league-analysis-mcp-server
PyPI
v0.3.1
Published by ari1110 — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
Model Context Protocol server for Yahoo Fantasy Sports API with advanced historical analysis and manager profiling
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`src/league_analysis_mcp_server/oauth_callback_server.py:230`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ] subprocess.run(cmd, check=True, capture_output=True, text=True) return cert_file, k
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server src/league_analysis_mcp_server/oauth_callback_server.py
Each tool and what it can reach — statically extracted from the published source.
analyze_draft_strategy_toolno sensitive capabilityanalyze_manager_historyno sensitive capabilitycheck_setup_statusno sensitive capabilityclear_cacheno sensitive capabilitycompare_seasonsno sensitive capabilitycreate_yahoo_appno sensitive capabilityevaluate_manager_skill_toolno sensitive capabilityget_all_yahoo_fantasy_game_keysno sensitive capabilityget_current_game_infono sensitive capabilityget_current_game_metadatano sensitive capabilityget_current_userno sensitive capabilityget_enhanced_draft_resultsno sensitive capabilityget_game_info_by_game_idno sensitive capabilityget_game_key_by_seasonno sensitive capabilityget_game_metadata_by_game_idno sensitive capabilityget_game_position_types_by_game_idno sensitive capabilityget_game_roster_positions_by_game_idno sensitive capabilityget_game_stat_categories_by_game_idno sensitive capabilityget_game_weeks_by_game_idno sensitive capabilityget_historical_draftsno sensitive capabilityget_league_draft_resultsno sensitive capabilityget_league_infono sensitive capabilityget_league_keyno sensitive capabilityget_league_metadatano sensitive capabilityget_league_playersno sensitive capabilityget_league_scoreboard_by_weekno sensitive capabilityget_league_settingsno sensitive capabilityget_matchupsno sensitive capabilityget_player_draft_analysisno sensitive capabilityget_player_ownershipno sensitive capabilityget_player_percent_owned_by_weekno sensitive capabilityget_player_stats_by_dateno sensitive capabilityget_player_stats_by_weekno sensitive capabilityget_player_stats_for_seasonno sensitive capabilityget_responseno sensitive capabilityget_season_transactionsno sensitive capabilityget_server_infono sensitive capabilityget_setup_instructionsno sensitive capabilityget_standingsno sensitive capabilityget_team_draft_resultsno sensitive capabilityget_team_infono sensitive capabilityget_team_matchupsno sensitive capabilityget_team_metadatano sensitive capabilityget_team_rosterno sensitive capabilityget_team_roster_player_info_by_dateno sensitive capabilityget_team_roster_player_info_by_weekno sensitive capabilityget_team_roster_player_statsno sensitive capabilityget_team_roster_player_stats_by_weekno sensitive capabilityget_team_standingsno sensitive capabilityget_team_statsno sensitive capabilityget_team_stats_by_weekno sensitive capabilityget_user_gamesno sensitive capabilityget_user_leaguesno sensitive capabilityget_user_teamsno sensitive capabilitylist_available_seasonsno sensitive capabilitypredict_trade_likelihood_toolno sensitive capabilityrefresh_yahoo_tokenno sensitive capabilityreset_authenticationno sensitive capabilitysave_yahoo_credentialsno sensitive capabilitystart_automated_oauth_flowno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.3.1 latest |
A 93/100 | 1 | 1.13.0 | 2026-08-25 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan league-analysis-mcp-server --online --registry pypi
Uncensored AI tools (chat, image, RE/malware analysis, JS deobfuscation, multi-step research) for Claude Desktop, Cursor, Cline, Zed, and any MCP client.
儿童故事 MCP 服务 - 提供故事列表和搜索功能
Grade any bet against thousands of play-by-play game simulations: win probability, odds, edge.
World Cup MCP server for the 2026 men's football tournament — live scores, fixtures, standings, read-only prediction-market signals, and paste-ready match cards. Works with Claude Code, Cursor, Codex, Windsurf, Zed. Not affiliated with FIFA or Anthropic.
MCP server exposing a live Dwarf Fortress fort to an AI agent as curated, semantic tools
MCP Server for Arknights: Endfield (TypeScript / stdio + Streamable HTTP)