Atlas / MCP servers / alekspetrov / Docs Service

Docs ServiceCAUTION

mcp/alekspetrov/docs-service

MCP Documentation Management Service - A Model Context Protocol implementation for documentation management

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
15 8r · 6w · 1d
Transport
stdio
License
MIT
Stars
58
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://codecov.io/gh/alekspetrov/mcp-docs-service)

What is it?

MCP Documentation Service is a Model Context Protocol (MCP) implementation for documentation management. It provides a set of tools for reading, writing, and managing markdown documentation with frontmatter metadata. The service is designed to work seamlessly with AI assistants like Claude in Cursor or Claude Desktop, making it easy to manage your documentation through natural language interactions.

Features

  • Read and Write Documents: Easily read and write markdown documents with frontmatter metadata
  • Edit Documents: Make precise line-based edits to documents with diff previews
  • List and Search: Find documents by content or metadata
  • Navigation Generation: Create navigation structures from your documentation
  • Health Checks: Analyze documentation quality and identify issues like missing metadata or broken links
  • LLM-Optimized Documentation: Generate consolidated single-document output optimized for large language models
  • MCP Integration: Seamless integration with the Model Context Protocol
  • Frontmatter Support: Full support for YAML frontmatter in markdown documents
  • Markdown Compatibility: Works with standard markdown files

Quick Start

Installation

Requires Node to be installed on your machine.

npm install -g mcp-docs-service

Or use directly with npx:

npx mcp-docs-service /path/to/docs

Cursor Integration

To use with Cursor, create a .cursor/mcp.json file in your project root:

{
"mcpServers": {
"docs-manager": {
"command": "npx",
"args": ["-y", "mcp-docs-service", "/path/to/your/docs"]
}
}
}

Claude

Read from source at commit ce16381a6361OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-docs-service -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-docs-service": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (15)

8 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
check_documentation_healthreadCheck the health of the documentation by analyzing frontmatter, links, and navigation.
consolidate_documentationreadGenerate a single consolidated markdown document optimized for LLM context windows.
create_documentation_folderwriteCreate a new folder in the docs directory. Optionally creates a README.md file
create_documentation_sectionwriteCreate a new navigation section with an index.md file.
edit_documentwriteMake line-based edits to a markdown document. Each edit replaces exact line sequences
generate_documentation_navigationreadGenerate a navigation structure from the markdown documents in the docs directory.
list_documentsreadList all markdown documents in the docs directory or a subdirectory.
move_documentwriteMove a document from one location to another. Optionally updates references to the
read_documentreadRead a markdown document from the docs directory. Returns the document content
rename_documentwriteRename a document while preserving its location and content. Optionally updates
search_documentsreadSearch for markdown documents containing specific text in their content or frontmatter.
update_documentation_navigation_orderwriteUpdate the navigation order of a document by modifying its frontmatter.
validate_documentation_linksreadCheck for broken internal links in documentation files.
validate_documentation_metadatareadEnsure all documents have required metadata fields.
write_documentdestructiveCreate a new markdown document or completely overwrite an existing document with new content.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMInventory / provenance · inv.binary · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
write_document
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/document-flow.test.ts:2
import { DocumentHandler } from "../../src/handlers/documents";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/document-flow.test.ts:3
import { NavigationHandler } from "../../src/handlers/navigation";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/document-flow.test.ts:4
import { HealthCheckHandler } from "../../src/handlers/health";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/document-handler.test.ts:2
import { DocumentHandler } from "../../src/handlers/documents";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/health-check-handler.test.ts:2
import { HealthCheckHandler } from "../../src/handlers/health";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, diff, glob, minimatch, zod, zod-to-json-schema, @types/diff, @types/node
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
temp-publish/package.json
@modelcontextprotocol/sdk, diff, glob, minimatch, zod, zod-to-json-schema, @types/diff, @types/node
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ce16381a6361full audit observations/trust-audit/mcp-server/alekspetrov__docs-service.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ce16381a6361CAUTIONB89first audit
06

Questions

What is the Docs Service MCP server?

MCP Documentation Management Service - A Model Context Protocol implementation for documentation management

What tools does Docs Service expose?

15 in total: 8 read-only, 6 that write, and 1 that can delete or overwrite (write_document). Every one is listed on this page with its risk.

Is Docs Service safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Docs Service need?

No credential environment variables were found in its source, so it appears to need none.

How does Docs Service run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-docs-service at 0.5.2.

How current is this page?

The grade is for one exact copy of the source (ce16381a6361), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement