Esolat Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Esolat Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for accurate Malaysian prayer times (official JAKIM/e-Solat), nearest masjid and surau, and Islamic calendar events.
Gives AI assistants like Claude Desktop and Claude Code reliable, hallucination-free access to Islamic worship tools with smart Malaysia-first routing.
Waktusolat.app API)The server registers three powerful tools that Claude can discover and call automatically:
No clone needed:
uvx esolat-mcpClaude Desktop config example:
{
"mcpServers": {
"esolat": {
"command": "uvx",
"args": ["esolat-mcp"]
}
}
}1. Clone the repo and set up token:
git clone https://github.com/zubir2k/esolat-mcp.git
cd esolat-mcp
cp .env.example .env2. Generate a strong token:
python -c "import secrets; print(secrets.token_urlsafe(32))"
# or: openssl rand -hex 323. Paste it into `.env` as `MCP_WEBHOOK_TOKEN=your_token_here`
4. Build and Start the container:
docker build -t esolat-mcp:latest .
docker compose up -d5. Endpoints
- Streamable MCP HTTP Endpoint (main one for AI clients):
http://your-server-ip:8626/api/webhook/<MCP_WEBHOOK_TOKEN>/mcp- Health Dashboard (useful for monitoring):
http://your-server-ip:8626/api/webhook/<MCP_WEBHOOK_TOKEN>(GET request without /mcp — shows status of JAKIM, Aladhan, and Overpass APIs)
[!WARNING] Always keep yourMCP_WEBHOOK_TOKENsecret. The token is part of the URL path for simple authentication. You can change the local port via thePORTenvironment variable.
>
For production: Consider using a reverse proxy (Nginx/Cloudflare) with HTTPS to prevent the token from being intercepted or leaked in access logs.
[!TIP] Prefer a simpler setup? If you want a no-server, no-Docker solution that runs on the edge, consider my Cloudflare Worker edition (free tier eligible). It automatically enforces HTTPS and avoids the self-hosting risks mentioned above.
>
👉 Head over to the repo: zubir2k/esolat-cfworker
_"What are today's prayer times in Kuala Lumpur?" \ "Show me full prayer schedule for Penang this Ramadan." \ "Prayer times for Kota Kinabalu next week."_
_"Find the nearest mosque to me." \ "Mosques within 10km of Petaling Jaya." \ "Nearest surau from KLCC."_
_"Major Islamic events in 2026 for Malaysia." \ "Plan my trip to Johor Bahru: prayer times + nearest mosques + Eid dates."_
This project is licensed under the MIT License.
This integration pulls data directly from the official e-Solat JAKIM (Department of Islamic Development Malaysia) portal. However, please note:
By using this tool, you acknowledge and agree that the developer holds no liability for missed schedules or data inaccuracies.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.