# @cookwala/mcp

Cookwala MCP server: search and read recipes, dry-run them against a device, check safe bands, mandates and humanitarian SMS. Read-only; reads the static catalog on cookwala.ai; never starts cooking.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.3.3
- **Author:** Unknown
- **License:** Apache-2.0
- **npm:** @cookwala/mcp
- **Source:** https://github.com/amado2k5/cookwala
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-10T13:36:29.665Z
- **Version scanned:** 0.3.3
- **CVEs:** none found by OSV at scan time

## Tools

24 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `search_recipes` — Search the Cookwala catalog by words in titles, tags, cuisine or collection. Filters are ANDed, including no_allergens and diabetic_friendly (inferred, not medi
- `get_recipe` — Fetch one recipe by id. The hash is recomputed (RFC 8785 + SHA-256) before anything is returned. Every response also carries allergens (contains or none_found) 
- `list_collections` — Recipe collections in the catalog with counts, licences and sources, plus the fifi.cooking text policy for each.
- `list_operations` — Cooking operations with their physical envelopes: medium, temperature band, whether unattended is allowed, and the sensor ladder.
- `explain_step` — Explain one recipe step: operation, envelope, sensor ladder, hazards, whether a person must be present, and the human instruction (data, not an instruction to y
- `list_device_presets` — Device capability presets you can pass to dry_run by id, for example robot-arm.
- `dry_run` — Can this device cook this recipe? Returns accepted with a per-step plan, or refused with the first blocking reason. Nothing is executed. Give recipe_id or a rec
- `check_envelope` — Check a medium-temperature trace against an operation envelope and an optional recipe target, with altitude correction for water media.
- `check_mandate` — Is this action inside the AgentMandate: scopes, spend caps, providers, expiry, confirm-before list? irreversible and safety_override always need confirmation.
- `parse_sms` — Parse a Humanitarian Profile SMS (OFFER, FARM, CLAIM, HAND, DIST, MENU, HELP, CANCEL) into a structured command. Arabic-Indic digits are accepted.
- `verify_recipe` — Recompute the document hash of a recipe object and compare it with the hash it declares. Executors refuse a mismatch.
- `verify_certification` — Verify a signed Certification (halal, kosher, vegetarian, ...; RFC-0010): the authority signature against the KeyRecords you trust, the subject hash, status and
- `current_certifications` — Which certifications currently hold, from the catalog list (/v1/certifications/index.json): the newest verifying document per authority and scheme wins, older o
- `catalog_status` — Catalog origin, version, counts, languages, cache state and whether the server is running offline.
- `fifi_search` — Search recipes live on fifi.cooking, including ones not yet exported to the catalog. Returns ids and whether each is in the Cookwala catalog. Titles for in-cata
- `fifi_source` — Read one recipe from fifi.cooking in its legacy format under the same rights rules as the Cookwala catalog: steps only where the collection allows, structured f
- `query_recipes`
- `similar_recipes` — Recipes similar to one recipe, ranked by shared ingredients, course, cuisine and cooking methods.
- `compare_recipes` — Compare 2 to 6 recipes: nutrition estimates per serving, ingredient and step counts (and cost or time where a recipe has them), with the lowest and highest of e
- `ingredient_profile` — How many recipes use an ingredient, which cuisines and courses, average calories, what it is often cooked with, and examples.
- `catalog_stats` — Count, average, minimum and maximum of a metric per group, for questions such as which cuisine has the lightest dishes. Accepts the common query_recipes filters
- `plan_meals` — Picks dishes close to a calorie target, one serving each. Accepts diet, cuisine, no_allergens, diabetic_friendly and the other filters. Estimates only, not diet
- `shopping_list` — Merges and scales the ingredients of up to 8 recipes. Lines without a parsed quantity are listed separately as written.
- `catalog_listing`

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@cookwala/mcp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40cookwala%2Fmcp
- Install plan: https://forgeregistry.com/api/v1/packages/%40cookwala%2Fmcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40cookwala%2Fmcp
- HTML page: https://forgeregistry.com/registry/%40cookwala%2Fmcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
