Atlas / MCP servers / braffolk / Summarization Functions

Summarization FunctionsSAFE

mcp/braffolk/summarization-functions

Provides summarised output from various actions that could otherwise eat up tokens and cause crashes for AI agents

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
7 6r · 1w · 0d
Transport
stdio
License
MIT
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Intelligent text summarization for the Model Context Protocol

Features • AI Agent Integration • Installation • Usage

[](https://smithery.ai/server/mcp-summarization-functions) [](https://www.npmjs.com/package/mcp-summarization-functions)

Overview

A powerful MCP server that provides intelligent summarization capabilities through a clean, extensible architecture. Built with modern TypeScript and designed for seamless integration with AI workflows.

Installation

Installing via Smithery

To install Summarization Functions for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install mcp-summarization-functions --client claude
npm i mcp-summarization-functions

AI Agent Integration

This MCP server was primarily developed to enhance the performance and reliability of AI agents like Roo Cline and Cline. It addresses a critical challenge in AI agent operations: context window management.

Context Window Optimization

AI agents frequently encounter situations where their context window gets rapidly filled with large outputs from:

  • Command execution results
  • File content readings
  • Directory listings
  • API responses
  • Error messages and stack traces

This server helps maintain efficient context usage by:

  1. Providing concise, relevant summaries instead of full content
  2. Storing full content for reference when needed
  3. Offering focused analysis based on specific needs (security, API surface, etc.)
  4. Supporting multiple output formats for optimal context utilization

Benefits for AI Agents

  • Reduced Failure Rates: By preventing context window overflow
  • **Improved Response Qu
Read from source at commit 536256d68785OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-summarization-functions --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env MAX_TOKENS=${MAX_TOKENS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-summarization-functions": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "API_KEY": "${API_KEY}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "MAX_TOKENS": "${MAX_TOKENS}"
      }
    }
  }
}
03

Exposed tools (7)

6 read · 1 write · 0 destructive.

ToolRiskDescription
get_full_contentreadRetrieve the full content for a given summary ID
summarize_commandwriteExecute a command and summarize its output if it exceeds the threshold
summarize_directoryreadSummarize the structure of a directory
summarize_directoryEvalreadEvaluates the directory summarization functionality
summarize_filesreadSummarize the contents of one or more files
summarize_textreadSummarize any text content (e.g., MCP tool output)
summarize_textEvalreadEvaluates the summarize_text tool by providing text to summarize
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/models/claude.test.ts:20
import { AnthropicModel, createAnthropicModel } from '../../models/anthropic.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/models/claude.test.ts:21
import { ModelConfig, SummarizationOptions } from '../../types/models.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/models/claude.test.ts:22
import { constructPrompt, getBaseSummarizationInstructions, getFinalInstructions } from '../../models/prompts.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/models/integration.test.ts:7
import { createAnthropicModel } from '../../models/anthropic.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/models/integration.test.ts:8
import { OpenAIModel } from '../../models/openai.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @modelcontextprotocol/sdk, dotenv, execa, isomorphic-fetch, mcp-evals, uuid, @types/isomorphic-fetch
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:259
The evals package loads an mcp client that then runs the index.ts file, so there is no need to rebuild between tests. You can load environment variables by prefixing the npx command. Full documentatio
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
in_action.png
in_action.png
Why it matters. 1345212 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 536256d68785full audit observations/trust-audit/mcp-server/braffolk__summarization-functions.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08536256d68785SAFEB89first audit
06

Questions

What is the Summarization Functions MCP server?

Provides summarised output from various actions that could otherwise eat up tokens and cause crashes for AI agents

What tools does Summarization Functions expose?

7 in total: 6 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Summarization Functions safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Summarization Functions need?

It reads ANTHROPIC_API_KEY, API_KEY, GEMINI_API_KEY, MAX_TOKENS and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Summarization Functions run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-summarization-functions at 0.1.5.

How current is this page?

The grade is for one exact copy of the source (536256d68785), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement