MCP Grocy API (saya6k/mcp-grocy-api) is an MCP server listed on the M8ven Trust Index. It scores 16 out of 100, grade F. It declares 38 tools. No publisher has claimed this listing.
Enables interaction with Grocy's API through MCP, allowing management of grocery inventory, shopping lists, and household tasks via natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
saya6k
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
get_stock_volatileGet volatile stock information (due products, overdue products, expired products, missing products).
get_shopping_listGet your current shopping list items.
get_choresGet all chores from your Grocy instance.
get_tasksGet all tasks from your Grocy instance.
get_locationsGet all storage locations from your Grocy instance.
get_shopping_locationsGet all shopping locations (stores) from your Grocy instance.
get_product_groupsGet all product groups from your Grocy instance.
get_quantity_unitsGet all quantity units from your Grocy instance.
get_usersGet all users from your Grocy instance.
get_recipes_fulfillmentGet fulfillment information for all recipes.
add_recipe_products_to_shopping_listAdd not fulfilled products of a recipe to the shopping list.
undo_actionUndo an action for different entity types (chores, batteries, tasks).
get_meal_planGet your meal plan data from Grocy instance.
get_productsGet all products from your Grocy instance.
get_recipesGet all recipes from your Grocy instance.
get_stockGet current stock from your Grocy instance.
get_batteriesGet all batteries from your Grocy instance.
get_equipmentGet all equipment from your Grocy instance.
add_shopping_list_itemAdd an item to your shopping list.
add_recipe_to_meal_planAdd a recipe to the meal plan.
inventory_productTrack a product inventory (set current stock amount).
create_recipeCreate a new recipe in your Grocy instance.
purchase_productTrack a product purchase in your Grocy instance.
consume_productTrack consumption of a product in your Grocy instance.
track_chore_executionTrack execution of a chore in your Grocy instance.
complete_taskMark a task as completed in your Grocy instance.
transfer_productTransfer a product from one location to another in your Grocy instance.
get_price_historyGet the price history of a product from your Grocy instance.
open_productMark a product as opened in your Grocy instance.
get_stock_by_locationGet all stock from a specific location in your Grocy instance.
consume_recipeConsume all ingredients needed for a recipe in your Grocy instance.
charge_batteryTrack charging of a battery in your Grocy instance.
add_missing_products_to_shopping_listAdd all missing products for a recipe to your shopping list.
get_recipe_fulfillmentGet stock fulfillment information for a recipe.
remove_shopping_list_itemRemove an item from your shopping list.
call_grocy_apiCall a specific Grocy API endpoint with custom parameters.
test_requestget_product_entriesGet all stock entries for a specific product in your Grocy instance.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
ENABLE_HTTP_SERVERGROCY_APIKEY_VALUEYour Grocy API keyGROCY_BASE_URLYour Grocy API URLGROCY_ENABLE_SSL_VERIFYWhether to verify SSL certificateHTTP_SERVER_PORTREST_RESPONSE_SIZE_LIMITREST API response size (default: 10000 = 10KB)Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
38/38 tools missing one or more hints — get_stock_volatile (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_shopping_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_chores (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +35 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 0/38 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 15 high severity in production deps — @modelcontextprotocol/sdk@1.11.4 (high), @modelcontextprotocol/sdk@1.11.4 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/saya6k/mcp-grocy-api)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check