Atlas / MCP servers / esaio / Esa

EsaSAFE

mcp/esaio/esa-5

esa.io の公式 MCP(Model Context Protocol)サーバー(STDIO Transport版)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
31 17r · 13w · 1d
Transport
stdio
License
MIT
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT)

日本語 | English

esa.io の公式 MCP(Model Context Protocol)サーバー(STDIO Transport 版)

概要

AI アシスタントと情報共有サービス esa をつなぐ MCP サーバーです。Model Context Protocol 経由で、AI アシスタントから esa の記事を読んだり、作成・更新・管理などができます。

使えるツール

チーム管理

  • esa_get_teams - 所属している esa チームの一覧
  • esa_get_team_stats - チームの統計情報(メンバー数、記事数、コメント数など)
  • esa_get_team_tags - チーム内で使われているタグと使用回数
  • esa_get_team_members - チームメンバーとその役割・プロフィール

記事管理

  • esa_search_posts - 記事を検索
  • esa_get_post - 記事 ID から記事を取得(バックリンク総数 backlinks_count、本文の文字数・行数 body_md_stats を含む)
  • esa_get_post_backlinks - 指定記事を参照している記事の一覧(ページング対応)
  • esa_create_post - 新しい記事を作成(タグ、カテゴリー、WIP ステータス付き)
  • esa_update_post - 記事を更新(タイトル、本文、タグ、カテゴリー、WIP ステータス)
  • esa_append_post - 記事本文の末尾に追記(既存本文を取得せずに追記でき、新しいリビジョンとして保存)
  • esa_prepend_post - 記事本文の先頭に追記(既存本文を取得せずに追記でき、新しいリビジョンとして保存)

記事の操作

  • esa_archive_post - 記事をアーカイブ(Archived/ カテゴリーへ移動)
  • esa_ship_post - 記事を Ship It!(WIP を外して公開)
  • esa_duplicate_post - 記事を複製(同じタイトル・本文の WIP 記事を作成。別チームへの複製も可能)

コメント管理

  • esa_get_comment - コメント ID からコメントを取得
  • esa_create_comment - 記事にコメントを追加
  • esa_update_comment - コメントを編集
  • esa_delete_comment - コメントを削除
  • esa_get_post_comments - 記事のコメント一覧(ページング対応)
  • esa_get_team_comments - チーム全体のコメント一覧(ページング対応)

カテゴリー管理

  • esa_get_categories - 指定パス配下のカテゴリー一覧
  • esa_get_top_categories - トップレベルのカテゴリー一覧
  • esa_get_all_category_paths - チーム内の全カテゴリーパス一覧(記事数付き、フィルタリング対応)
  • カテゴリ構造の把握、整理、統合の計画に最適
  • フィルター例: prefix: "dev" で開発関連、match: "api" で API 関連を検索

添付ファイル

  • esa_get_attachment - 記事やコメントの添付ファイルを取得
  • サポート形式(JPEG, PNG, GIF, WebP)で 30MB 以下の画像は base64 エンコードで返却
  • その他のファイル、大きな画像、または forceSignedUrl 指定時は署名付き URL(有効期限 5 分)を返却

ヘルプとドキュメント

  • esa_get_search_options_help - esa の検索構文ヘルプ
  • esa_get_markdown_syntax_help - esa の Ma
Read from source at commit 0ed343314bdaOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add esa-mcp-server --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} -- npx -y @esaio/esa-mcp-server@__VERSION__
claude-code (oci)
claude mcp add esa-mcp-server:__VERSION__ --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} -- docker run -i --rm ghcr.io/esaio/esa-mcp-server:__VERSION__:None
03

Exposed tools (31)

17 read · 13 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
esa_append_postwrite
esa_archive_postwrite
esa_create_commentwrite
esa_create_postwrite
esa_delete_commentdestructive
esa_duplicate_postwrite
esa_get_all_category_pathsread
esa_get_attachmentread
esa_get_categoriesread
esa_get_commentread
esa_get_markdown_syntax_helpread
esa_get_postwrite
esa_get_post_backlinkswrite
esa_get_post_commentswrite
esa_get_search_options_helpread
esa_get_team_commentsread
esa_get_team_membersread
esa_get_team_statsread
esa_get_team_tagsread
esa_get_teamsread
esa_get_top_categoriesread
esa_prepend_postwrite
esa_rollback_post_revisionwrite
esa_search_helpread
esa_search_postsread
esa_ship_postwrite
esa_update_commentwrite
esa_update_postwrite
team1readTeam One
team2read
test-teamreadTest team
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
esa_delete_comment
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/fixtures/mock-backlink.ts:1
import type { components } from "../../generated/api-types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/fixtures/mock-backlink.ts:2
import { transformPostSummary } from "../../transformers/post-summary-transformer.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/fixtures/mock-comment.ts:1
import type { components } from "../../generated/api-types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/fixtures/mock-comment.ts:5
} from "../../transformers/comment-transformer.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/fixtures/mock-post.ts:1
import type { components } from "../../generated/api-types.js";
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/transformers/__tests__/post-transformer.test.ts:101
const post = createMockPost({ body_md: "a👨👩👧👦b" });
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, i18next, openapi-fetch, zod, @biomejs/biome, @types/node, @vitest/coverage-v8, tsdown
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0ed343314bdafull audit observations/trust-audit/mcp-server/esaio__esa-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070ed343314bdaSAFEB89first audit
06

Questions

What is the Esa MCP server?

esa.io の公式 MCP(Model Context Protocol)サーバー(STDIO Transport版)

What tools does Esa expose?

31 in total: 17 read-only, 13 that write, and 1 that can delete or overwrite (esa_delete_comment). Every one is listed on this page with its risk.

Is Esa safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Esa need?

It reads ESA_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Esa run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @esaio/esa-mcp-server at 0.14.1.

How current is this page?

The grade is for one exact copy of the source (0ed343314bda), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement