# io.github.markswendsen-code/tacobell (npm · @striderlabs/mcp-tacobell)

MCP server for Taco Bell - browse menu, customize orders, place pickup

- Trust score: 66/100 (medium)
- Change this week: +20
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `@striderlabs/mcp-tacobell`: 66/100 (this document), [markdown](https://verifymcp.io/servers/markswendsen-code-tacobell/striderlabs-mcp-tacobell.md), [page](https://verifymcp.io/servers/markswendsen-code-tacobell/striderlabs-mcp-tacobell)

## Channel facts

- Registry: `npm`
- Package: `@striderlabs/mcp-tacobell`
- Version: `0.1.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (97 of 101), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (97 of 101), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 46 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 77/100
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 940 tokens (~67/item across 14 items; 14 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add markswendsen-code-tacobell -- npx -y @striderlabs/mcp-tacobell
```

### Codex

```bash
codex mcp add markswendsen-code-tacobell -- npx -y @striderlabs/mcp-tacobell
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "markswendsen-code-tacobell": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@striderlabs/mcp-tacobell"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add markswendsen-code-tacobell --command npx --arg -y --arg @striderlabs/mcp-tacobell
```

### Hermes

```yaml
mcp_servers:
  markswendsen-code-tacobell:
    command: "npx"
    args: ["-y", "@striderlabs/mcp-tacobell"]
```

### Other

```json
{
  "mcpServers": {
    "markswendsen-code-tacobell": {
      "command": "npx",
      "args": [
        "-y",
        "@striderlabs/mcp-tacobell"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 66, +45)

- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] Schema quality: unverified → excellent
- [functional improvement] License: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] MCP protocol: unverified → pass
- [functional] Licence: MIT

### 2026-07-31 (score 21, −7)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 28, +4)

- [security regression] Malware scan: pass → unverified
- [functional improvement] Tool coverage: unverified → 100

### 2026-07-28 (score 24, −22)

- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-07-27 (score 46)

First indexed and scored.

## MCP tools (14)

### `taco_bell_status` (~32 tokens)

Check connection status and whether you are logged in to Taco Bell. Call this first to verify authentication before ordering.

### `taco_bell_login` (~59 tokens)

Authenticate with your Taco Bell account using email and password. Required to place orders, access Taco Bell Rewards, and view order history.

Input parameters:

- `email` (string, required): Taco Bell account email address
- `password` (string, required): Taco Bell account password

### `taco_bell_logout` (~28 tokens)

Log out of Taco Bell by clearing stored session cookies. Use this to reset authentication state.

### `get_menu` (~117 tokens)

Get the full Taco Bell menu or filter by category. Returns all items with names, prices, and calorie counts. Categories include: Tacos, Burritos, Quesadillas, Nachos, Bowls, Sides, Drinks, Combos, Breakfast, Vegetarian.

Input parameters:

- `category` (string): Optional category filter (e.g., 'Tacos', 'Burritos', 'Quesadillas', 'Nachos', 'Bowls', 'Sides', 'Drinks', 'Combos', 'Breakfast', 'Vegetarian')

### `search_menu` (~89 tokens)

Search the Taco Bell menu by name or keyword. Returns matching items with prices and calorie counts.

Input parameters:

- `category` (string): Optional category to narrow the search (e.g., 'Tacos', 'Burritos', 'Drinks')
- `query` (string, required): Search term (e.g., 'taco', 'burrito', 'nachos', 'chicken', 'vegetarian')

### `get_item_details` (~77 tokens)

Get full details for a menu item including all available customization options (protein, cheese, sauce, add-ons, tortilla type, etc.).

Input parameters:

- `itemId` (string, required): Item ID from get_menu or search_menu results (e.g., 'crunchy-taco', 'bean-burrito', 'nachos-bellgrande')

### `customize_item` (~116 tokens)

Build a customized Taco Bell item. Specify the item ID and your customization choices. Call add_to_cart afterwards to add it to your cart.

Input parameters:

- `customizations` (object): Key-value pairs of customizations. Examples: { "protein": "chicken", "cheese": "three-cheese", "sauce": "fire", "extras": ["sour-cream", "guacamole"], "tortilla": "flour" }
- `itemId` (string, required): Item ID from get_menu or search_menu results

### `add_to_cart` (~46 tokens)

Add the currently customized item to your cart. Call customize_item first. Optionally specify quantity.

Input parameters:

- `quantity` (number): Number of this item to add (default: 1)

### `view_cart` (~31 tokens)

View all items currently in your cart with customizations, quantities, and pricing. Also shows the selected pickup location.

### `remove_from_cart` (~62 tokens)

Remove an item from your cart by item ID or cart index.

Input parameters:

- `index` (number): Cart position index (0-based) to remove — useful if you have the same item multiple times
- `itemId` (string, required): Item ID to remove from cart

### `get_nearby_locations` (~92 tokens)

Find nearby Taco Bell locations by address or zip code. Returns location names, addresses, hours, and available features (drive-thru, delivery, mobile order).

Input parameters:

- `address` (string, required): Address, city, or zip code to search near (e.g., '90001', '123 Main St, Los Angeles CA')
- `radius` (number): Search radius in miles (default: 10)

### `checkout` (~111 tokens)

Checkout and place your Taco Bell order. Set confirm=false to preview the order first, confirm=true to actually place it. Requires being logged in to confirm.

Input parameters:

- `confirm` (boolean): Set true to place the order, false to preview only (default: false)
- `deliveryAddress` (string): Delivery address (required if fulfillment is 'delivery')
- `fulfillment` (string, required): Order fulfillment method
- `pickupTime` (string): Desired pickup time (e.g., 'ASAP', '6:30 PM')

### `get_rewards_status` (~32 tokens)

Check your Taco Bell Rewards points balance, reward level, and available rewards you can redeem. Requires being logged in.

### `view_orders` (~48 tokens)

View your past Taco Bell orders including items, dates, locations, and totals. Requires being logged in.

Input parameters:

- `limit` (number): Maximum number of past orders to return (default: 10)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/markswendsen-code-tacobell/striderlabs-mcp-tacobell#diagnostics

## Score history

- 2026-08-03: 66
- 2026-08-02: 66
- 2026-08-01: 21
- 2026-07-31: 21
- 2026-07-30: 28
- 2026-07-28: 24
- 2026-07-27: 46

## Links

- npm package: https://www.npmjs.com/package/@striderlabs/mcp-tacobell
- Socket report: https://socket.dev/npm/package/@striderlabs/mcp-tacobell
- Repository: https://github.com/markswendsen-code/mcp-tacobell
- Changelog RSS feed: https://verifymcp.io/servers/markswendsen-code-tacobell/striderlabs-mcp-tacobell/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/markswendsen-code-tacobell/striderlabs-mcp-tacobell/changelog.json
- HTML version of this page: https://verifymcp.io/servers/markswendsen-code-tacobell/striderlabs-mcp-tacobell
