OpenFate Bazi MCP server with deterministic Four Pillars calculation, True Solar Time, branch interactions, and reverse Bazi lookup.
Based on the available materials, bazi-mcp does not declare any required secrets, remote endpoints, or data exfiltration behavior, and it is marked as open-source, MIT-licensed, and prompt-only, indicating low overall risk. Since the README is absent and maintenance status is unknown, supply-chain transparency is relatively good but still warrants basic verification.
The materials explicitly state that no keys or environment variables are required. There is no indication of API keys, tokens, or other sensitive credentials, so credential leakage and abuse exposure appears low.
The materials state that the remote endpoint host is 'none', and they do not describe any online lookups, cloud processing, or third-party data transfer. Based on the available facts, no user data egress path is evident.
The objective checks label it as prompt-only, and there is no description requiring local script execution, spawning additional processes, or invoking privileged system capabilities. From the materials, no clear code-execution risk is shown.
There is no declared need to read or write local files, databases, system directories, or other resources. The description focuses on Bazi calculation functionality, and no excessive data-access request is visible in the provided materials.
The source is an open-source GitHub repository under the MIT license, which provides good auditability, and it has some community adoption (72 stars), both of which are positive risk-reducing signals. The missing README and unknown maintenance status reduce visibility into implementation details and dependency health, but these alone do not justify a high-risk rating.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "bazi-mcp" yet — see the docs or source repo.