DocumentationCAUTION
MCP Documentation Server - Bridge the AI Knowledge Gap. ✨ Features: Document management • Gemini integration • AI-powered semantic search • File uploads • Smart chunking • Multilingual support • Zero-setup 🎯 Perfect for: New frameworks • API docs • Internal guides
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://registry.modelcontextprotocol.io/servers/io.github.andrea9293/mcp-documentation-server) [](https://badge.fury.io/js/@andrea9293%2Fmcp-documentation-server) [](https://github.com/andrea9293/mcp-documentation-server) [](https://opensource.org/licenses/MIT) [](https://deepwiki.com/andrea9293/mcp-documentation-server)
[](https://www.paypal.com/donate/?hostedbuttonid=HXATGECV8HUJN) [](https://buymeacoffee.com/andrea.bravaccino)
Local-first document management and semantic search for AI coding agents. No external databases, no cloud APIs, no vendor lock-in.
Unlike other MCP servers that are CLI-only, this one ships with a full web dashboard — browse, search, upload, and manage your knowledge base from your browser. Every MCP tool is also exposed as a REST API, giving AI agents a lean, schema-free interface.
- 🏠 Runs fully offline — Orama vector DB with local AI embeddings (Transformers.js)
- 🌐 Built-in Web UI — starts automatically on port 3080 alongside the MCP server
- 🔍 Hybrid search — full-text + vector similarity with parent-child chunking
- 🤖 Optional AI search — Google Gemini for advanced document analysis (bring your own key)
- 📁 Drag & drop uploads —
.txt,.md,.pdfsupport - 📦 Published on the [MCP Registry](https://registry.modelcontextprotocol.io/servers/io.github.andrea9293/mcp-documentation-server) — installable via npx, no clone needed
Quick
d7c2715bcebbOBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-documentation-server -- npx -y @andrea9293/[email protected]
Exposed tools (12)
9 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_document | write | Add a new document to the knowledge base |
delete_document | destructive | Delete a document from the collection |
get_context_window | read | Returns a window of parent content sections around a central parent_index. Use parent_index values from search results. Always tell the user if result is truncated because of length. |
get_document | read | Use this tool only when user explicitly requests it. Retrieve a specific document by ID. Always tell the user if result is truncated because of length. for example if you recive a message like this in the response: |
get_ui_url | read | Get the URL of the web UI. use this tool when user ask you to access the web interface, when the user ask you to upload a file or when the user ask you the uploads folder path. All these function are available in the web UI. |
get_uploads_path | read | Get the absolute path to the uploads folder where you can manually place .txt and .md files |
list_documents | read | List all documents in the knowledge base |
list_uploads_files | read | List all files in the uploads folder with their details |
process_uploads | write | Process all .txt and .md files in the uploads folder and create embeddings for them |
search_all_documents | read | Search for relevant chunks across ALL documents in the knowledge base using semantic similarity (hybrid: full-text + vector). Useful for cross-document search when you don |
search_documents | read | Search for chunks within a specific document using semantic similarity. Always tell the user if result is truncated because of length. for example if you recive a message like this in the response: |
search_documents_with_ai | read | Search within a document using Gemini AI for advanced semantic analysis and content extraction. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
This server provides a **local-first knowledge base** with semantic search, parent-child chunking, and an embedded vector database (Orama). Every operation available through the MCP protocol is also a
delete_document
.releaserc.json
Every MCP tool is also accessible via the **REST API** on `http://127.0.0.1:3080/api/`. This is the recommended way to interact from AI agents (Claude Code, OpenCode, Gemini CLI, Cursor) because it av
curl -s http://127.0.0.1:3080/api/config
curl -s http://127.0.0.1:3080/api/documents
curl -s -X POST http://127.0.0.1:3080/api/search-all \
@google/genai, @modelcontextprotocol/sdk, @orama/orama, @orama/plugin-data-persistence, @types/express, @types/multer, @types/node, @xenova/transformers
* add dotenv import to load environment variables from .env files ([b91f578](https://github.com/andrea9293/mcp-documentation-server/commit/b91f5781bd3fe6d3c7bc89511d2560bb4fc37d3e))
Gates applied: no_behavioural_pass.
d7c2715bcebbfull audit observations/trust-audit/mcp-server/andrea9293__documentation-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | d7c2715bcebb | CAUTION | B | 89 | first audit |
Questions
What is the Documentation MCP server?
MCP Documentation Server - Bridge the AI Knowledge Gap. ✨ Features: Document management • Gemini integration • AI-powered semantic search • File uploads • Smart chunking • Multilingual support • Zero-setup 🎯 Perfect for: New frameworks • API docs • Internal guides
What tools does Documentation expose?
12 in total: 9 read-only, 2 that write, and 1 that can delete or overwrite (delete_document). Every one is listed on this page with its risk.
Is Documentation safe to connect to an agent?
With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Documentation need?
It reads GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Documentation run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @andrea9293/mcp-documentation-server at 1.15.3.
How current is this page?
The grade is for one exact copy of the source (d7c2715bcebb), read on 2026-10-02. The repository is watched and re-audited when it changes.