Atlas / MCP servers / adeze / Raindrop

RaindropCAUTION

mcp/adeze/raindrop

Raindrop MCP Server

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
21 17r · 0w · 4d
Transport
stdio
License
MIT
Stars
188
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@adeze/raindrop-mcp) [](https://www.npmjs.com/package/@adeze/raindrop-mcp) [](https://github.com/adeze/raindrop-mcp/releases)

Connect Raindrop.io to your AI assistant with a simple MCP server. Use it to organize, search, and manage bookmarks with natural language.

Raindrop.io now also offers a hosted Streamable HTTP MCP endpoint (https://api.raindrop.io/rest/v2/ai/mcp) in beta for Pro users. Use that when its hosted toolset is sufficient; use this package for local stdio, self-hosted HTTP, and its additional library-management tools.

What it can do

  • Create, update, and delete collections and bookmarks
  • Search bookmarks by tags, domain, type, date, and more
  • Manage tags (list, rename, merge, delete)
  • Read highlights from bookmarks
  • Bulk edit bookmarks in a collection
  • Audit broken links and duplicates, and manage trash

Tools

  • diagnostics - Server diagnostic information and library health metrics
  • collection_list - List all collections as a flat list
  • get_collection_tree - Hierarchical view of collections with full breadcrumb paths
  • collection_manage - Create, update, or delete collections
  • bookmark_search - Advanced search with filters, tags, and pagination
  • bookmark_manage - Create, update, or delete bookmarks
  • get_raindrop - Fetch a single bookmark by ID
  • list_raindrops - List bookmarks for a collection with pagination
  • get_suggestions - AI-powered organization advice (tags/collections) for a URL or bookmark
  • suggest_tags - Suggest relevant tags from bookmark metadata using AI-assisted analysis
  • bulk_edit_raindrops - Bulk update, move, or remove bookmarks in a specific collection
  • tag_manage -
Read from source at commit 127d7d00b8d6OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add raindrop-mcp --env RAINDROP_ACCESS_TOKEN=${RAINDROP_ACCESS_TOKEN} --env RAINDROP_CLIENT_SECRET=${RAINDROP_CLIENT_SECRET} -- npx -y @adeze/[email protected]
claude-desktop
{
  "mcpServers": {
    "raindrop-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@adeze/[email protected]"
      ],
      "env": {
        "RAINDROP_ACCESS_TOKEN": "${RAINDROP_ACCESS_TOKEN}",
        "RAINDROP_CLIENT_SECRET": "${RAINDROP_CLIENT_SECRET}"
      }
    }
  }
}
03

Exposed tools (21)

17 read · 0 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bookmark_managereadCreates, updates, or deletes bookmarks. Use the operation parameter to specify the action.
bookmark_searchreadSearches bookmarks with advanced filters, tags, and full-text search.
bulk_edit_raindropsdestructiveBulk update, move, or remove bookmarks in a specific collection.
cleanup_collectionsdestructiveRemove all collections that do not contain any bookmarks. Requires
collection_listreadLists all Raindrop.io collections as a flat list.
collection_managereadCreates, updates, or deletes a collection. Use the operation parameter to specify the action.
diagnosticsreadDiagnostics resource and runtime metadata.
empty_trashdestructivePermanently delete all bookmarks currently in the trash collection. Requires
export_markdownreadRender bookmarks as Markdown list with title, link, tags, and excerpt.
find_duplicatesreadIdentify potential duplicate bookmarks using URL + title similarity.
get_collection_treereadReturns a hierarchical view of all collections with full breadcrumb paths.
get_raindropreadFetch a single Raindrop.io bookmark by ID.
get_suggestionsreadGet AI-powered suggestions for tags and collections for a specific URL or existing bookmark.
highlight_managereadCreates, updates, or deletes highlights. Use the operation parameter to specify the action.
library_auditreadScans the entire library for broken links and duplicate bookmarks.
list_raindropsreadList Raindrop.io bookmarks for a collection with pagination.
organize_by_topicreadAnalyze titles/excerpts and suggest collections + tags for organization.
remove_duplicatesdestructiveOptimized duplicate deletion pattern. Scans all collections and removes duplicates in batches of 50 to minimize round-trips. Supports dry run to report counts without deleting.
suggest_tagsreadUses AI to suggest relevant tags based on bookmark metadata (title, URL, description).
tag_managereadRenames, merges, or deletes tags. Use the operation parameter to specify the action.
test_toolreadA test tool
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
scripts/auth-check.mjs:9
/.env" ... fetch(
Why it matters. reads secrets in the same file that sends data out
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bulk_edit_raindrops, cleanup_collections, empty_trash, remove_duplicates
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/raindropmcp.service.ts:3
import pkg from "../../package.json";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/diagnostics.ts:2
import pkg from "../../package.json";
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/assets/hierarchy.js:1
window.hierarchyData = "eJyV0D1rwzAQgOH/cvMl9YdsFG0d2qntUGiXEIqwFSyqDyOdhxL834tJW+QujiaBuFfPoQsE7ymCONa8OCEEdTaqI+1dBHGBmhfL4aRVIOC5Gx9C8AEQPrXrQZQVR5iCAQGdkTGqeEdfo4of9mcy7n+b/UDWAF7nQADFfrc8srteIHSD
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/assets/navigation.js:1
window.navigationData = "eJytmV1v1DgUhv9L2MtSaCns0jt2WATa6W7VdrlBaORxPIk1jm3FTumC+O8omST+iH1splx1NHnPc15/HPtk+ulbocmDLi4LykvyUJwUEum6uCwaUXaMqGfD16e1blhxUuwpL4vL85MC15SVLeHF5acZ0CDKTfyu41hTwSdC/9TFvLr
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/assets/search.js:1
window.searchData = "eJy9XV2T2zay/S/yfZzYavDbb1knqXXd+G4qTvZlKpWiJYzEMiVqScpx1uX/fguAKDaApqbFDz95yiKaB+BBo9GnCX5Z1dVfzer145fVx+K4Xb0WD6tjfpCr16viuJWfVw+rc12uXq8O1fZcyuaV/t+X+/ZQrh5WmzJvGtmsXq9WXx86C3F
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/client, @modelcontextprotocol/node, @modelcontextprotocol/server, axios, dotenv, esm, express, keyv
Why it matters. 45 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/interfaces/types_raindrop.schema.operations.html
docs/interfaces/types_raindrop.schema.operations.html
Why it matters. 1073304 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 127d7d00b8d6full audit observations/trust-audit/mcp-server/adeze__raindrop.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06127d7d00b8d6CAUTIONB87first audit
06

Questions

What is the Raindrop MCP server?

Raindrop MCP Server

What tools does Raindrop expose?

21 in total: 17 read-only, 0 that write, and 4 that can delete or overwrite (bulk_edit_raindrops, cleanup_collections, empty_trash, remove_duplicates). Every one is listed on this page with its risk.

Is Raindrop safe to connect to an agent?

With care. The audit graded it B (87/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Raindrop need?

It reads RAINDROP_ACCESS_TOKEN and RAINDROP_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Raindrop run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @adeze/raindrop-mcp at 2.4.5.

How current is this page?

The grade is for one exact copy of the source (127d7d00b8d6), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement