Atlas / MCP servers / dejuknow / Md Redline

Md RedlineBLOCK

mcp/dejuknow/md-redline

Inline review comments for markdown specs. Built-in MCP server hands feedback directly to your AI agent.

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
6 3r · 3w · 0d
Transport
stdio
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/md-redline)

Inline review comments for markdown specs, prompts, and design docs.

Highlight text in a rendered document, leave comments, and your AI agent can read and address them directly. Comments are stored as invisible HTML markers in the .md file itself. No sidecar files, no database, no external service. The markdown file stays the source of truth.

With the built-in MCP server, review runs in both directions. Your agent can request your review mid-task and pause until you send your feedback, or review a doc you wrote and leave anchored comments for you. Either way: no copy-paste, no context switching.

See the full review workflow in about 30 seconds:

https://github.com/user-attachments/assets/8b9b3546-a895-42e1-b3cc-5ee5b2c00398

Works with Claude Code, Claude Desktop, Codex CLI, Gemini CLI, and any other MCP client that supports stdio servers. As Sean Grove argues in specs are the new code, specs are becoming the primary unit of work in agentic development. mdr gives that workflow review tooling closer to code review.

Quick start

Prerequisite: Node 20 or newer.

npx md-redline /path/to/spec.md

This starts the local app if needed and opens it in your browser.

Or install globally:

npm install -g md-redline
mdr /path/to/spec.md        # Open a file
mdr /path/to/dir             # Open a directory
mdr --stop                   # Stop the running server
mdr sessions                 # List open review sessions (--kill ID ends one)

md-redline also works as an alias for mdr.

That gives you the v

Read from source at commit ab9aad89cc75OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add md-redline -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "md-redline": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (6)

3 read · 3 write · 0 destructive.

ToolRiskDescription
mdr_add_fileswriteAdd markdown files to a review session that is already open in mdr
mdr_askreadAsk the user one or more questions anchored to specific text in a file
mdr_baselinewriteCall this BEFORE you edit markdown files the user will later review in mdr
mdr_commentwritePost YOUR OWN comments into markdown files for the user to read.
mdr_request_reviewreadOpen markdown files in mdr (md-redline) so the USER can review them and
mdr_waitreadBlock until the user has finished engaging with an mdr_comment session.
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (10 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (23)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
bin/server-control.js:44
const output = exec(command, { encoding: 'utf8' }) ?? '';
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
bin/server-control.js:55
exec(`taskkill /PID ${pid} /F`, { stdio: 'ignore' });
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
bin/server-control.js:62
exec(command, { stdio: 'ignore' });
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bin/cli.js:242
const response = await fetch(`http://127.0.0.1:${p}/__mdr__`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bin/cli.js:554
const response = await fetch(`http://127.0.0.1:${port}/api/version`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bin/cli.js:724
const baseUrl = `http://127.0.0.1:${port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bin/cli.js:1087
const res = await fetch(`http://127.0.0.1:${port}/api/baselines`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bin/cli.js:1157
const base = `http://127.0.0.1:${port}`;
LOWInventory / provenance · inv.hidden_file · CWE-1104
.git-blame-ignore-revs
.git-blame-ignore-revs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
eval/agents/claude-cli-remove.ts:4
import { buildAddressCommentsPrompt } from '../../src/lib/agent-prompts.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
eval/agents/claude-cli-remove.ts:5
import { parseComments } from '../../src/lib/comment-parser.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
eval/agents/claude-cli-resolve.ts:4
import { buildAddressCommentsPrompt } from '../../src/lib/agent-prompts.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
eval/agents/claude-cli-resolve.ts:5
import { parseComments } from '../../src/lib/comment-parser.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/routes/review-sessions.ts:12
} from '../../src/lib/comment-parser';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@fontsource-variable/inter, @fontsource-variable/jetbrains-mono, @fontsource-variable/source-serif-4, @hono/node-server, @modelcontextprotocol/sdk, dompurify, hast-util-phrasing, hast-util-whitespace
Why it matters. 54 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
eval/fixtures/07-threaded-comments/input.md:9
- **Admin**: Full access to all resources
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
eval/fixtures/20-threaded-comments-resolve/input.md:9
- **Admin**: Full access to all resources
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
sample.md:23
As a user, I want to sign in with my Google or GitHub account so that I can access the application without creating a new password.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
sample.md:34
As a user, I want to sign in via a magic link sent to my email so that I can access the application without remembering a password.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
AGENTS.md:220
- `POST /api/review-sessions` — create a session (`{ filePaths, enableResolve?, origin?: 'user' | 'agent', clientId? }`). `enableResolve` defaults to the READER's saved setting, falling back to `DEFAU
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:265
| `MD_REDLINE_CLIENT_ID` | a new ID for each `mdr mcp` process | Identifies one agent session to `mdr mcp`. Set it once per agent session when a tool starts a fresh `mdr mcp` for every call (for examp
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
demo/assets/background.png
demo/assets/background.png
Why it matters. 1517853 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha ab9aad89cc75full audit observations/trust-audit/mcp-server/dejuknow__md-redline.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ab9aad89cc75BLOCKF56first audit
06

Questions

What is the Md Redline MCP server?

Inline review comments for markdown specs. Built-in MCP server hands feedback directly to your AI agent.

What tools does Md Redline expose?

6 in total: 3 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Md Redline safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Md Redline need?

No credential environment variables were found in its source, so it appears to need none.

How does Md Redline run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as md-redline at 0.10.0.

How current is this page?

The grade is for one exact copy of the source (ab9aad89cc75), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement