AnilistSAFE
AniList MCP server for accessing anime and manga data
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that interfaces with the AniList API, allowing LLM clients to access and interact with anime, manga, character, staff, and user data from AniList.
Features
- Search for anime, manga, characters, staff, and studios
- Get detailed information about specific anime, manga, characters, and staff members
- Access user profiles and lists
- Support for advanced filtering options
- Retrieve genres and media tags
- Dual transport support: Both HTTP and STDIO transports
- Cloud deployment ready: Support Smithery and other platforms
Requirements
- Node.js 18+
Local Installation (STDIO Transport)
- Add this server to your
mcp.json/claude_desktop_config.json:
{
"mcpServers": {
"anilist": {
"command": "npx",
"args": ["-y", "anilist-mcp"],
"env": {
"ANILIST_TOKEN": "your_api_token"
}
}
}
}You may remove the env object entirely, if you are not planning to use the AniList Token for operations that require login.
- Restart your MCP client (e.g., Claude Desktop)
- Use the tools to interact with AniList
Server Deployment (HTTP Transport)
Self-Hosting
Follow the Local Development instructions to set up the project locally, then run:
pnpm run start:http
This will start the server on port 8081 by default. You can change the port by setting the PORT environment variable.
Cloud Deployment
You can deploy this MCP server to any cloud platform that supports Node.js server applications.
You can also deploy via MCP platforms like Smithery.
Configuration
Environment Variables (STDIO Transport and HTTP Transport server where host provides the config)
When using the STDIO transport or hosting the HTTP transport server, you can pass configuration via environment variables:
ANILIST_TOKEN: (Optional) AniList API Token (Only needed for op
a725f40b5730OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add anilist-mcp --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} -- npx -y [email protected]claude mcp add anilist-mcp:1.4.0 --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} --env ANILIST_TOKEN=${ANILIST_TOKEN} -- docker run -i --rm ghcr.io/yuna0x0/anilist-mcp:1.4.0:NoneExposed tools (44)
36 read · 5 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_list_entry | write | [Requires Login] Add an entry to the authorized user |
delete_activity | destructive | [Requires Login] Delete the current authorized user |
delete_thread | destructive | [Requires Login] Delete a thread by its ID |
favourite_anime | read | [Requires Login] Favourite or unfavourite an anime by its ID |
favourite_character | read | [Requires Login] Favourite or unfavourite a character by its ID |
favourite_manga | read | [Requires Login] Favourite or unfavourite a manga by its ID |
favourite_staff | read | [Requires Login] Favourite or unfavourite a staff member by their ID |
favourite_studio | read | [Requires Login] Favourite or unfavourite a studio by its ID |
follow_user | read | [Requires Login] Follow or unfollow a user by their ID |
get_activity | read | Get a specific AniList activity by its ID |
get_anime | read | Get detailed information about anime by AniList ID(s) |
get_authorized_user | read | [Requires Login] Get profile information of the currently authorized user |
get_character | read | Get information about a character by their AniList ID or name |
get_full_user_info | read | Get a user |
get_genres | read | Get all available genres on AniList |
get_manga | read | Get detailed information about manga by AniList ID(s) |
get_media_tags | read | Get all available media tags on AniList |
get_recommendation | read | Get an AniList recommendation by its ID |
get_recommendations_for_media | read | Get AniList recommendations for a specific media |
get_site_statistics | read | Get AniList site statistics over the last seven days |
get_staff | read | Get information about staff member by their AniList ID or name |
get_studio | read | Get information about a studio by its AniList ID or name |
get_thread | read | Get a specific thread by its AniList ID |
get_thread_comments | read | Get comments for a specific thread |
get_todays_birthday_characters | read | Get all characters whose birthday is today |
get_todays_birthday_staff | read | Get all staff members whose birthday is today |
get_user_activity | read | Fetch activities from a user |
get_user_anime_list | read | Get a user |
get_user_manga_list | read | Get a user |
get_user_profile | read | Get a user |
get_user_recent_activity | read | Get recent activity from a user |
get_user_stats | read | Get a user |
post_message_activity | write | [Requires Login] Post a new message activity or update an existing one |
post_text_activity | write | [Requires Login] Post a new text activity or update an existing one |
remove_list_entry | destructive | [Requires Login] Remove an entry from the authorized user |
search_activity | read | Search for activities on AniList |
search_anime | read | Search for anime with query term and filters |
search_character | read | Search for characters based on a query term |
search_manga | read | Search for manga with query term and filters |
search_staff | read | Search for staff members based on a query term |
search_studio | read | Search for studios based on a query term |
search_user | read | Search for users on AniList |
update_list_entry | write | [Requires Login] Update an entry on the authorized user |
update_user | write | [Requires Login] Update user settings |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
delete_activity, delete_thread, remove_list_entry
@modelcontextprotocol/sdk, @yuna0x0/anilist-node, cors, dotenv, express, zod, @anthropic-ai/mcpb, @modelcontextprotocol/inspector
Gates applied: no_behavioural_pass.
a725f40b5730full audit observations/trust-audit/mcp-server/yuna0x0__anilist.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a725f40b5730 | SAFE | B | 89 | first audit |
Questions
What is the Anilist MCP server?
AniList MCP server for accessing anime and manga data
What tools does Anilist expose?
44 in total: 36 read-only, 5 that write, and 3 that can delete or overwrite (delete_activity, delete_thread, remove_list_entry). Every one is listed on this page with its risk.
Is Anilist safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Anilist need?
It reads ANILIST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Anilist run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as anilist-mcp at 1.4.0.
How current is this page?
The grade is for one exact copy of the source (a725f40b5730), read on 2026-10-07. The repository is watched and re-audited when it changes.