Football DocsBLOCK
Searchable football data provider documentation for AI coding agents. Like Context7 for football data.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Searchable football data provider and tooling documentation for AI coding agents. Like Context7 for football data.
Who it's for: Developers and analysts who use AI coding tools (Claude Code, Cursor, VS Code Copilot) to work with football data. Works with any tool that supports MCP.
What it does: Gives your AI agent a searchable index of documentation for 30 football data providers and tools — event types, qualifier IDs, coordinate systems, API endpoints, data models, identity surfaces, and cross-provider comparisons for the data providers (StatsBomb, Opta, Wyscout, Impect, SkillCorner, Sportradar, TheSportsDB, FMDB Pro, TransferRoom, and more), the open-source libraries people build with (kloppy, mplsoccer, socceraction, soccerdata, floodlight, fast-forward, unravelsports, and more), and the APIs of wearable and sports-science vendors (STATSports, Firstbeat, Hawkin Dynamics, VALD). Your agent looks up the real docs instead of guessing from training data.
Why not just let the AI figure it out? LLMs get football data specifics wrong constantly — Opta qualifier IDs, StatsBomb coordinate ranges, API endpoint URLs, library method signatures. These are mutable facts that change across versions. football-docs gives the agent verified, sourced documentation with provenance tracking so you know where every answer came from.
Strategy
football-docs is intended to be a community-owned, source-transparent Context7 for football data. The public operating contract is in STRATEGY.md: what belongs here, what must stay out, how we handle public-safe provider facts, and how contributors should prove retrieval quality.
Provider identity facts
football-docs is the public source for provider identity-surface facts: access shape, ID schemes, matching fields, provider quirks, and provenance rules. Curated provider identity notes belong here when they can be stated as public facts about the provider. They shoul
2b16f5c5de87OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add football-docs -- npx -y [email protected]
Exposed tools (15)
11 read · 2 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_local_paper | write | |
compare_providers | read | Compare what two or more providers offer for a specific data type or concept. For example: |
forget_paper | destructive | Remove one paper |
get_paper | read | |
get_provider_docs | read | Retrieve documentation for a resolved provider, optionally filtered by topic or indexed category. Use after resolve_provider_id when you know which provider to inspect and want provenance-bearing docs. |
get_web_source | read | |
list_providers | read | List all indexed football data providers, their document count, and coverage categories. Use to understand what documentation is available. Call this first to see what providers are indexed before searching. |
match_quote | read | |
purge_cache | destructive | Delete the user |
read_paper | read | |
request_update | write | Request that a provider |
resolve_entity | read | |
resolve_provider_id | read | Resolve a football data provider name or alias to the canonical football-docs provider key before searching. Use when users mention brands, vendors, products, or aliases such as Stats Perform, Opta F24, Hudl Wyscout, Second Spectrum, FMDB, Transfer Room, FBref, Sofascore, or TheSportsDB. |
search_docs | read | Search football data provider documentation. Use for finding event types, qualifier IDs, API endpoints, coordinate systems, data models, and cross-provider mappings. Returns the most relevant documentation chunks. Results that do not contain every query term are marked \ |
search_papers | read |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
annotation = eval(annotation, namespace) # noqa: S307 - package's own namespace
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
<table><thead><tr><th>Name</th><th width="232.66666666666666">Required?</th><th>Description</th></tr></thead><tbody><tr><td><code>api_token</code></td><td><p>YES </p><p>Another option is to provide th
root = importlib.import_module(args.package)
mod = importlib.import_module(mod_name)
forget_paper, purge_cache
expect(slugify("../../../etc/passwd")).toBe("etc-passwd");"http://169.254.169.254/latest/meta-data",
[XT, { status: 302, headers: { location: "http://127.0.0.1:23119/api/" } }],"http://127.0.0.1/",
"http://10.1.2.3/",
"http://192.168.1.10/",
"http://169.254.169.254/latest/meta-data",
@apidevtools/swagger-parser, @modelcontextprotocol/sdk, @mozilla/readability, linkedom, turndown, zod, @biomejs/biome, @types/node
| Premium+ | "Full access: build and use your own API client, in addition to API Partner connections." |
- Windows: use the environment variable; the tools do not read Windows Credential Manager.
Also available: `Sbapi` (for API access with credentials) and `Sblocal` (for local files).
Using such a proxy makes it much harder for malicious actors to access your credentials or misuse your API.
If you allow credentials (`Access-Control-Allow-Credentials: true`), the `Allow-Origin` must be an explicit origin, not `*`.
Access-Control-Allow-Credentials: true
creds = {"user": "[email protected]", "passwd": "your-password"}Gates applied: no_behavioural_pass, no_license.
2b16f5c5de87full audit observations/trust-audit/mcp-server/withqwerty__football-docs.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2b16f5c5de87 | BLOCK | F | 56 | first audit |
Questions
What is the Football Docs MCP server?
Searchable football data provider documentation for AI coding agents. Like Context7 for football data.
What tools does Football Docs expose?
15 in total: 11 read-only, 2 that write, and 2 that can delete or overwrite (forget_paper, purge_cache). Every one is listed on this page with its risk.
Is Football Docs safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Football Docs need?
No credential environment variables were found in its source, so it appears to need none.
How does Football Docs run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as football-docs at 0.16.2.
How current is this page?
The grade is for one exact copy of the source (2b16f5c5de87), read on 2026-10-08. The repository is watched and re-audited when it changes.