NOAA STOFS MCP Server
PYPI · STOFS-MCP · SCANNED OCT 4
NOAA STOFS storm surge forecasts, observation validation, and OPeNDAP data
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
- 2 of 37 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to oceanmodeling/ocean-mcp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 2 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability62
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1911 tokens (~238/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the NOAA STOFS MCP Server server?
NOAA STOFS MCP Server runs locally as a PyPI package, launched with uvx stofs-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · stofs-mcp
claude mcp add oceanmodeling-stofs-mcp -- uvx stofs-mcp
{
"mcpServers": {
"oceanmodeling-stofs-mcp": {
"command": "uvx",
"args": [
"stofs-mcp"
]
}
}
} {
"servers": {
"oceanmodeling-stofs-mcp": {
"command": "uvx",
"args": [
"stofs-mcp"
]
}
}
} codex mcp add oceanmodeling-stofs-mcp -- uvx stofs-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"oceanmodeling-stofs-mcp": {
"type": "local",
"command": [
"uvx",
"stofs-mcp"
],
"enabled": true
}
}
} openclaw mcp add oceanmodeling-stofs-mcp --command uvx --arg stofs-mcp
mcp_servers:
oceanmodeling-stofs-mcp:
command: "uvx"
args: ["stofs-mcp"] {
"McpServers": {
"oceanmodeling-stofs-mcp": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"stofs-mcp"
]
}
}
} assistant mcp add oceanmodeling-stofs-mcp -t stdio -c uvx -a stofs-mcp
{
"mcpServers": {
"oceanmodeling-stofs-mcp": {
"command": "uvx",
"args": [
"stofs-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Oct 26 +15
- Malware scan: unverified → pass ▲ security
- 1 Oct 26 62
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Analysed pypi/stofs-mcp@0.2.0
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | pypi |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | oceanmodeling/ocean-mcp |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/oceanmodeling/ocean-mcp/.github/workflows/publish.yml@refs/tags/stofs-mcp-v0.2.0 |
| Rekor log index | 3034476681 |
| Predicate type | PyPI publish attestation https://docs.pypi.org/attestations/publish/v1 |
| Subject digest | sha256:a9135dc72c0c5a6ab7ac8687adac16e79d2cb53823cc8375adba394ca5fde209 |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 37 packages
| Packages resolved | 37 |
|---|---|
| Stale | 1 |
| No linked repository | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
stofs_compare_with_observations ~362
Compare STOFS forecast against CO-OPS observed water levels at a station. Downloads the STOFS station file, fetches CO-OPS observations for the overlapping period, and aligns the two series. The response leads with a summary — observed and forecast peak (value and time), peak error, peak timing error, bias, RMSE — followed by the aligned series. Statistics always use every 6-minute point; the returned series is hourly unless full_resolution is set. The comparison window starts at the beginning of the station file, which is the nowcast 6 hours before the cycle time. To cover an event N hours after the cycle time, set hours_to_compare to at least N + 6. Args: station_id: CO-OPS station ID (e.g., '8518750' for The Battery, NY). model: '2d_global' or '3d_atlantic'. cycle_date: Date in YYYY-MM-DD format. Default: latest. cycle_hour: Cycle hour '00', '06', '12', '18'. Default: latest. hours_to_compare: Hours from the start of the file (default 24, max 96). full_resolution: Return every 6-minute point instead of hourly points. max_points: Maximum series points to return (default 2000). response_format: 'markdown' or 'json'.
| Name | Type | Req | Description |
|---|---|---|---|
| cycle_date | – | – | – |
| cycle_hour | – | – | – |
| full_resolution | boolean | – | – |
| hours_to_compare | integer | – | – |
| max_points | integer | – | – |
| model | – | – | – |
| response_format | string | – | – |
| station_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
stofs_get_gridded_forecast ~435
[CURRENTLY UNAVAILABLE — NOMADS OPeNDAP retired Oct 2025, NWS SCN 25-81] Get STOFS forecast at any lat/lon from the regular gridded product via OPeNDAP. Unlike stofs_get_station_forecast (limited to ~385 fixed CO-OPS stations), this tool queries the STOFS regular-grid product interpolated onto structured lat/lon grids and served via NOMADS OPeNDAP. Only the requested grid cell is downloaded — no large file transfer required. Coverage: US East Coast, Gulf, West Coast, Alaska, Hawaii, Puerto Rico, Guam. Resolution: ~2.5 km (conus/hawaii/guam), ~1.25 km (Puerto Rico), ~6 km (Alaska). Note: NOMADS OPeNDAP was RETIRED in October 2025 (NWS Service Change Notice 25-81), so this tool currently returns a retirement notice rather than data. Use stofs_get_point_forecast / stofs_get_station_forecast instead (station- based, reliable AWS S3). It is kept so the retirement is reported clearly, and so it resumes working automatically if NOMADS ever restores the service. Args: latitude: Target latitude in decimal degrees. longitude: Target longitude in decimal degrees. model: '2d_global' or '3d_atlantic'. variable: OPeNDAP variable name. Auto-detected if None. Common names: 'etcwlsfc' (combined WL), 'etsrgsfc' (surge only). cycle_date: Date in YYYY-MM-DD format. Default: latest available. cycle_hour: Cycle hour '00', '06', '12', '18'. Default: latest. response_format: 'markdown' or 'json'.
| Name | Type | Req | Description |
|---|---|---|---|
| cycle_date | – | – | – |
| cycle_hour | – | – | – |
| latitude | number | yes | – |
| longitude | number | yes | – |
| model | – | – | – |
| response_format | string | – | – |
| variable | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
stofs_get_max_water_level ~192
Get the stations with the highest predicted water levels in a STOFS cycle. Computes the maximum water level across all forecast timesteps for each station, then returns the top N sorted by peak value. Uses station files (not the large gridded maxele file). Args: model: '2d_global' or '3d_atlantic'. cycle_date: Date in YYYY-MM-DD format. Default: latest. cycle_hour: Cycle hour. Default: latest. top_n: Number of top stations to return (default 20). region: Optional region filter ('east_coast', 'gulf', etc.). response_format: 'markdown' or 'json'.
| Name | Type | Req | Description |
|---|---|---|---|
| cycle_date | – | – | – |
| cycle_hour | – | – | – |
| model | – | – | – |
| region | – | – | – |
| response_format | string | – | – |
| top_n | integer | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
stofs_get_point_forecast ~227
Get STOFS forecast at an arbitrary lat/lon by finding the nearest station. Downloads the station file and finds the closest STOFS output point to the requested location. Args: latitude: Target latitude in decimal degrees. longitude: Target longitude in decimal degrees. model: '2d_global' or '3d_atlantic'. product: 'cwl', 'htp', or 'swl' (3D only supports 'cwl'). cycle_date: Date in YYYY-MM-DD format. Default: latest. cycle_hour: Cycle hour '00', '06', '12', '18'. Default: latest. max_distance_km: Maximum search radius to nearest station (default 50 km). response_format: 'markdown' or 'json'.
| Name | Type | Req | Description |
|---|---|---|---|
| cycle_date | – | – | – |
| cycle_hour | – | – | – |
| latitude | number | yes | – |
| longitude | number | yes | – |
| max_distance_km | number | – | – |
| model | – | – | – |
| product | – | – | – |
| response_format | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
stofs_get_station_forecast ~251
Get STOFS water level forecast time series at a specific CO-OPS station. Downloads the station NetCDF file from AWS S3 (~2–10 MB) and extracts the full forecast time series for the specified station. Args: station_id: CO-OPS station ID (e.g., '8518750' for The Battery, NY). model: '2d_global' (global, 4x daily) or '3d_atlantic' (US East/Gulf, 1x daily). product: 'cwl' (combined), 'htp' (tidal only), 'swl' (surge only). Note: 3D-Atlantic only supports 'cwl'. cycle_date: Date in YYYY-MM-DD format. Default: latest available. cycle_hour: Cycle hour '00', '06', '12', '18'. Default: latest available. response_format: 'markdown' (default) or 'json'.
| Name | Type | Req | Description |
|---|---|---|---|
| cycle_date | – | – | – |
| cycle_hour | – | – | – |
| model | – | – | – |
| product | – | – | – |
| response_format | string | – | – |
| station_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
stofs_get_system_info ~84
Get STOFS system metadata — model specifications, datums, cycle schedule. Args: model: '2d_global', '3d_atlantic', or None for both. Default: None. include_stations: If True, include the full station registry. Default: False.
| Name | Type | Req | Description |
|---|---|---|---|
| include_stations | boolean | – | – |
| model | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
stofs_list_cycles ~134
List available STOFS forecast cycles on AWS S3 for a given date range. Checks AWS S3 for available station NetCDF files to determine which forecast cycles have been published. Args: model: 'two_global' (4x daily, global) or '3d_atlantic' (1x daily, US East/Gulf). date: Specific date in YYYY-MM-DD format. Default: today UTC. num_days: Number of past days to check (1–7). Default: 2.
| Name | Type | Req | Description |
|---|---|---|---|
| date | – | – | – |
| model | – | – | – |
| num_days | integer | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
stofs_list_stations ~226
List STOFS output stations, optionally filtered by location, state, or region. Uses the built-in station registry (~50 key CO-OPS stations). For the complete dynamic list, the station NetCDF file must be downloaded. Args: model: '2d_global' or '3d_atlantic'. near_lat: Filter to stations near this latitude. near_lon: Filter to stations near this longitude. radius_km: Search radius in km when near_lat/near_lon provided (default 100). state: Filter by US state abbreviation (e.g., 'NY', 'FL'). region: Filter by region ('east_coast', 'gulf', 'west_coast', 'alaska', 'hawaii', 'puerto_rico'). limit: Max stations to return (default 20).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| model | – | – | – |
| near_lat | – | – | – |
| near_lon | – | – | – |
| radius_km | number | – | – |
| region | – | – | – |
| state | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
What is the NOAA STOFS MCP Server server?
NOAA STOFS MCP Server is listed in the public MCP registry as io.github.oceanmodeling/stofs-mcp. NOAA STOFS storm surge forecasts, observation validation, and OPeNDAP data. This page covers its PyPI package (stofs-mcp).
Is the NOAA STOFS MCP Server server safe to use?
NOAA STOFS MCP Server scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the NOAA STOFS MCP Server server expose?
NOAA STOFS MCP Server exposes 8 tools: stofs_list_cycles, stofs_get_system_info, stofs_list_stations, stofs_get_station_forecast, stofs_get_point_forecast, and 3 more. Their descriptions and schemas cost roughly 1,911 tokens of context every time the server is loaded.
Is the NOAA STOFS MCP Server server still maintained?
NOAA STOFS MCP Server is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the NOAA STOFS MCP Server server under?
NOAA STOFS MCP Server declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.