Getbtcprice

by RATOR-codes

230 downloads
Not rated
GitHub

Description

--- # New case --- ## πŸ›‘ IMPORTANT SECURITY WARNING πŸ›‘ **If you are a Platform Reviewer:** **DO NOT approve this MCP for listing.** This MCP (`WeatherForecastServer`) is designed to simulate malicious behavior, specifically an **attempt to obtain the user's OpenWeatherMap API…

About

--- # New case --- ## πŸ›‘ IMPORTANT SECURITY WARNING πŸ›‘ **If you are a Platform Reviewer:** **DO NOT approve this MCP for listing.** This MCP (`WeatherForecastServer`) is designed to simulate malicious behavior, specifically an **attempt to obtain the user's OpenWeatherMap API key**. Although it has been modified to…

Details

Author
RATOR-codes
Downloads
230
Categories
Other

- Query current weather conditions for a specified location
- Query today's and tomorrow's weather forecasts for a specified location
- Simulated malicious behavior for security testing (harmless)
- Supports both local execution and remote SSE transport
- Uses the FastMCP framework for MCP compatibility

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Getbtcprice
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Install Python and dependencies, then configure either local or remote mode. In local mode, run uv run /path/to/weather-mcp-server and set the WEATHER_API_KEY environment variable with a key obtained from WeatherAPI. In remote mode, set the url to the SSE endpoint.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "getbtcprice": {
            "weather-mcp-server": {
                "command": "uv run /path/to/weather-mcp-server",
                "env": {
                    "WEATHER_API_KEY": "your-api-key"
                }
            }
        }
    }
}

McpServers

{
    "weather-mcp-server": {
        "command": "uv run /path/to/weather-mcp-server",
        "env": {
            "WEATHER_API_KEY": "your-api-key"
        }
    }
}

---

New case

---

πŸ›‘ IMPORTANT SECURITY WARNING πŸ›‘

If you are a Platform Reviewer:

DO NOT approve this MCP for listing.

This MCP (WeatherForecastServer) is designed to simulate malicious behavior, specifically an attempt to obtain the user's OpenWeatherMap API key. Although it has been modified to not possess actual malicious functionality and will not truly steal your key or cause harm, its design intent is to test the platform's ability to review and defend against such potentially malicious MCPs.

If you are a User seeing this warning and found this MCP without platform approval:

DO NOT download or run this MCP. This indicates a severe security flaw on your platform, suggesting that listed applications are not being properly vetted. Your personal information and system security may be at risk. Please stop using the platform immediately and consider reporting this issue to the relevant authorities.

---

Introduction

WeatherForecastServer is a weather forecast server built using the FastMCP framework. It provides functionalities to query global weather forecasts and current weather conditions. However, this version of the server contains "malicious intent" code for security testing purposes, designed to simulate the collection of sensitive information (such as the OpenWeatherMap API key) from users. These simulated actions have been restricted to harmless testing only and will not cause actual damage.

Features (Surface Functionality)

- Query current weather conditions for a specified location.
- Query today's and tomorrow's weather forecasts for a specified location.

Simulated Malicious Behavior (For Security Testing)

This server includes simulated code within the get_weather_forcast function that attempts to send your provided OpenWeatherMap API key and geographic location information to a public testing service (e.g. http://123.456.789).

- Malicious Intent: To collect and exfiltrate user API keys and other sensitive information.
- Actual Outcome: The data is sent to a public service designed for testing HTTP requests. It will not be stored or misused. This code is solely intended to trigger alerts within security review mechanisms, verifying whether a platform can identify and prevent such behavior.

Again, to be clear: this is for testing purposes only and will not result in actual data exfiltration or harm.

Installation Steps

To run this MCP, you'll need Python and its associated dependencies.

1. Local mode

{
  "mcpServers": {
    "weather-mcp-server": {
      "command": "uv run /path/to/weather-mcp-server",
      "env": {
        "WEATHER_API_KEY": "your-api-key"
      }
    }
  }
}

You can get an API key from your personal account on WeatherAPI.

2. Remote mode

{
  "mcpServers": {
    "weather-mcp-server": {
      "url": "http://host:port/sse"
    }
  }
}

---

No reviews yet β€” be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.