Atlas / MCP servers / zenml-io / ZenML

ZenMLBLOCK

mcp/zenml-io/zenml

MCP server to connect an MCP client (Cursor, Claude Desktop etc) with your ZenML MLOps and LLMOps pipelines

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://archestra.ai/mcp-catalog/zenml-io__mcp-zenml)

This project implements a Model Context Protocol (MCP) server for interacting with the ZenML API.

What is MCP?

The Model Context Protocol (MCP) is an open protocol that standardizes how applications provide context to Large Language Models (LLMs). It acts like a "USB-C port for AI applications" - providing a standardized way to connect AI models to different data sources and tools.

MCP follows a client-server architecture where:

  • MCP Hosts: Programs like Claude Desktop or IDEs that want to access data through MCP
  • MCP Clients: Protocol clients that maintain 1:1 connections with servers
  • MCP Servers: Lightweight programs that expose specific capabilities through the standardized protocol
  • Local Data Sources: Your computer's files, databases, and services that MCP servers can securely access
  • Remote Services: External systems available over the internet that MCP servers can connect to

What is ZenML?

ZenML is an open-source platform for building and managing ML and AI pipelines. It provides a unified interface for managing data, models, and experiments.

For more information, see the ZenML website and our documentation.

Features

The server provides MCP tools to access core read functionality from the ZenML server, providing a way to get live information about:

Core Entities

  • Users - user accounts and permissions
  • Stacks - infrastructure configurations
  • Stack Components - individual stack building blocks
  • Flavors - available component types
  • Service Connectors - cloud authentication

Pipeline Execution

  • Pipelines - pipeline definitions
  • Pipeline Runs - execution history
Read from source at commit c9593a9452c3OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add mcp-zenml:2.0.0 --env ZENML_STORE_API_KEY=${ZENML_STORE_API_KEY} -- docker run -i --rm docker.io/zenmldocker/mcp-zenml:2.0.0:None
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
slow_callreadwith events.open(
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (11)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
server/zenml_resource_dispatch.py:1011
verify=False,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
server/zenml_resource_dispatch.py:1154
verify=False,
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.local.example
.env.local.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:296
`http://127.0.0.1:8001`, require an identity or service credential for the
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/test_mcp_transport.py:222
assert "http://127.0.0.2:*" in alternate_loopback.allowed_origins
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/test_mcp_transport.py:269
"origin": "http://127.0.0.1:8000",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/test_mcp_transport.py:304
"origin": "http://127.0.0.1:evil.com",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/test_mcp_transport.py:312
"http://127.0.0.1:8000/path",
INFOInventory / provenance · inv.oversize · CWE-1104
assets/icon.png
assets/icon.png
Why it matters. 1270288 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/mcp-settings-page.gif
assets/mcp-settings-page.gif
Why it matters. 1937146 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
mcp-zenml.mcpb
mcp-zenml.mcpb
Why it matters. 1434937 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c9593a9452c3full audit observations/trust-audit/mcp-server/zenml-io__zenml.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c9593a9452c3BLOCKD69first audit
06

Questions

What is the ZenML MCP server?

MCP server to connect an MCP client (Cursor, Claude Desktop etc) with your ZenML MLOps and LLMOps pipelines

What tools does ZenML expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ZenML safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does ZenML need?

It reads ZENML_MCP_RESTRICTED_API_KEY and ZENML_STORE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ZenML run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-zenml.

How current is this page?

The grade is for one exact copy of the source (c9593a9452c3), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement