Atlas / MCP servers / andrea9293 / Documentation

DocumentationCAUTION

mcp/andrea9293/documentation-2

MCP Documentation Server - Bridge the AI Knowledge Gap. ✨ Features: Document management • Gemini integration • AI-powered semantic search • File uploads • Smart chunking • Multilingual support • Zero-setup 🎯 Perfect for: New frameworks • API docs • Internal guides

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
12 9r · 2w · 1d
Transport
stdio
License
MIT
Stars
342
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://registry.modelcontextprotocol.io/servers/io.github.andrea9293/mcp-documentation-server) [](https://badge.fury.io/js/@andrea9293%2Fmcp-documentation-server) [](https://github.com/andrea9293/mcp-documentation-server) [](https://opensource.org/licenses/MIT) [](https://deepwiki.com/andrea9293/mcp-documentation-server)

[](https://www.paypal.com/donate/?hostedbuttonid=HXATGECV8HUJN) [](https://buymeacoffee.com/andrea.bravaccino)

Local-first document management and semantic search for AI coding agents. No external databases, no cloud APIs, no vendor lock-in.

Unlike other MCP servers that are CLI-only, this one ships with a full web dashboard — browse, search, upload, and manage your knowledge base from your browser. Every MCP tool is also exposed as a REST API, giving AI agents a lean, schema-free interface.

  • 🏠 Runs fully offline — Orama vector DB with local AI embeddings (Transformers.js)
  • 🌐 Built-in Web UI — starts automatically on port 3080 alongside the MCP server
  • 🔍 Hybrid search — full-text + vector similarity with parent-child chunking
  • 🤖 Optional AI search — Google Gemini for advanced document analysis (bring your own key)
  • 📁 Drag & drop uploads — .txt, .md, .pdf support
  • 📦 Published on the [MCP Registry](https://registry.modelcontextprotocol.io/servers/io.github.andrea9293/mcp-documentation-server) — installable via npx, no clone needed

Quick

Read from source at commit d7c2715bcebbOBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-documentation-server -- npx -y @andrea9293/[email protected]
03

Exposed tools (12)

9 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_documentwriteAdd a new document to the knowledge base
delete_documentdestructiveDelete a document from the collection
get_context_windowreadReturns a window of parent content sections around a central parent_index. Use parent_index values from search results. Always tell the user if result is truncated because of length.
get_documentreadUse this tool only when user explicitly requests it. Retrieve a specific document by ID. Always tell the user if result is truncated because of length. for example if you recive a message like this in the response:
get_ui_urlreadGet the URL of the web UI. use this tool when user ask you to access the web interface, when the user ask you to upload a file or when the user ask you the uploads folder path. All these function are available in the web UI.
get_uploads_pathreadGet the absolute path to the uploads folder where you can manually place .txt and .md files
list_documentsreadList all documents in the knowledge base
list_uploads_filesreadList all files in the uploads folder with their details
process_uploadswriteProcess all .txt and .md files in the uploads folder and create embeddings for them
search_all_documentsreadSearch for relevant chunks across ALL documents in the knowledge base using semantic similarity (hybrid: full-text + vector). Useful for cross-document search when you don
search_documentsreadSearch for chunks within a specific document using semantic similarity. Always tell the user if result is truncated because of length. for example if you recive a message like this in the response:
search_documents_with_aireadSearch within a document using Gemini AI for advanced semantic analysis and content extraction.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
skills/documentation-server/SKILL.md:10
This server provides a **local-first knowledge base** with semantic search, parent-child chunking, and an embedded vector database (Orama). Every operation available through the MCP protocol is also a
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_document
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:40
Every MCP tool is also accessible via the **REST API** on `http://127.0.0.1:3080/api/`. This is the recommended way to interact from AI agents (Claude Code, OpenCode, Gemini CLI, Cursor) because it av
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:43
curl -s http://127.0.0.1:3080/api/config
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:44
curl -s http://127.0.0.1:3080/api/documents
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:45
curl -s -X POST http://127.0.0.1:3080/api/search-all \
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google/genai, @modelcontextprotocol/sdk, @orama/orama, @orama/plugin-data-persistence, @types/express, @types/multer, @types/node, @xenova/transformers
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:177
* add dotenv import to load environment variables from .env files ([b91f578](https://github.com/andrea9293/mcp-documentation-server/commit/b91f5781bd3fe6d3c7bc89511d2560bb4fc37d3e))
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha d7c2715bcebbfull audit observations/trust-audit/mcp-server/andrea9293__documentation-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02d7c2715bcebbCAUTIONB89first audit
06

Questions

What is the Documentation MCP server?

MCP Documentation Server - Bridge the AI Knowledge Gap. ✨ Features: Document management • Gemini integration • AI-powered semantic search • File uploads • Smart chunking • Multilingual support • Zero-setup 🎯 Perfect for: New frameworks • API docs • Internal guides

What tools does Documentation expose?

12 in total: 9 read-only, 2 that write, and 1 that can delete or overwrite (delete_document). Every one is listed on this page with its risk.

Is Documentation safe to connect to an agent?

With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Documentation need?

It reads GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Documentation run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @andrea9293/mcp-documentation-server at 1.15.3.

How current is this page?

The grade is for one exact copy of the source (d7c2715bcebb), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement