Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Tecan Cavro Syringe Pump

PYPI · LABMCP-CAVRO · SCANNED SEP 30

MCP server for Tecan Cavro syringe pumps (XLP 6000, XMP 6000, XCalibur) over the DT protocol.

Available components

83 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security99
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
  • 2 of 17 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to K-Dense-AI/lab-instrument-mcps). View diagnostics → Pass
  • Clear OSI-approved license (Apache-2.0).Pass
  • Actively maintained (last published 3 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability75
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 1077 tokens (~119/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
  • Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage98
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 94% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Tecan Cavro Syringe Pump MCP server?

Tecan Cavro Syringe Pump runs locally as a PyPI package, launched with uvx labmcp-cavro. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · labmcp-cavro

# add to Claude Code
claude mcp add k-dense-ai-labmcp-cavro -- uvx labmcp-cavro
// .cursor/mcp.json
{
  "mcpServers": {
    "k-dense-ai-labmcp-cavro": {
      "command": "uvx",
      "args": [
        "labmcp-cavro"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "k-dense-ai-labmcp-cavro": {
      "command": "uvx",
      "args": [
        "labmcp-cavro"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add k-dense-ai-labmcp-cavro -- uvx labmcp-cavro
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "k-dense-ai-labmcp-cavro": {
      "type": "local",
      "command": [
        "uvx",
        "labmcp-cavro"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add k-dense-ai-labmcp-cavro --command uvx --arg labmcp-cavro
# ~/.hermes/config.yaml
mcp_servers:
  k-dense-ai-labmcp-cavro:
    command: "uvx"
    args: ["labmcp-cavro"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "k-dense-ai-labmcp-cavro": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "labmcp-cavro"
      ]
    }
  }
}
# add to Vellum
assistant mcp add k-dense-ai-labmcp-cavro -t stdio -c uvx -a labmcp-cavro
// mcp.json
{
  "mcpServers": {
    "k-dense-ai-labmcp-cavro": {
      "command": "uvx",
      "args": [
        "labmcp-cavro"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 30 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
  • 29 Sept 26 −14
    • Malware scan: pass → unverified ▼ security
  • 28 Sept 26 +43
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • Package version: 0.1.0 → 0.1.3 functional
  • 26 Sept 26 −32
    • Tool safety: pass → unverified ▼ security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • Stability: unverified → 0.03 ▲ functional
    • First check of Schema quality: unverified functional
    • Package version: 0.1.0 → 0.1.2 functional
    • Package version: 0.1.0 → 0.1.1 functional
  • 25 Sept 26 71

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 30 Sept 2026 · Analysed pypi/labmcp-cavro@0.1.3

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem pypi
Reason Verified
Discovered via Registry attestation endpoint
Source repo K-Dense-AI/lab-instrument-mcps
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/K-Dense-AI/lab-instrument-mcps/.github/workflows/release.yml@refs/tags/labmcp-cavro-v0.1.3
Rekor log index 2969517078
Predicate type PyPI publish attestation https://docs.pypi.org/attestations/publish/v1
Subject digest sha256:9d01c4640f8167f33390febcee1c02d45126c81a56a5d7003df5f843b0b10d59

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted hatchling.build

Background: Why install scripts are a supply-chain risk →

Dependencies 17 packages
Packages resolved 17
Stale 2
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 9 exposed · ~678 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
aspirate_ul ~116

Draw `volume_ul` into the syringe at `flow_ul_s` through the current (or given) valve port, and wait until the move has finished. The pump must be initialized and have room for the volume.

NameTypeReqDescription
flow_ul_snumber–Plunger flow rate, µL/s
port––Distribution valves: port to turn to first
valve––Turn the valve here first (e.g. 'input')
volume_ulnumberyesVolume to draw into the syringe, µL
NameTypeReqDescription
actionstringyes–
duration_snumberyes–
flow_ul_snumberyesFlow at the commanded top speed (ramps make the average slightly lower)
moved_ulnumberyesVolume actually commanded after rounding to whole plunger steps
plunger_position_ulnumberyes–
requested_ulnumberyes–
stepsintegeryes–
terminatedbooleanyesTrue if `terminate` interrupted the move
timestampstringyes–
top_speed_pulses_sintegeryes–
valve_positionstringyes–

No examples provided.

dispense_ul ~114

Push `volume_ul` out of the syringe at `flow_ul_s` through the current (or given) valve port, and wait until the move has finished. The syringe must contain at least that volume.

NameTypeReqDescription
flow_ul_snumber–Plunger flow rate, µL/s
port––Distribution valves: port to turn to first
valve––Turn the valve here first (e.g. 'output')
volume_ulnumberyesVolume to push out of the syringe, µL
NameTypeReqDescription
actionstringyes–
duration_snumberyes–
flow_ul_snumberyesFlow at the commanded top speed (ramps make the average slightly lower)
moved_ulnumberyesVolume actually commanded after rounding to whole plunger steps
plunger_position_ulnumberyes–
requested_ulnumberyes–
stepsintegeryes–
terminatedbooleanyesTrue if `terminate` interrupted the move
timestampstringyes–
top_speed_pulses_sintegeryes–
valve_positionstringyes–

No examples provided.

get_command_log ~46

Return the most recent raw commands sent to / replies received from the instrument (newest last). Useful for debugging and for recording what was done.

NameTypeReqDescription
limitinteger––
NameTypeReqDescription
resultarrayyes–

No examples provided.

get_connection_info ~40

Report which instrument is connected (identity, address, simulated or real), whether the server is read-only, and the active safety limits. Call this first.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

get_status ~45

Report whether the pump is ready or busy, any error (decoded), the plunger position as the volume in the syringe, the valve position, resolution mode and current top speed.

Input schema present but exposes no named parameters.

NameTypeReqDescription
errorstringyesMeaning of the error code
error_codeintegeryesError code from the status byte (0 = none)
plunger_position_stepsintegeryes–
plunger_position_ulnumberyesVolume currently drawn into the syringe
readybooleanyesTrue when the pump accepts new move commands (Q status bit 5)
resolution_modeintegeryes0 = standard (N0), 1 = fine positioning (N1), 2 = microstep (N2)
steps_per_strokeintegeryesPlunger increments for a full stroke in the current mode
syringe_ulnumberyes–
timestampstringyes–
top_speed_flow_ul_snumberyesFlow rate the current top speed corresponds to
top_speed_pulses_sintegeryes–
valve_positionstringyes–

No examples provided.

initialize ~149

Initialize the pump: drive the plunger to the top of the syringe (expelling its contents through the valve), set that as position 0 and home the valve. Needed after power-up, a plunger overload or `terminate`. Route the valve output to waste first. Takes a few seconds.

NameTypeReqDescription
forcestring–Plunger force against the syringe top; auto picks it from the syringe size
input_port––Distribution valves: input port
output_port––Distribution valves: output port
valve_directionstring–Valve homing/port numbering: cw (Z command), ccw (Y), or no_valve (W, plunger only)
NameTypeReqDescription
errorstringyesMeaning of the error code
error_codeintegeryesError code from the status byte (0 = none)
plunger_position_stepsintegeryes–
plunger_position_ulnumberyesVolume currently drawn into the syringe
readybooleanyesTrue when the pump accepts new move commands (Q status bit 5)
resolution_modeintegeryes0 = standard (N0), 1 = fine positioning (N1), 2 = microstep (N2)
steps_per_strokeintegeryesPlunger increments for a full stroke in the current mode
syringe_ulnumberyes–
timestampstringyes–
top_speed_flow_ul_snumberyesFlow rate the current top speed corresponds to
top_speed_pulses_sintegeryes–
valve_positionstringyes–

No examples provided.

reconnect ~35

Close and re-open the connection to the instrument (e.g. after it was power cycled or a cable was re-plugged).

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

set_valve ~89

Turn the valve to a named position (3/4-port valves) or to a numbered port (distribution valves). In bypass the plunger cannot move. Returns the new status.

NameTypeReqDescription
directionstring–Distribution valves: rotation direction to the port
port––Distribution valves: port number
position––Non-distribution valves: input, output, bypass or extra
NameTypeReqDescription
errorstringyesMeaning of the error code
error_codeintegeryesError code from the status byte (0 = none)
plunger_position_stepsintegeryes–
plunger_position_ulnumberyesVolume currently drawn into the syringe
readybooleanyesTrue when the pump accepts new move commands (Q status bit 5)
resolution_modeintegeryes0 = standard (N0), 1 = fine positioning (N1), 2 = microstep (N2)
steps_per_strokeintegeryesPlunger increments for a full stroke in the current mode
syringe_ulnumberyes–
timestampstringyes–
top_speed_flow_ul_snumberyesFlow rate the current top speed corresponds to
top_speed_pulses_sintegeryes–
valve_positionstringyes–

No examples provided.

terminate ~44

Stop any plunger move, loop or delay immediately (DT command T). A valve move in progress still completes. Re-initialize afterwards: the plunger may have lost steps.

Input schema present but exposes no named parameters.

NameTypeReqDescription
errorstringyesMeaning of the error code
error_codeintegeryesError code from the status byte (0 = none)
plunger_position_stepsintegeryes–
plunger_position_ulnumberyesVolume currently drawn into the syringe
readybooleanyesTrue when the pump accepts new move commands (Q status bit 5)
resolution_modeintegeryes0 = standard (N0), 1 = fine positioning (N1), 2 = microstep (N2)
steps_per_strokeintegeryesPlunger increments for a full stroke in the current mode
syringe_ulnumberyes–
timestampstringyes–
top_speed_flow_ul_snumberyesFlow rate the current top speed corresponds to
top_speed_pulses_sintegeryes–
valve_positionstringyes–

No examples provided.

Common questions

What is the Tecan Cavro Syringe Pump MCP server?

Tecan Cavro Syringe Pump is an MCP server listed in the public MCP registry as io.github.K-Dense-AI/labmcp-cavro. MCP server for Tecan Cavro syringe pumps (XLP 6000, XMP 6000, XCalibur) over the DT protocol. This page covers its PyPI package (labmcp-cavro).

Is the Tecan Cavro Syringe Pump MCP server safe to use?

Tecan Cavro Syringe Pump scores 83 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 30 September 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Tecan Cavro Syringe Pump MCP server expose?

Tecan Cavro Syringe Pump exposes 9 tools: get_connection_info, get_command_log, reconnect, get_status, initialize, and 4 more. Their descriptions and schemas cost roughly 678 tokens of context every time the server is loaded.

Is the Tecan Cavro Syringe Pump MCP server still maintained?

Tecan Cavro Syringe Pump is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the Tecan Cavro Syringe Pump MCP server under?

Tecan Cavro Syringe Pump declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.