Atlas / MCP servers / anipotts / Claude Code Tips

Claude Code TipsBLOCK

mcp/anipotts/claude-code-tips

guidance for coding with agents in production, from pet projects to startups and big tech

Verdict
BLOCK
Grade
D
Trust score
67 /100
Exposed tools
5 4r · 1w · 0d
Transport
stdio
License
MIT
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

this is my evidence backed guide to working with coding agents, whether you are a student having an existential crisis, a startup founder working with real money for yourself and other people, or an engineer at one of the biggest technology companies in the world. the guidance is organized around the scale and consequences of the work.

read the handbook or go directly to a principal guide:

what this helps you decide

the handbook separates the surface where you steer work, the harness that runs the agent loop, the model that supplies inference, and the orchestration used for parallel work. it also covers repository instructions, permissions, review, evidence, hardware, and the operating costs that appear after the first demo.

evidence principle

  • tested: reproduced in a named environment and version, with the tester and limits stated
  • official source: confirmed in current primary documentation or source code
  • analysis: a judgment derived from stated evidence
  • open question: current evidence is missing or incomplete

citations sit beside the claims they support. tested observations name their limits, while source based claims stay distinct from personal analysis.

local verification

bun install --frozen-lockfile
bun run verify

built and maintained by [ani potts](https://anipo

Read from source at commit 41255d868c47OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add cc --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "cc": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GITHUB_TOKEN": "${GITHUB_TOKEN}"
      }
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
inspect_sourcereadReturns the public title, publisher, URL, and evidence type for one source referenced by the handbook.
list_handbook_pageswriteLists canonical public coding agent tips pages with route, update, evidence, and source provenance.
open_handbook_pagereadNavigates to a validated canonical handbook route and optional heading on the current site.
read_handbook_sectionreadReads one public section by canonical route and heading anchor, returning bounded text and source provenance.
search_handbookreadSearches canonical public handbook text locally and returns bounded matches with provenance and normal URLs.
04

Trust audit

BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (6 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugins/cc/skills/sessions/SKILL.md:28
tool until restart) — use the bash fast path below. Don't tell the user
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugins/lore/skills/query/SKILL.md:296
NEVER write to the database. NEVER show SQL to the user. If a query fails, describe what data was unavailable, not which table was missing.
Why it matters. asks the agent to act without the user's knowledge
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugins/cc/server.ts:1338
"requests to the human instead of acting. Exfil guard refuses paths under " +
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/audit-performance.mjs:15
const origin = `http://127.0.0.1:${previewPort}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/lib/http2-preview.mjs:41
return { origin: `https://127.0.0.1:${server.address().port}`, close };
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/test-a11y.mjs:11
const origin = `http://127.0.0.1:${previewPort}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/test-agent-surface.mjs:125
const origin = `http://127.0.0.1:${port}`;
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
plugins/lore/tests/test_mine.py:180
result = mine.sanitize_string("token ghp_abcdefghijklmnopqrstuvwxyz0123456789")
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
plugins/lore/tests/test_mine.py:203
text = "sk-longkeyhere12345678901234 and ghp_anotherlongkey1234567890123456789012"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.jsonc
.markdownlint.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
plugins/lore/.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
plugins/lore/AGENTS.md
plugins/lore/AGENTS.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/integrations/editorial-progress.mjs:3
import { buildEditorialInventory } from '../../scripts/lib/editorial-inventory.mjs';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/pages/agent-pages/[...page].json.ts:2
import { buildAgentIndex } from '../../agent-index.mjs';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/pages/agent-pages/[...page].json.ts:3
import { contentKeyForRoute } from '../../agent-catalog.mjs';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/pages/agent-pages/[...page].json.ts:4
import { AGENT_CATALOG_VERSION } from '../../agent-index-version.mjs';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/rehype/link-metadata.mjs:3
const registry = JSON.parse(readFileSync(new URL('../../editorial/sources.json', import.meta.url), 'utf8'));
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
editorial/selected-homepage-qa.md:13
- Implementation: http://127.0.0.1:4330/, desktop light theme, scroll position 0, menus closed.
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
plugins/cc/package.json
@modelcontextprotocol/sdk, zod, zod-to-json-schema, typescript, @types/bun
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugins/cc/CHANGELOG.md:21
helper, silently. Don't tell the user it's a "fallback."
Why it matters. asks the agent to act without the user's knowledge
INFOInventory / provenance · inv.oversize · CWE-1104
public/media/guides/claude-terminal-recording.mp4
public/media/guides/claude-terminal-recording.mp4
Why it matters. 2749627 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
content/handbook/credentials-and-access.md:26
an access layer can keep credential values out of prompts and supply them to
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
plugins/cc/CHANGELOG.md:93
output now tunes by the active effort level read from `process.env.CLAUDE_EFFORT`:
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
plugins/cc/README.md:18
**runtime:** [bun](https://bun.sh) 1.1+. install with `curl -fsSL https://bun.sh/install | bash` (~15s, one-time). bun replaces node + tsx + better-sqlite3 with a single binary; cold-start is ~13× fas

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 41255d868c47full audit observations/trust-audit/mcp-server/anipotts__claude-code-tips.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0841255d868c47BLOCKD67first audit
06

Questions

What is the Claude Code Tips MCP server?

guidance for coding with agents in production, from pet projects to startups and big tech

What tools does Claude Code Tips expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Claude Code Tips safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (67/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Claude Code Tips need?

It reads GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Code Tips run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as cc at 3.8.0.

How current is this page?

The grade is for one exact copy of the source (41255d868c47), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement