EsaSAFE
esa.io の公式 MCP(Model Context Protocol)サーバー(STDIO Transport版)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT)
日本語 | English
esa.io の公式 MCP(Model Context Protocol)サーバー(STDIO Transport 版)
概要
AI アシスタントと情報共有サービス esa をつなぐ MCP サーバーです。Model Context Protocol 経由で、AI アシスタントから esa の記事を読んだり、作成・更新・管理などができます。
使えるツール
チーム管理
esa_get_teams- 所属している esa チームの一覧esa_get_team_stats- チームの統計情報(メンバー数、記事数、コメント数など)esa_get_team_tags- チーム内で使われているタグと使用回数esa_get_team_members- チームメンバーとその役割・プロフィール
記事管理
esa_search_posts- 記事を検索esa_get_post- 記事 ID から記事を取得(バックリンク総数backlinks_count、本文の文字数・行数body_md_statsを含む)esa_get_post_backlinks- 指定記事を参照している記事の一覧(ページング対応)esa_create_post- 新しい記事を作成(タグ、カテゴリー、WIP ステータス付き)esa_update_post- 記事を更新(タイトル、本文、タグ、カテゴリー、WIP ステータス)esa_append_post- 記事本文の末尾に追記(既存本文を取得せずに追記でき、新しいリビジョンとして保存)esa_prepend_post- 記事本文の先頭に追記(既存本文を取得せずに追記でき、新しいリビジョンとして保存)
記事の操作
esa_archive_post- 記事をアーカイブ(Archived/ カテゴリーへ移動)esa_ship_post- 記事を Ship It!(WIP を外して公開)esa_duplicate_post- 記事を複製(同じタイトル・本文の WIP 記事を作成。別チームへの複製も可能)
コメント管理
esa_get_comment- コメント ID からコメントを取得esa_create_comment- 記事にコメントを追加esa_update_comment- コメントを編集esa_delete_comment- コメントを削除esa_get_post_comments- 記事のコメント一覧(ページング対応)esa_get_team_comments- チーム全体のコメント一覧(ページング対応)
カテゴリー管理
esa_get_categories- 指定パス配下のカテゴリー一覧esa_get_top_categories- トップレベルのカテゴリー一覧esa_get_all_category_paths- チーム内の全カテゴリーパス一覧(記事数付き、フィルタリング対応)- カテゴリ構造の把握、整理、統合の計画に最適
- フィルター例:
prefix: "dev"で開発関連、match: "api"で API 関連を検索
添付ファイル
esa_get_attachment- 記事やコメントの添付ファイルを取得- サポート形式(JPEG, PNG, GIF, WebP)で 30MB 以下の画像は base64 エンコードで返却
- その他のファイル、大きな画像、または forceSignedUrl 指定時は署名付き URL(有効期限 5 分)を返却
ヘルプとドキュメント
esa_get_search_options_help- esa の検索構文ヘルプesa_get_markdown_syntax_help- esa の Ma
0ed343314bdaOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add esa-mcp-server --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} -- npx -y @esaio/esa-mcp-server@__VERSION__claude mcp add esa-mcp-server:__VERSION__ --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} --env ESA_ACCESS_TOKEN=${ESA_ACCESS_TOKEN} -- docker run -i --rm ghcr.io/esaio/esa-mcp-server:__VERSION__:NoneExposed tools (31)
17 read · 13 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
esa_append_post | write | |
esa_archive_post | write | |
esa_create_comment | write | |
esa_create_post | write | |
esa_delete_comment | destructive | |
esa_duplicate_post | write | |
esa_get_all_category_paths | read | |
esa_get_attachment | read | |
esa_get_categories | read | |
esa_get_comment | read | |
esa_get_markdown_syntax_help | read | |
esa_get_post | write | |
esa_get_post_backlinks | write | |
esa_get_post_comments | write | |
esa_get_search_options_help | read | |
esa_get_team_comments | read | |
esa_get_team_members | read | |
esa_get_team_stats | read | |
esa_get_team_tags | read | |
esa_get_teams | read | |
esa_get_top_categories | read | |
esa_prepend_post | write | |
esa_rollback_post_revision | write | |
esa_search_help | read | |
esa_search_posts | read | |
esa_ship_post | write | |
esa_update_comment | write | |
esa_update_post | write | |
team1 | read | Team One |
team2 | read | |
test-team | read | Test team |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
esa_delete_comment
import type { components } from "../../generated/api-types.js";import { transformPostSummary } from "../../transformers/post-summary-transformer.js";import type { components } from "../../generated/api-types.js";} from "../../transformers/comment-transformer.js";
import type { components } from "../../generated/api-types.js";const post = createMockPost({ body_md: "a👨👩👧👦b" });@modelcontextprotocol/sdk, i18next, openapi-fetch, zod, @biomejs/biome, @types/node, @vitest/coverage-v8, tsdown
Gates applied: no_behavioural_pass.
0ed343314bdafull audit observations/trust-audit/mcp-server/esaio__esa-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0ed343314bda | SAFE | B | 89 | first audit |
Questions
What is the Esa MCP server?
esa.io の公式 MCP(Model Context Protocol)サーバー(STDIO Transport版)
What tools does Esa expose?
31 in total: 17 read-only, 13 that write, and 1 that can delete or overwrite (esa_delete_comment). Every one is listed on this page with its risk.
Is Esa safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Esa need?
It reads ESA_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Esa run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @esaio/esa-mcp-server at 0.14.1.
How current is this page?
The grade is for one exact copy of the source (0ed343314bda), read on 2026-10-07. The repository is watched and re-audited when it changes.