125
annotation = eval(annotation, namespace)  # noqa: S307 - package's own namespace
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/sportmonks/get-all-fixtures.md:77
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/sportmonks/get-all-leagues-by-team-id.md:66
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/sportmonks/get-all-leagues.md:66
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/sportmonks/get-all-livescores.md:80
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/sportmonks/get-all-seasons.md:66
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/gen_python_truth.py:179
root = importlib.import_module(args.package)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/gen_python_truth.py:215
mod = importlib.import_module(mod_name)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
forget_paper, purge_cache
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/crawl.test.ts:40
expect(slugify("../../../etc/passwd")).toBe("etc-passwd");
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/__tests__/papers.test.ts:495
"http://169.254.169.254/latest/meta-data",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/papers.test.ts:455
[XT, { status: 302, headers: { location: "http://127.0.0.1:23119/api/" } }],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/papers.test.ts:491
"http://127.0.0.1/",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/papers.test.ts:493
"http://10.1.2.3/",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/papers.test.ts:494
"http://192.168.1.10/",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/papers.test.ts:495
"http://169.254.169.254/latest/meta-data",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@apidevtools/swagger-parser, @modelcontextprotocol/sdk, @mozilla/readability, linkedom, turndown, zod, @biomejs/biome, @types/node
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/firstbeat/api-access.md:32
| Premium+ | "Full access: build and use your own API client, in addition to API Partner connections." |
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:241
- Windows: use the environment variable; the tools do not read Windows Credential Manager.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mplsoccer/visualizations.md:640
Also available: `Sbapi` (for API access with credentials) and `Sblocal` (for local files).
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/sportmonks/best-practices.md:249
Using such a proxy makes it much harder for malicious actors to access your credentials or misuse your API.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/sportmonks/best-practices.md:271
If you allow credentials (`Access-Control-Allow-Credentials: true`), the `Allow-Origin` must be an explicit origin, not `*`.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/sportmonks/best-practices.md:291
Access-Control-Allow-Credentials: true
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/statsbomb/api-access.md:152
creds = {"user": "[email protected]", "passwd": "your-password"}
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 2b16f5c5de87full audit observations/trust-audit/mcp-server/withqwerty__football-docs.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082b16f5c5de87BLOCKF56first audit
06

Questions

What is the Football Docs MCP server?

Searchable football data provider documentation for AI coding agents. Like Context7 for football data.

What tools does Football Docs expose?

15 in total: 11 read-only, 2 that write, and 2 that can delete or overwrite (forget_paper, purge_cache). Every one is listed on this page with its risk.

Is Football Docs safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Football Docs need?

No credential environment variables were found in its source, so it appears to need none.

How does Football Docs run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as football-docs at 0.16.2.

How current is this page?

The grade is for one exact copy of the source (2b16f5c5de87), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement