Emy Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Emy Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server for Greek weather data from EMY — the Hellenic National Meteorological Service (Εθνική Μετεωρολογική Υπηρεσία).
It wraps EMY's public (api.emy.gr) endpoints as MCP tools. No API key is required, and nothing is hardcoded — locations and data are always fetched live from EMY.
| Tool | What it returns |
|---|---|
list_locations | The live directory of ~1035 forecast locations (id, Greek/English name, prefecture, coordinates). Optional name/prefecture filter. |
get_forecast | Today + up to 3 days for one location, resolved by name, id, or coordinates (nearest point). Temp max/min (°C), wind, precipitation probability, sky condition. |
get_alerts | Structured CAP alerts (event, severity, urgency, onset/expiry, area). |
get_marine | Marine bulletin for Greek seas (METAREA 3): forecast + warnings text. |
get_warnings | National emergency weather bulletins (text, Greek only — EMY publishes no English variant). |
get_climate_records | All-time Greek climate extremes (temperature, precipitation, wind). |
This is the tricky part. EMY stores names transliterated from Greek with a prefecture suffix, e.g. KORINTHOS (M. KORINTHIAS). Three independent problems:
(m. Korinthias).Κόρινθος vs KORINTHOS.How they're handled:
get_forecast(location=...) or list_locations(query=...).Names are accent-folded, suffix-stripped, and Greek is transliterated to Latin using EMY's own scheme, so Κόρινθος, korinthos and KORINTHOS all match. Fuzzy ranking handles typos and returns alternatives.
and call get_forecast(latitude=..., longitude=...). This returns the nearest forecast point regardless of spelling or language (e.g. Corinth's coordinates → Korinthos, 5 km away). An LLM client typically knows the coordinates already.
Everything is fetched live. Per endpoint:
(EMY's forecasts update ~twice daily).
24 hours, flagged stale with its age.
Every tool response includes a source block with fetched_at, age_minutes and stale.
api.emy.gr serves a valid *.emy.gr certificate but omits the intermediate CA from the handshake, so standard clients fail with "unable to get local issuer certificate". The client fetches the intermediate (RapidSSL TLS RSA CA G1) from the certificate's own AIA URL on first use and caches it under ~/.cache/emy-mcp/. Because a fetched cert is installed as a trusted anchor, it is pinned by SHA-256 fingerprint — a fetched or cached cert is only trusted if its fingerprint matches the known-good value, which makes the fetch safe against tampering and self-heals a corrupt cache. Certificate verification is not disabled; if EMY ever rotates this CA the pin must be updated.
cloudy, Scattered showers, Cloudy with rain, Thunderstorms — so it's coarse.
m/s and are labelled as such, but EMY does not document this.
forecasts, alerts, marine and climate. This server reflects that.
pip install -e . # or: pip install httpx certifi "mcp>=1.2"
# stdio (Claude Desktop, Claude Code, local assistants)
python -m emy_mcp
# streamable-HTTP (hostable)
python -m emy_mcp --http --host 0.0.0.0 --port 8000{
"mcpServers": {
"emy-weather": {
"command": "python",
"args": ["-m", "emy_mcp"]
}
}
}MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.