Atlas / MCP servers / zymazza / Mazzap

MazzapCAUTION

mcp/zymazza/mazzap

Mazzap, part of the Mazzstack: essentials for the Singularity Slowlife

Verdict
CAUTION
Grade
D
Trust score
60 /100
Exposed tools
66 48r · 12w · 6d
Transport
—
License
MIT
Stars
152
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

https://github.com/user-attachments/assets/deb9e860-abf8-4e34-ab9b-88b3c7a2643f

Mazzap v2 turns a patch of real ground into a VEIL — a Virtually Embodied Intelligent Land: a standalone, fully georeferenced 3D digital twin that Mazzap models and instantiates from open geospatial data. Open it in a browser, click to read true GPS coordinates, drape your own map layers onto the terrain, simulate the processes that move water and fire across it, and ask questions about it in natural language.

No database, no cloud, no build step at view time: one tiny zero-dependency Node static server serves a Three.js viewer over a self-contained bundle of geospatial data. Nothing is fetched from the network when you view it.

# A fresh clone ships the engine, not a place — build a twin first:
npm run demo       # build the bundled Flatirons demo twin (needs internet + GDAL)
npm run serve-demo # -> http://127.0.0.1:4174

# ...or build your own area interactively, then serve it:
npm run init       # guided setup: draw an AOI, fetch data, build the twin
npm start          # -> http://127.0.0.1:4173

(npm start with no twin built yet just tells you to run one of the above.)

Requires Node ≥ 18 (the server uses the built-in fetch); the data pipeline scripts need Python 3 with GDAL (osgeo), numpy, pyproj, and Pillow. The MCP/chat path also needs the Python mcp SDK from requirements.txt. If you'd rather not assemble that toolchain yourself, run it in a container — GDAL, numpy, Node, and the rest come pinned and pre-built.

Point it at your own DEM and imagery (see "Build your own twin" below) — the engine is region-agnostic. The coordinate system, the vegetation knowledge, the map-layer styling, and any source-acquisition scripts all live in data and in an optional regional pack, never hardcoded in the engine.

What you get

  • 3D terrain from any DEM (a LiDAR
Read from source at commit c7665744d686OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mazzap --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENAI_REQUIRE_USER_KEY=${OPENAI_REQUIRE_USER_KEY} --env VEIL_LIVE_TOKEN=${VEIL_LIVE_TOKEN} --env VEIL_SESSION_SECRET=${VEIL_SESSION_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mazzap": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "OPENAI_REQUIRE_USER_KEY": "${OPENAI_REQUIRE_USER_KEY}",
        "VEIL_LIVE_TOKEN": "${VEIL_LIVE_TOKEN}",
        "VEIL_SESSION_SECRET": "${VEIL_SESSION_SECRET}"
      }
    }
  }
}
03

Exposed tools (66)

48 read · 12 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
aggregate_entitiesreadAggregate latest-state values over entities of one kind. metric:
apply_plan_proposalwriteApply a proposal as a new immutable plan revision. Set confirmed=true
best_viewpointsreadRank candidate viewpoints inside a region. objective=
body_positionreadReturn topocentric alt/az, RA/Dec, distance, magnitude/phase where
branch_planwriteCreate a named alternative from a plan
can_seereadIntervisibility along one ray. Returns visible, controlling obstruction
canopy_changereadWhen did canopy density change: tree count and summed crown area (m2)
clear_drawingsdestructiveRemove every drawn polygon and point marker from the user
clear_plan_visualizationdestructiveClear GAIA
clear_sky_highlightsdestructiveClear all sky highlights from the live viewer. Map drawings and atlas
compare_solar_sitesreadCompare multiple proposed solar-panel sites and rank them by annual or
create_planwriteCreate a new empty, non-destructive plan pinned to the current baseline.
describe_placereadLightweight orientation: the twin
describe_twinreadOrient yourself: the twin
discover_live_connectionsreadDiscover local gateway connection targets for live telemetry.
draw_pointdestructiveDrop an orange marker on the user
draw_polygonreadDraw an orange polygon on the user
entity_historyreadThe append-only observation timeline of one entity, oldest first —
et_atreadSample ET/water-balance outputs at a point. point is {
et_summaryreadEvapotranspiration and water-balance summary: annual/monthly ET0,
export_live_telemetry_to_twinreadMaterialize live telemetry into the durable twin store as `live_device`
filter_layerreadReveal ONLY the selected regions of an atlas layer (and turn the layer
find_entitiesreadFind entities of one kind, spatially and/or by attribute.
fire_atreadThe wildfire read at one point (the Fire pane
fire_summaryreadProperty-wide wildfire summary: fuel-model breakdown, canopy stats,
get_entityreadFull current state of one entity by ID (e.g.
get_planwriteInspect a plan and one reachable revision: complete edit snapshot,
highlight_skyreadHighlight a sky target in the live viewer. name resolves to a body,
horizon_atreadReturn a 360-degree terrain/canopy horizon profile at a point, compacted
hydrology_atreadThe terrain-hydrology read at one point (the Simulation window
hydrology_summaryreadProperty-wide hydrology: the Tier-1 analysis summary (drainage outlet,
identify_atreadEverything true at a single point — the server-side equivalent of
layer_summaryreadOne layer in depth. Vectors: feature count, geometry types, attribute
list_layersreadThe layer catalog: every atlas layer and registered input file with
list_planswriteList saved land plans, current immutable heads, edit counts, branches,
list_survey_layersreadThe field-survey catalog (Survey companion, docs/survey.md): one entry
live_telemetry_historyreadRead raw events from the temporary live telemetry data store
live_telemetry_snapshotreadCurrent live telemetry state for field devices and gateway connections.
live_telemetry_store_summaryreadSummarize the temporary live telemetry store: recorded days, total event
manage_live_devicereadManage a tracked live device.
manage_live_gatewayreadRegister and control live telemetry gateway connections.
next_sky_eventreadFind upcoming sky events at the twin site. kind: solar_eclipse (next
planning_catalogreadReturn this regional pack
propose_gardenreadDraft and visualize a filled/raised garden footprint. Terrain change is
propose_orchardreadDraft a deterministic, spacing-respecting orchard inside a polygon and
propose_plan_editswriteValidate arbitrary Plan edits and create a reviewable proposal without
propose_swalereadDraft and visualize a smooth swale depression along a centerline. Points
propose_vegetation_clearancereadDraft and visualize removal of effective trees/shrubs within buffer_m
recommend_sitesreadRecommend multiple good sites inside a region (default: parcel AOI), ranked
recommend_solar_sitesreadRank ideal fixed-panel solar sites inside a region. Recommended sites
reset_layer_viewsdestructiveUndo every layer override you made with set_layer_visibility /
run_fire_scenariowriteRun a wildfire ignition/weather scenario and return the result. This
run_plan_simulationwriteRun hydrology, fire, et, solar, solar_site, or viewshed against any
run_scenariowriteRun a snowmelt or rainstorm hydrology scenario and return the result.
sample_rasterreadSample one raster atlas layer at a point: raw cell value plus its
save_plan_versionwriteSave a named immutable checkpoint at the current plan head. The expected
set_layer_visibilitywriteShow or hide one of the twin
set_view_timewriteSet the viewer
sky_atreadReturn the sky state at the twin site for a UTC time (default now):
solar_atreadPlan a fixed solar-panel site at a point. Returns optimized or requested
solar_irradiancedestructiveReturn clear-sky GHI/DNI/DHI and sun geometry at the twin site for a UTC
solar_profilereadMonthly and seasonal solar/PV profile for a proposed panel site,
summarize_regionreadWhat
viewshed_fromreadCompute the viewshed from a point. surface defaults to bare_earth; pass
visualize_planreadSignal the user
water_balancereadAggregate annual P, ET0, AET, modeled runoff, storage-change proxy and
04

Trust audit

CAUTIONgrade D · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (10 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
packs/us-national/demo/flatirons_aoi.dbf
flatirons_aoi.dbf
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packs/us-national/demo/flatirons_aoi.shp
flatirons_aoi.shp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packs/us-national/demo/flatirons_aoi.shx
flatirons_aoi.shx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
packs/nato/adapters/be.py:25
global_sources = importlib.import_module(__package__ + ".global")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
packs/nato/adapters/cz.py:20
global_sources = importlib.import_module(__package__ + ".global")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
packs/nato/adapters/dk.py:21
global_sources = importlib.import_module(__package__ + ".global")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
packs/nato/adapters/ee.py:23
global_sources = importlib.import_module(__package__ + ".global")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
packs/nato/adapters/es.py:45
global_sources = importlib.import_module(__package__ + ".global")
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
packs/us-national/build_landfire_vat.py:86
header = [h.strip().lstrip("") for h in rows[0]]
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_drawings, clear_plan_visualization, clear_sky_highlights, draw_point, reset_layer_views, solar_irradiance
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/mini-twin/data/journal/000001-build-test-fixture-py.jsonl.gz
000001-build-test-fixture-py.jsonl.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
tests/fixtures/mini-twin/data/twin.gpkg
twin.gpkg
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packs/nato/adapters/atlas_global.py:596
key = hashlib.sha1(("%s|%s|%s" % (wkt, facet_limit, offset)).encode("utf-8")).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packs/nato/display.py:298
h = hashlib.sha1()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/analyze_fuels.py:592
sha = hashlib.sha1(open(png_path, "rb").read()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/analyze_hydrology.py:656
sha = hashlib.sha1(open(png_path, "rb").read()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/fetch_distant_terrain.py:124
return hashlib.sha1(text.encode("utf-8")).hexdigest()[:12]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CLAUDE.md:14
npm start                 # serve at http://127.0.0.1:4173 (PORT/HOST/TWIN_DATA_DIR env override)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CLAUDE.md:16
npm run serve-demo        # serve the demo twin at http://127.0.0.1:4174
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CLAUDE.md:105
**Chat panel ("Ask the land"):** the viewer's collapsible chat window (`public/chat.js`, stacked above the coordinate readout) talks to `POST /api/chat` in `server.js`, which spawns `scripts/mcp_serve
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:23
npm run serve-demo # -> http://127.0.0.1:4174
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:27
npm start          # -> http://127.0.0.1:4173
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/twin_store.py:1078
bytes.fromhex(op["wkb"]), op.get("properties"))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/twin_store.py:1081
bytes.fromhex(op["wkb"]), op.get("properties"))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, pyproj, Pillow, astronomy-engine
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c7665744d686full audit observations/trust-audit/mcp-server/zymazza__mazzap.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c7665744d686CAUTIOND60first audit
06

Questions

What is the Mazzap MCP server?

Mazzap, part of the Mazzstack: essentials for the Singularity Slowlife

What tools does Mazzap expose?

66 in total: 48 read-only, 12 that write, and 6 that can delete or overwrite (clear_drawings, clear_plan_visualization, clear_sky_highlights, draw_point, reset_layer_views). Every one is listed on this page with its risk.

Is Mazzap safe to connect to an agent?

With care. The audit graded it D (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mazzap need?

It reads OPENAI_API_KEY, OPENAI_REQUIRE_USER_KEY, VEIL_LIVE_TOKEN and VEIL_SESSION_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (c7665744d686), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement