Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.smeet666/mcp-recipes

NPM · MCP-RECIPES · 2 COMPONENTS · SCANNED SEP 21

Search six recipe sites at once, in French, English and Spanish, and scale quantities.

+1 this week 91 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 101 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to smeet666/mcp-recipes). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 17 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability61
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2273 tokens (~568/item across 4 items; 4 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
  • Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 4 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 5 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.smeet666/mcp-recipes server?

io.github.smeet666/mcp-recipes runs locally as an npm package, launched with npx -y mcp-recipes. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · mcp-recipes

# add to Claude Code
claude mcp add smeet666-mcp-recipes -- npx -y mcp-recipes
// .cursor/mcp.json
{
  "mcpServers": {
    "smeet666-mcp-recipes": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-recipes"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "smeet666-mcp-recipes": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-recipes"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add smeet666-mcp-recipes -- npx -y mcp-recipes
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "smeet666-mcp-recipes": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "mcp-recipes"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add smeet666-mcp-recipes --command npx --arg -y --arg mcp-recipes
# ~/.hermes/config.yaml
mcp_servers:
  smeet666-mcp-recipes:
    command: "npx"
    args: ["-y", "mcp-recipes"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "smeet666-mcp-recipes": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "mcp-recipes"
      ]
    }
  }
}
# add to Vellum
assistant mcp add smeet666-mcp-recipes -t stdio -c npx -a -y mcp-recipes
// mcp.json
{
  "mcpServers": {
    "smeet666-mcp-recipes": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-recipes"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 21 Sept 26 −1
    • Stability: pass → 0.87 functional
  • 20 Sept 26 0
    • Stability: 0.97 → pass security
  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 −2
    • Stability: pass → 0.80 functional
  • 13 Sept 26 0
    • Stability: 0.97 → pass security
  • 12 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 9 Sept 26 −1
    • Stability: pass → 0.87 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 21 Sept 2026 · Analysed npm/mcp-recipes@4.0.0

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem npm
Reason Verified
Discovered via Registry attestation endpoint
Source repo smeet666/mcp-recipes
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/smeet666/mcp-recipes/.github/workflows/publish.yml@refs/tags/v4.0.0
Rekor log index 2703365792
Predicate type https://slsa.dev/provenance/v1
Subject digest sha512:321af3de881161a206aa2f78705b9baeafc342eeb35dda3301862aaa6e5eaffea85941f5739041dcd8bc29bab71a6ffc489533e5c061809991d5056b3

Background: How many MCP packages publish verified provenance →

Dependencies 101 packages
Packages resolved 101
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 4 exposed · ~1,845 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
compare_recipes ~303

Take a dish and show how each source writes it, side by side. Each source's closest match is read in full, and all of them can be rescaled to the same number of servings so the ingredient lists stand comparison. The answer states what differs and leaves it there: the quantities each asks for, what each measures in, what each yields, and which fields each source publishes at all. No version is ranked above another. Some sources carry reader ratings and some have no author and no rating by nature, so there is no score they share. When only one source answers, the answer says so and shows that one rather than presenting part of a comparison as the whole of it.

NameTypeReqDescription
dishstringyesThe dish to compare, in any of the languages the sources publish in.
max_step_charsintegerCharacters kept per step. Raise it only if a step was cut mid-sentence.
max_stepsintegerSteps to return per version.
sectionsarrayWhich parts of each version to return. Several full recipes is a lot of text.
servingsintegerRescale every version to this many, which is what makes the lists comparable.
sourcesarraySources to compare, by id. Left out, every source is read, which is the point of this tool. Name two or three to put particular traditions side by side. The ids are the ones 'per_source' reports.
NameTypeReqDescription
differencesarrayyesWhat differs between the versions, stated as fact. No version is ranked.
dishstringyes
notesarrayyes
per_sourcearrayyes
versionsarrayyes

No examples provided.

get_recipe ~541

Read one recipe in full: its ingredients, its steps, what it yields, and whatever times, rating and nutrition its source publishes. 'id' must come from search_recipes. It names the source, so this reads the right one without guessing; an identifier no source would have minted is refused, because sending it anywhere would answer about the wrong dish. Pass 'servings' to rescale. Quantities land where a kitchen can follow them: an egg stays whole, anything that pours or cuts can halve, a small measurement moves to a smaller unit before it is rounded, and anything unmultipliable is flagged rather than scaled. A page that states no number of servings comes back as published and says so, because dividing by a yield nobody wrote would answer for a number of people the page never claimed. Read 'kind' first. Some sources publish articles gathering other recipes at the same kind of address as a recipe, and such an answer carries 'collection' with the recipes it points at and no 'recipe' at all: there is nothing to cook from that page, and the recipes it lists are read with get_recipe. A part this answer holds nothing for says which of two things happened: the page showed no sign of it, or this server failed to read what the page carries. An empty ingredient list is never evidence that an ingredient is absent from the dish. 'sections' decides what comes back, and 'sections_omitted' names what was left out: a field belonging to an omitted section is empty because nobody asked for it, never because the page states nothing. A field a source does not publish is null, never zero. Credit the source and link the url when you repeat any of it.

NameTypeReqDescription
idstringyesFrom search_recipes, such as 'marmiton:44078', 'pequerecetas:paella-de-marisco' or 'cookbook:Cookbook:Carbonara'. Two sources address a recipe by a bare number, so spell an id with its source.
max_gatheredintegerRecipes and headings to return from an address that gathers recipes. The answer says how many the article holds.
max_step_charsintegerCharacters kept per step. Raise it only if a step was cut mid-sentence.
max_stepsintegerSteps to return. The answer says how many more there are.
sectionsarrayWhich parts to return. A full recipe is a lot of text, so this defaults to two.
servingsintegerRescale to this many. Left out, the quantities come back as published.
NameTypeReqDescription
collectionobjectPresent when 'kind' is 'collection'.
id_read_asstring|nullyesHow a raw identifier was routed, when it was not spelled with its source.
kindstringyesWhat the address held. 'recipe' comes with 'recipe' and no 'collection'; 'collection' comes with 'collection' and no 'recipe', and is an article gathering other recipes, with no ingredients and no me…
notesarrayyes
recipeobjectPresent when 'kind' is 'recipe'.

No examples provided.

scale_ingredients ~378

Multiply a list of ingredient lines, in French, in English, in Spanish, or in a list holding more than one of them. Give either 'factor', or 'from_servings' and 'to_servings' and the factor is worked out from them. Quantities land where a kitchen can follow them: an egg stays whole because half of one is not something a cook takes out of the shell, while anything that pours, weighs or cuts can halve, a spoonful shrinks into the smaller spoon before it is rounded, and a pinch keeps whatever size a hand gives it while its count is multiplied. Every line comes back with 'scaling': 'scaled' when the arithmetic landed on the exact product, 'rounded' when something had to move for the line to stay usable, 'unscaled' when the line carries nothing to multiply. A rounded line says what it was rounded from and in which direction. No quantity is converted between measuring systems: grams stay grams and cups stay cups, because a conversion changes what the recipe said.

NameTypeReqDescription
factornumberWhat to multiply by. Give exactly one of: 'factor', or both 'from_servings' and 'to_servings'.
from_servingsintegerWhat the list serves now. Give it with 'to_servings', and without 'factor'.
ingredientsarrayyesThe lines as written, one ingredient each, such as '200 g de farine' or '3 eggs'. One line, not a whole recipe.
languagestring'auto' reads each line on its own, which is what a list holding more than one language needs. Name a language to read every line that way.
to_servingsintegerWhat it should serve. Give it with 'from_servings', and without 'factor'.
NameTypeReqDescription
equipment_countintegeryesLines naming a tool, which are never multiplied: a recipe made for more people uses the same pan.
factornumberyesWhat every quantity was multiplied by.
ingredientsarrayyes
languagestringyesHow the lines were read.
notesarrayyes
rounded_countintegeryesLines whose value moved to stay usable.
scaled_countintegeryesLines whose arithmetic came out exact.
unscaled_countintegeryesLines carrying nothing that can be multiplied, tools excepted.

No examples provided.

search_recipes ~623

Search every recipe source this server reads, at the same time, for a dish or an ingredient, and get one merged list. Each row carries the id get_recipe takes, and that id names the source it came from, so nothing has to be guessed afterwards. The sources are written in different languages and count their own results differently, so 'per_source' says what each one answered, what its own number means, and names any that failed. A short list is never evidence of what exists. Not every row opens onto a recipe. Some sources file pages about an ingredient beside the recipes using it, and some publish articles that gather recipes; 'per_source' says in each source's own words what one of its rows can be. Only get_recipe tells them apart, and it says what it read off the page. The query goes to each source's own search as free text. There is no filtering: a word naming a diet, a time or a calorie count matches only where that source's index happens to carry it. Ask in a whole sentence if that is the question. These indexes answer the words they are handed, so a sentence is also sent as the words naming the dish and as the dish word alone, and the rows are the union; 'per_source' lists every wording and what it returned. What the question says the recipe must not hold is set aside from those shorter wordings rather than searched for, and named back in the notes: a negation, an allergy stated as one, a diet named in one word, and the number of people at the table. No source filters on any of it, so open a row with get_recipe and read the ingredient list before calling it suitable. A condition is read with the food on whichever side of it the sentence put one, so 'allergique aux noix' and 'peanut allergy' both name the nut. Where a sentence puts a food on neither side, the notes say a condition was stated and that its food was not read, because naming the wrong word would hide a dish and search for the food being avoided at once. Rows are interleaved one source at a time rath…

NameTypeReqDescription
fan_outbooleanWhether a question may also be sent in shorter wordings derived from it. On, because these indexes answer the words they are handed: a question written as a sentence comes back empty from a corpus ho…
limit_per_sourceintegerRows to take from each source, so one source cannot fill the whole list.
querystringyesA dish or an ingredient, in any of the languages the sources publish in.
sourcesarraySources to ask, by id. Left out, they are all asked, which is the point of this tool. The ids are the ones 'per_source' reports.
NameTypeReqDescription
notesarrayyes
orderstringyesHow the list was built, in words.
per_sourcearrayyes
querystringyes
result_countintegeryesRows in this answer, across every source.
resultsarrayyes

No examples provided.

Common questions

What is the io.github.smeet666/mcp-recipes server?

io.github.smeet666/mcp-recipes is listed in the public MCP registry as io.github.smeet666/mcp-recipes. Search six recipe sites at once, in French, English and Spanish, and scale quantities. This page covers its npm package (mcp-recipes).

Is the io.github.smeet666/mcp-recipes server safe to use?

io.github.smeet666/mcp-recipes scores 91 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.smeet666/mcp-recipes server expose?

io.github.smeet666/mcp-recipes exposes 4 tools: search_recipes, get_recipe, scale_ingredients, compare_recipes. Their descriptions and schemas cost roughly 1,845 tokens of context every time the server is loaded.

Is the io.github.smeet666/mcp-recipes server still maintained?

io.github.smeet666/mcp-recipes is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.smeet666/mcp-recipes server under?

io.github.smeet666/mcp-recipes declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.