MazzapCAUTION
Mazzap, part of the Mazzstack: essentials for the Singularity Slowlife
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
https://github.com/user-attachments/assets/deb9e860-abf8-4e34-ab9b-88b3c7a2643f
Mazzap v2 turns a patch of real ground into a VEIL — a Virtually Embodied Intelligent Land: a standalone, fully georeferenced 3D digital twin that Mazzap models and instantiates from open geospatial data. Open it in a browser, click to read true GPS coordinates, drape your own map layers onto the terrain, simulate the processes that move water and fire across it, and ask questions about it in natural language.
No database, no cloud, no build step at view time: one tiny zero-dependency Node static server serves a Three.js viewer over a self-contained bundle of geospatial data. Nothing is fetched from the network when you view it.
# A fresh clone ships the engine, not a place — build a twin first: npm run demo # build the bundled Flatirons demo twin (needs internet + GDAL) npm run serve-demo # -> http://127.0.0.1:4174 # ...or build your own area interactively, then serve it: npm run init # guided setup: draw an AOI, fetch data, build the twin npm start # -> http://127.0.0.1:4173
(npm start with no twin built yet just tells you to run one of the above.)
Requires Node ≥ 18 (the server uses the built-in fetch); the data pipeline scripts need Python 3 with GDAL (osgeo), numpy, pyproj, and Pillow. The MCP/chat path also needs the Python mcp SDK from requirements.txt. If you'd rather not assemble that toolchain yourself, run it in a container — GDAL, numpy, Node, and the rest come pinned and pre-built.
Point it at your own DEM and imagery (see "Build your own twin" below) — the engine is region-agnostic. The coordinate system, the vegetation knowledge, the map-layer styling, and any source-acquisition scripts all live in data and in an optional regional pack, never hardcoded in the engine.
What you get
- 3D terrain from any DEM (a LiDAR
c7665744d686OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mazzap --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENAI_REQUIRE_USER_KEY=${OPENAI_REQUIRE_USER_KEY} --env VEIL_LIVE_TOKEN=${VEIL_LIVE_TOKEN} --env VEIL_SESSION_SECRET=${VEIL_SESSION_SECRET} -- npx -y [email protected]{
"mcpServers": {
"mazzap": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"OPENAI_REQUIRE_USER_KEY": "${OPENAI_REQUIRE_USER_KEY}",
"VEIL_LIVE_TOKEN": "${VEIL_LIVE_TOKEN}",
"VEIL_SESSION_SECRET": "${VEIL_SESSION_SECRET}"
}
}
}
}Exposed tools (66)
48 read · 12 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
aggregate_entities | read | Aggregate latest-state values over entities of one kind. metric: |
apply_plan_proposal | write | Apply a proposal as a new immutable plan revision. Set confirmed=true |
best_viewpoints | read | Rank candidate viewpoints inside a region. objective= |
body_position | read | Return topocentric alt/az, RA/Dec, distance, magnitude/phase where |
branch_plan | write | Create a named alternative from a plan |
can_see | read | Intervisibility along one ray. Returns visible, controlling obstruction |
canopy_change | read | When did canopy density change: tree count and summed crown area (m2) |
clear_drawings | destructive | Remove every drawn polygon and point marker from the user |
clear_plan_visualization | destructive | Clear GAIA |
clear_sky_highlights | destructive | Clear all sky highlights from the live viewer. Map drawings and atlas |
compare_solar_sites | read | Compare multiple proposed solar-panel sites and rank them by annual or |
create_plan | write | Create a new empty, non-destructive plan pinned to the current baseline. |
describe_place | read | Lightweight orientation: the twin |
describe_twin | read | Orient yourself: the twin |
discover_live_connections | read | Discover local gateway connection targets for live telemetry. |
draw_point | destructive | Drop an orange marker on the user |
draw_polygon | read | Draw an orange polygon on the user |
entity_history | read | The append-only observation timeline of one entity, oldest first — |
et_at | read | Sample ET/water-balance outputs at a point. point is { |
et_summary | read | Evapotranspiration and water-balance summary: annual/monthly ET0, |
export_live_telemetry_to_twin | read | Materialize live telemetry into the durable twin store as `live_device` |
filter_layer | read | Reveal ONLY the selected regions of an atlas layer (and turn the layer |
find_entities | read | Find entities of one kind, spatially and/or by attribute. |
fire_at | read | The wildfire read at one point (the Fire pane |
fire_summary | read | Property-wide wildfire summary: fuel-model breakdown, canopy stats, |
get_entity | read | Full current state of one entity by ID (e.g. |
get_plan | write | Inspect a plan and one reachable revision: complete edit snapshot, |
highlight_sky | read | Highlight a sky target in the live viewer. name resolves to a body, |
horizon_at | read | Return a 360-degree terrain/canopy horizon profile at a point, compacted |
hydrology_at | read | The terrain-hydrology read at one point (the Simulation window |
hydrology_summary | read | Property-wide hydrology: the Tier-1 analysis summary (drainage outlet, |
identify_at | read | Everything true at a single point — the server-side equivalent of |
layer_summary | read | One layer in depth. Vectors: feature count, geometry types, attribute |
list_layers | read | The layer catalog: every atlas layer and registered input file with |
list_plans | write | List saved land plans, current immutable heads, edit counts, branches, |
list_survey_layers | read | The field-survey catalog (Survey companion, docs/survey.md): one entry |
live_telemetry_history | read | Read raw events from the temporary live telemetry data store |
live_telemetry_snapshot | read | Current live telemetry state for field devices and gateway connections. |
live_telemetry_store_summary | read | Summarize the temporary live telemetry store: recorded days, total event |
manage_live_device | read | Manage a tracked live device. |
manage_live_gateway | read | Register and control live telemetry gateway connections. |
next_sky_event | read | Find upcoming sky events at the twin site. kind: solar_eclipse (next |
planning_catalog | read | Return this regional pack |
propose_garden | read | Draft and visualize a filled/raised garden footprint. Terrain change is |
propose_orchard | read | Draft a deterministic, spacing-respecting orchard inside a polygon and |
propose_plan_edits | write | Validate arbitrary Plan edits and create a reviewable proposal without |
propose_swale | read | Draft and visualize a smooth swale depression along a centerline. Points |
propose_vegetation_clearance | read | Draft and visualize removal of effective trees/shrubs within buffer_m |
recommend_sites | read | Recommend multiple good sites inside a region (default: parcel AOI), ranked |
recommend_solar_sites | read | Rank ideal fixed-panel solar sites inside a region. Recommended sites |
reset_layer_views | destructive | Undo every layer override you made with set_layer_visibility / |
run_fire_scenario | write | Run a wildfire ignition/weather scenario and return the result. This |
run_plan_simulation | write | Run hydrology, fire, et, solar, solar_site, or viewshed against any |
run_scenario | write | Run a snowmelt or rainstorm hydrology scenario and return the result. |
sample_raster | read | Sample one raster atlas layer at a point: raw cell value plus its |
save_plan_version | write | Save a named immutable checkpoint at the current plan head. The expected |
set_layer_visibility | write | Show or hide one of the twin |
set_view_time | write | Set the viewer |
sky_at | read | Return the sky state at the twin site for a UTC time (default now): |
solar_at | read | Plan a fixed solar-panel site at a point. Returns optimized or requested |
solar_irradiance | destructive | Return clear-sky GHI/DNI/DHI and sun geometry at the twin site for a UTC |
solar_profile | read | Monthly and seasonal solar/PV profile for a proposed panel site, |
summarize_region | read | What |
viewshed_from | read | Compute the viewshed from a point. surface defaults to bare_earth; pass |
visualize_plan | read | Signal the user |
water_balance | read | Aggregate annual P, ET0, AET, modeled runoff, storage-change proxy and |
Trust audit
CAUTIONgrade D · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
flatirons_aoi.dbf
flatirons_aoi.shp
flatirons_aoi.shx
global_sources = importlib.import_module(__package__ + ".global")
global_sources = importlib.import_module(__package__ + ".global")
global_sources = importlib.import_module(__package__ + ".global")
global_sources = importlib.import_module(__package__ + ".global")
global_sources = importlib.import_module(__package__ + ".global")
header = [h.strip().lstrip("") for h in rows[0]]clear_drawings, clear_plan_visualization, clear_sky_highlights, draw_point, reset_layer_views, solar_irradiance
000001-build-test-fixture-py.jsonl.gz
twin.gpkg
key = hashlib.sha1(("%s|%s|%s" % (wkt, facet_limit, offset)).encode("utf-8")).hexdigest()h = hashlib.sha1()
sha = hashlib.sha1(open(png_path, "rb").read()).hexdigest()
sha = hashlib.sha1(open(png_path, "rb").read()).hexdigest()
return hashlib.sha1(text.encode("utf-8")).hexdigest()[:12]npm start # serve at http://127.0.0.1:4173 (PORT/HOST/TWIN_DATA_DIR env override)
npm run serve-demo # serve the demo twin at http://127.0.0.1:4174
**Chat panel ("Ask the land"):** the viewer's collapsible chat window (`public/chat.js`, stacked above the coordinate readout) talks to `POST /api/chat` in `server.js`, which spawns `scripts/mcp_servenpm run serve-demo # -> http://127.0.0.1:4174
npm start # -> http://127.0.0.1:4173
bytes.fromhex(op["wkb"]), op.get("properties"))bytes.fromhex(op["wkb"]), op.get("properties"))mcp, pyproj, Pillow, astronomy-engine
Gates applied: no_behavioural_pass.
c7665744d686full audit observations/trust-audit/mcp-server/zymazza__mazzap.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c7665744d686 | CAUTION | D | 60 | first audit |
Questions
What is the Mazzap MCP server?
Mazzap, part of the Mazzstack: essentials for the Singularity Slowlife
What tools does Mazzap expose?
66 in total: 48 read-only, 12 that write, and 6 that can delete or overwrite (clear_drawings, clear_plan_visualization, clear_sky_highlights, draw_point, reset_layer_views). Every one is listed on this page with its risk.
Is Mazzap safe to connect to an agent?
With care. The audit graded it D (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Mazzap need?
It reads OPENAI_API_KEY, OPENAI_REQUIRE_USER_KEY, VEIL_LIVE_TOKEN and VEIL_SESSION_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (c7665744d686), read on 2026-10-07. The repository is watched and re-audited when it changes.