Atlas / MCP servers / yuna0x0 / Anilist

AnilistSAFE

mcp/yuna0x0/anilist

AniList MCP server for accessing anime and manga data

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
44 36r · 5w · 3d
Transport
stdio · streamable-http
License
MIT
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that interfaces with the AniList API, allowing LLM clients to access and interact with anime, manga, character, staff, and user data from AniList.

Features

  • Search for anime, manga, characters, staff, and studios
  • Get detailed information about specific anime, manga, characters, and staff members
  • Access user profiles and lists
  • Support for advanced filtering options
  • Retrieve genres and media tags
  • Dual transport support: Both HTTP and STDIO transports
  • Cloud deployment ready: Support Smithery and other platforms

Requirements

  • Node.js 18+

Local Installation (STDIO Transport)

  1. Add this server to your mcp.json / claude_desktop_config.json:
{
"mcpServers": {
"anilist": {
"command": "npx",
"args": ["-y", "anilist-mcp"],
"env": {
"ANILIST_TOKEN": "your_api_token"
}
}
}
}

You may remove the env object entirely, if you are not planning to use the AniList Token for operations that require login.

  1. Restart your MCP client (e.g., Claude Desktop)
  2. Use the tools to interact with AniList

Server Deployment (HTTP Transport)

Self-Hosting

Follow the Local Development instructions to set up the project locally, then run:

pnpm run start:http

This will start the server on port 8081 by default. You can change the port by setting the PORT environment variable.

Cloud Deployment

You can deploy this MCP server to any cloud platform that supports Node.js server applications.

You can also deploy via MCP platforms like Smithery.

Configuration

Environment Variables (STDIO Transport and HTTP Transport server where host provides the config)

When using the STDIO transport or hosting the HTTP transport server, you can pass configuration via environment variables:

  • ANILIST_TOKEN: (Optional) AniList API Token (Only needed for op
Read from source at commit a725f40b5730OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add anilist-mcp --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} -- npx -y [email protected]
claude-code (oci)
claude mcp add anilist-mcp:1.4.0 --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} -- docker run -i --rm ghcr.io/yuna0x0/anilist-mcp:1.4.0:None
03

Exposed tools (44)

36 read · 5 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_list_entrywrite[Requires Login] Add an entry to the authorized user
delete_activitydestructive[Requires Login] Delete the current authorized user
delete_threaddestructive[Requires Login] Delete a thread by its ID
favourite_animeread[Requires Login] Favourite or unfavourite an anime by its ID
favourite_characterread[Requires Login] Favourite or unfavourite a character by its ID
favourite_mangaread[Requires Login] Favourite or unfavourite a manga by its ID
favourite_staffread[Requires Login] Favourite or unfavourite a staff member by their ID
favourite_studioread[Requires Login] Favourite or unfavourite a studio by its ID
follow_userread[Requires Login] Follow or unfollow a user by their ID
get_activityreadGet a specific AniList activity by its ID
get_animereadGet detailed information about anime by AniList ID(s)
get_authorized_userread[Requires Login] Get profile information of the currently authorized user
get_characterreadGet information about a character by their AniList ID or name
get_full_user_inforeadGet a user
get_genresreadGet all available genres on AniList
get_mangareadGet detailed information about manga by AniList ID(s)
get_media_tagsreadGet all available media tags on AniList
get_recommendationreadGet an AniList recommendation by its ID
get_recommendations_for_mediareadGet AniList recommendations for a specific media
get_site_statisticsreadGet AniList site statistics over the last seven days
get_staffreadGet information about staff member by their AniList ID or name
get_studioreadGet information about a studio by its AniList ID or name
get_threadreadGet a specific thread by its AniList ID
get_thread_commentsreadGet comments for a specific thread
get_todays_birthday_charactersreadGet all characters whose birthday is today
get_todays_birthday_staffreadGet all staff members whose birthday is today
get_user_activityreadFetch activities from a user
get_user_anime_listreadGet a user
get_user_manga_listreadGet a user
get_user_profilereadGet a user
get_user_recent_activityreadGet recent activity from a user
get_user_statsreadGet a user
post_message_activitywrite[Requires Login] Post a new message activity or update an existing one
post_text_activitywrite[Requires Login] Post a new text activity or update an existing one
remove_list_entrydestructive[Requires Login] Remove an entry from the authorized user
search_activityreadSearch for activities on AniList
search_animereadSearch for anime with query term and filters
search_characterreadSearch for characters based on a query term
search_mangareadSearch for manga with query term and filters
search_staffreadSearch for staff members based on a query term
search_studioreadSearch for studios based on a query term
search_userreadSearch for users on AniList
update_list_entrywrite[Requires Login] Update an entry on the authorized user
update_userwrite[Requires Login] Update user settings
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_activity, delete_thread, remove_list_entry
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @yuna0x0/anilist-node, cors, dotenv, express, zod, @anthropic-ai/mcpb, @modelcontextprotocol/inspector
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha a725f40b5730full audit observations/trust-audit/mcp-server/yuna0x0__anilist.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a725f40b5730SAFEB89first audit
06

Questions

What is the Anilist MCP server?

AniList MCP server for accessing anime and manga data

What tools does Anilist expose?

44 in total: 36 read-only, 5 that write, and 3 that can delete or overwrite (delete_activity, delete_thread, remove_list_entry). Every one is listed on this page with its risk.

Is Anilist safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Anilist need?

It reads ANILIST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Anilist run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as anilist-mcp at 1.4.0.

How current is this page?

The grade is for one exact copy of the source (a725f40b5730), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement