Codabench Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Codabench Mcp (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
Aggregate score unchanged between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for the Codabench REST API. Lets an AI agent drive a full participant ML-benchmark workflow: discover competitions, read rules, download data, submit, poll, read leaderboards.
Curated tools for the participant path:
search_competitions, get_competition, list_competition_phases,get_phase, get_competition_rules, list_competition_tasks, get_task
download_dataset (streaming + SHA-256)list_my_submissions, get_submission, get_submission_logssubmit_to_phase (handles Codabench's 3-step upload flow)poll_submission (backoff + timeout + non-error "still_running")get_leaderboard, get_my_profilecodabench_request — generic REST escape hatch (GET-only by default)You need a Codabench API token. Two ways to get one:
api-token-auth endpoint → Try it outtoken value from the responsecurl -X POST https://www.codabench.org/api/api-token-auth/ \
-H "Content-Type: application/json" \
-d '{"username":"YOUR_USERNAME","password":"YOUR_PASSWORD"}'The response is {"token": "..."}.
uvx codabench-mcpTo run the bleeding-edge main branch instead of the last release:
uvx --from git+https://github.com/harshitAgr/codabench-mcp codabench-mcpOr for development:
git clone https://github.com/harshitAgr/codabench-mcp.git
cd codabench-mcp
uv sync
uv run codabench-mcp # requires CODABENCH_API_TOKENclaude_desktop_config.json){
"mcpServers": {
"codabench": {
"command": "uvx",
"args": ["codabench-mcp"],
"env": {
"CODABENCH_API_TOKEN": "paste-your-token-here"
}
}
}
}/plugin marketplace add harshitAgr/codabench-mcp
/plugin install codabench-mcp@codabench-mcpThen export your token in the shell where you launch Claude Code:
export CODABENCH_API_TOKEN=paste-your-token-hereIf you'd rather skip the plugin layer:
claude mcp add codabench \
--env CODABENCH_API_TOKEN=paste-your-token-here \
-- uvx codabench-mcp| Variable | Required | Default | Purpose |
|---|---|---|---|
CODABENCH_API_TOKEN | yes | — | DRF token, sent as Authorization: Token <token> |
CODABENCH_BASE_URL | no | https://www.codabench.org | Override for tests |
CODABENCH_ALLOW_WRITE_RAW | no | 0 | Set to 1 to allow non-GET methods through codabench_request |
CODABENCH_MAX_DOWNLOAD_BYTES | no | 5368709120 (5 GB) | Cap for download_dataset |
uv sync
uv run pytest # unit tests, no network
uv run ruff check . # lint
uv run ruff format --check . # format checkMIT — see LICENSE.
<sub>mcp-name: io.github.harshitAgr/codabench-mcp</sub>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.