Back to Home
conda-incubator icon

conda-meta-mcp

Verified Safe

by conda-incubator

Overview

Provides authoritative, read-only Conda ecosystem metadata for AI agents to answer packaging questions.

Installation

Run Command
pixi run cmm run

Security Notes

The server's core function involves making network requests to Conda ecosystem endpoints (conda.anaconda.org, cforge.quansight.dev) and arbitrary URLs for package tarballs via the `package_insights` tool. While no direct code execution from arbitrary URLs is apparent, this could pose a risk for resource exhaustion or parsing vulnerabilities. The `cli_help` tool's `grep` parameter uses regular expressions, which could potentially be exploited for ReDoS (Regular Expression Denial of Service) if a malicious regex is provided. However, the project adheres to a 'read-only, zero-side-effect' contract and uses established libraries.

Similar Servers

Stats

Interest Score35
Security Score8
Cost ClassLow
Avg Tokens350
Stars5
Forks0
Last Update2026-01-17

Tags

condamcpai agentsmetadatapackagingllm