4 MCP servers with elevated access found in the CZI data portal
This is charter's report. The repository commits a real .mcp.json declaring six MCP servers, which is what an agent working in this codebase is actually allowed to reach — a database, source control, the filesystem, and a browser. None of them were launched to produce this page.
- Repository
- chanzuckerberg/single-cell-data-portal
- Commit
- f41b2a4b1a0916a12767b52f567532b30a808418
- Subject
- fix: fall back to the free Crossref API when no Plus key is configured (#7798)
- Scanned
- 2026-09-16 · 862 source files
This is an independent analysis of a public repository. Foretop is not affiliated with or endorsed by the repository owner.
What Ebb, telltale, charter and lading found
Ebb, telltale, charter and lading are the checks you can install and re-run yourself today. Each one's scope, its result, and — below — every source it matched.
| Check | Scope | Results | Outcome |
|---|---|---|---|
| ebb | whole repo | 3 | Model IDs matched against the bundled retirement registry. |
| telltale | repo root | — | No OpenAPI spec at the repo root (tried openapi.yaml/.yml/.json, swagger.yaml/.yml/.json). There is no declared contract here to compare telemetry against. |
| charter | .mcp.json | 6 | Six declared MCP servers, classified from the committed config alone. Capabilities come from a registry of published server packages that cites the documentation each entry was transcribed from; credentials come from the env block and launch arguments the config itself declares. No server was launched, and one package is not curated — so it is still reported as unknown. |
| lading | python_dependencies/backend | 52 | 25 packages from a real requirements.txt, 16 resolved to a licence. Scoped to one of several dependency directories; an unpinned requirement names no single release, so it resolves against the latest metadata for that package rather than an exact version. |
Every result, grouped and filterable
Deduplicated into real issue groups, never one row per raw occurrence. Filter by check, deadline, provider or context, or search — every filter is reflected in the URL, so a filtered view is a link you can share.
6 issue groups across 6 occurrences · 34 scanned
Plan gpt-4 Plan · retires 2026-10-23 · configuration reference 1 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| configuration | backend/cellguide/common/providers/openai_provider.py:12:35 | gpt-4 |
Plan gpt-3.5-turbo Plan · retires 2026-10-23 · configuration reference 1 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| configuration | backend/cellguide/common/providers/openai_provider.py:12:64 | gpt-3.5-turbo |
Plan postgresql Plan · a credential is embedded in a launch argument · documented capabilities: read, not enumerated 1 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| server | .mcp.json:3 | postgresql (stdio): npx |
Plan github Plan · wired to GITHUB_PERSONAL_ACCESS_TOKEN · documented capabilities: network_egress, read, write, not enumerated 1 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| server | .mcp.json:11 | github (stdio): npx |
Plan playwright Plan · documented code_execution capability, not enumerated 1 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| server | .mcp.json:29 | playwright (stdio): npx |
Plan zeroheight Plan · wired to ZEROHEIGHT_ACCESS_TOKEN 1 occurrence(s)
| Context | Evidence | Excerpt |
|---|---|---|
| server | .mcp.json:41 | zeroheight (stdio): npx |
What one pull request granted
All six servers arrived in a single pull request, whose title is about a navigation entry point. Before it, this repository declared no MCP configuration at all; after it, an agent working here could reach a database, source control, the filesystem and a browser. Charter was not running on this repository when that landed, so there was no committed baseline to diff against — the commit immediately before the pull request was scanned to produce one, and the pull request was then scanned against it. The commit, the configuration change and every server named below are real.
| Server | Transport | Why it is flagged | State |
|---|---|---|---|
| postgresql | stdio | Act now · new server since baseline | ✕ break |
| github | stdio | Act now · new server since baseline | ✕ break |
| filesystem | stdio | Act now · new server since baseline | ✕ break |
| playwright | stdio | Act now · new server since baseline | ✕ break |
| sds-mcp | stdio | Act now · new server since baseline | ✕ break |
| zeroheight | stdio | Act now · new server since baseline | ✕ break |
Baseline 0876a03 →
e717928 (feat: UW-9 addition of byod entry point from cxg top nav (#7653)).
charter scan --base exits 1 on this change, which is what makes it a
pull-request gate rather than a report someone has to remember to read.
The same five checks, elsewhere
What a suite is for: the answers come back in a different shape for every codebase, and which checks have nothing to say is itself information.
LangChain — 1 model migration found in LangChain · Langfuse — 117 API operations with no declared telemetry config found in Langfuse · AutoGPT — 286 dependencies found in AutoGPT · nuxt.com — 3 declared MCP servers found in nuxt.com
Preview: what Undertow observed
Undertow is still in development. It is not publicly installable, and nothing below can be reproduced by a reader today — it is shown because a check that cannot see something has to say so, including here. Ebb, telltale, charter and lading, above, are all available now.
| Check | Scope | Observations | Outcome |
|---|---|---|---|
| undertow | — | — | Scans vendor subprocessor pages by URL, not repositories. Nothing in a source tree is in its scope by design. |
Run it on yours
Same command, same registry, no account and no upload — detection is local and only results ever leave your machine.
Results above are a snapshot at
commit f41b2a4, taken 2026-09-16. Both
projects move quickly; re-running it today may return something different, which is
rather the point.