io.github.UncleTIM-GZ/oprocess
PYPI · OPROCESS · SCANNED SEP 22
AI-native process classification. 2436 processes + 3284 KPIs from APQC, ITIL, SCOR.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security38
- Malware scan not yet available for this package.Unverified
- No known CVEs affecting this package version or its production dependencies.Pass
- Install-script risk not yet assessed.Unverified
- 0 of 30 dependencies flagged as unhealthy. View diagnostics → Pass
Provenance & Transparency6
- Repository check failed: the declared repository URL returned HTTP 404. See how to fix → View diagnostics → Fail
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: the license (MIT License) isn't a recognized OSI-approved license. See how to fix → Fail
- Actively maintained (last published 53 days ago).Pass
- Security-disclosure policy not yet verified: we couldn't inspect the source repository.Unverified
Schema Quality & AI Usability84
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 767 tokens (~69/item across 11 items; 8 tools + 3 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management93
- Stability observed for 28 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage97
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 89% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.UncleTIM-GZ/oprocess MCP server?
io.github.UncleTIM-GZ/oprocess runs locally as a PyPI package, launched with uvx oprocess. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · oprocess
claude mcp add uncletim-gz-oprocess -- uvx oprocess
{
"mcpServers": {
"uncletim-gz-oprocess": {
"command": "uvx",
"args": [
"oprocess"
]
}
}
} {
"servers": {
"uncletim-gz-oprocess": {
"command": "uvx",
"args": [
"oprocess"
]
}
}
} codex mcp add uncletim-gz-oprocess -- uvx oprocess
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"uncletim-gz-oprocess": {
"type": "local",
"command": [
"uvx",
"oprocess"
],
"enabled": true
}
}
} openclaw mcp add uncletim-gz-oprocess --command uvx --arg oprocess
mcp_servers:
uncletim-gz-oprocess:
command: "uvx"
args: ["oprocess"] {
"McpServers": {
"uncletim-gz-oprocess": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"oprocess"
]
}
}
} assistant mcp add uncletim-gz-oprocess -t stdio -c uvx -a oprocess
{
"mcpServers": {
"uncletim-gz-oprocess": {
"command": "uvx",
"args": [
"oprocess"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 22 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −18
- Malware scan: pass → unverified ▼ security
- Stability: pass → 0.77 functional
- 16 Sept 26 0
- Stability: 0.97 → pass security
- 15 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 14 Sept 26 −14
- Malware scan: pass → unverified ▼ security
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Analysed pypi/oprocess@0.4.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Dependencies 30 packages
| Packages resolved | 30 |
|---|---|
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compare_processes Process Comparison ~66
Compare two or more process nodes side-by-side across all attributes. Accepts comma-separated process IDs. Returns differences in name, description, domain, level, KPI count, and hierarchy path for each node.
| Name | Type | Req | Description |
|---|---|---|---|
| process_ids | string | yes | Comma-separated process IDs (2+) |
| Name | Type | Req | Description |
|---|---|---|---|
| provenance_chain | array | – | – |
| response_ms | integer | – | – |
| result | – | yes | – |
| session_id | – | – | – |
No examples provided.
export_responsibility_doc Responsibility Document Export ~76
Export a complete role responsibility document. Generates Markdown with provenance appendix. Accepts one or more process IDs. Sections: role overview, responsibilities, KPIs, provenance.
| Name | Type | Req | Description |
|---|---|---|---|
| lang | string | – | Language |
| process_ids | string | yes | Comma-separated process IDs (1+) |
| role_name | – | – | Role name |
| Name | Type | Req | Description |
|---|---|---|---|
| provenance_chain | array | – | – |
| response_ms | integer | – | – |
| result | – | yes | – |
| session_id | – | – | – |
No examples provided.
get_kpi_suggestions KPI Suggestions ~69
Retrieve KPI metrics for a process node. Queries the 3284-entry KPI database. Returns process info, KPI list with name/unit/category, count, and provenance.
| Name | Type | Req | Description |
|---|---|---|---|
| process_id | string | yes | Process ID (e.g. '1.0', '8.5.3') |
| Name | Type | Req | Description |
|---|---|---|---|
| provenance_chain | array | – | – |
| response_ms | integer | – | – |
| result | – | yes | – |
| session_id | – | – | – |
No examples provided.
get_process_tree Process Tree ~105
Retrieve a process node and its full subtree. Returns hierarchical JSON with id, name, description, and nested children up to max_depth levels. Large trees are truncated at max_nodes with a warning. Use to explore the 5-level process taxonomy.
| Name | Type | Req | Description |
|---|---|---|---|
| max_depth | integer | – | Max depth |
| max_nodes | integer | – | Max nodes in response |
| process_id | string | yes | Process ID (e.g. '1.0', '8.5.3') |
| Name | Type | Req | Description |
|---|---|---|---|
| provenance_chain | array | – | – |
| response_ms | integer | – | – |
| result | – | yes | – |
| session_id | – | – | – |
No examples provided.
get_responsibilities Role Responsibilities ~85
Generate role responsibilities for a process node. Includes full hierarchy context: ancestor chain, sub-processes, and domain. Supports JSON or Markdown output. Has provenance.
| Name | Type | Req | Description |
|---|---|---|---|
| lang | string | – | Language |
| output_format | string | – | Output format |
| process_id | string | yes | Process ID (e.g. '1.0', '8.5.3') |
| Name | Type | Req | Description |
|---|---|---|---|
| provenance_chain | array | – | – |
| response_ms | integer | – | – |
| result | – | yes | – |
| session_id | – | – | – |
No examples provided.
health_check Health Check ~41
Health check for the O'Process MCP server. Returns JSON with status, server name, process/KPI counts, sqlite-vec availability, and semantic search readiness.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| semantic_search_available | boolean | yes | – |
| server | string | yes | – |
| status | string | yes | – |
| total_kpis | integer | yes | – |
| total_processes | integer | yes | – |
| vec_available | boolean | yes | – |
No examples provided.
map_role_to_processes Role-Process Mapping ~80
Map a job role to relevant process nodes. Uses semantic search to find matching processes. Returns ranked list with confidence scores. Optionally filter by industry tag. Low-confidence triggers BoundaryResponse.
| Name | Type | Req | Description |
|---|---|---|---|
| industry | – | – | Industry tag |
| lang | string | – | Language |
| limit | integer | – | Max matches |
| role_description | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| provenance_chain | array | – | – |
| response_ms | integer | – | – |
| result | – | yes | – |
| session_id | – | – | – |
No examples provided.
search_process Process Search ~103
Search the O'Process framework (2436 nodes). Covers APQC PCF 8.0 + ITIL V5 + SCOR DS 14.0. Supports semantic vector search with cosine similarity. Returns matching nodes with id, name, description, score. Low-confidence queries trigger BoundaryResponse.
| Name | Type | Req | Description |
|---|---|---|---|
| lang | string | – | Language |
| level | – | – | Level 1-5 |
| limit | integer | – | Max results |
| query | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| provenance_chain | array | – | – |
| response_ms | integer | – | – |
| result | – | yes | – |
| session_id | – | – | – |
No examples provided.
What is the io.github.UncleTIM-GZ/oprocess MCP server?
io.github.UncleTIM-GZ/oprocess is an MCP server listed in the public MCP registry as io.github.UncleTIM-GZ/oprocess. AI-native process classification. 2436 processes + 3284 KPIs from APQC, ITIL, SCOR. This page covers its PyPI package (oprocess).
Is the io.github.UncleTIM-GZ/oprocess MCP server safe to use?
io.github.UncleTIM-GZ/oprocess scores 59 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 22 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.UncleTIM-GZ/oprocess MCP server expose?
io.github.UncleTIM-GZ/oprocess exposes 8 tools: search_process, map_role_to_processes, get_process_tree, get_kpi_suggestions, compare_processes, and 3 more. Their descriptions and schemas cost roughly 625 tokens of context every time the server is loaded.
Is the io.github.UncleTIM-GZ/oprocess MCP server still maintained?
io.github.UncleTIM-GZ/oprocess is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.