Atlas / MCP servers / geml-spec / geml

gemlBLOCK

mcp/geml-spec/geml

One format, two readers. People and AI agents now co-write the same document. Legible for people; addressable, verifiable, and versioned for machines. GEML is plain text — organized by one typed block for everything, remembered by a .gemlhistory sidecar.

Verdict
BLOCK
Grade
D
Trust score
67 /100
Exposed tools
12 9r · 2w · 1d
Transport
stdio
License
MIT
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mcptoplist.com/server/io.github.geml-spec%2Fgeml) [](https://glama.ai/mcp/servers/geml-spec/geml) [](https://github.com/hashgraph-online/awesome-ai-plugins#development--workflow) [](https://github.com/mundimark/awesome-markdown#beyond-markdown---lets-fix-markdown-quirks--oddities-and-lets-fill-in--add-the-missing-parts-tables-footnotes-generic-blocks-etc)

[](https://www.npmjs.com/package/@geml/geml) [](https://modelcontextprotocol.io) [](https://github.com/geml-spec/geml/actions/workflows/ci.yml) [](https://github.com/geml-spec/geml/actions/workflows/geml-check.yml) [](spec/GEML-spec.md) [](LICENSE) [](spec/LICENSE-spec.md)

English | 中文

GEML is a lightweight markup language with uniform, addressable blocks and standard verbs. Easy for humans to read, safe for agents to mutate. In agent-driven development and knowledge work, plain text and Markdown have no d

Read from source at commit 3dc7a8eb24ffOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add geml -- npx -y @geml/[email protected] mcp
03

Exposed tools (12)

9 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
geml_addwriteInsert new content — one or more blocks, or prose — at the end of the document (
geml_checkreadValidate a GEML document without changing it: returns every diagnostic with a stable
geml_codemap_callchainreadWalk the call graph SEVERAL hops from one symbol and get the whole chain back as an indented tree —
geml_codemap_listreadBrowse the graph by MODULE. Called with no argument it lists every module with its document and symbol count — the map to open first on an unfamiliar repo, before you know any name to search for. Called with a
geml_codemap_nodereadOpen ONE node of the graph verbatim: a symbol
geml_codemap_searchreadFind symbols in the code graph BY NAME — case-insensitive substring by default, or the whole name with
geml_deletedestructiveRemove one or more blocks, each named by an id or any address geml_list prints; a filter (
geml_getreadRead ONE block from a GEML document instead of the whole file: only that block comes back, typically a few percent of the document. Pass the
geml_listreadList every addressable block in a GEML document — its address, kind and heading text — in one call, with no paging. Call this FIRST: what it returns is what every other tool here addresses, and it is cheaper and more reliable than reading the file to see what is in it. Rows marked
geml_renamewriteRename a block id AND every reference to it in the same document, in one id-boundary-safe write. Use this rather than geml_set or a text search-and-replace, which would also hit ids that merely share a prefix. A Markdown heading
geml_revertreadUndo ONE block, leaving every other block byte-for-byte unchanged — recover a single block after a bad edit without losing the good edits around it.
geml_toreadConvert a WHOLE document and get the result back as text — the read half of the CLI
04

Trust audit

BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (9 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/WRITING-A-PARSER.md:78
assert parse(base) == parse("" + base) == parse(base.replace("\n", "\r\n")) == parse(base.replace("\n", "\r"))
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/WRITING-A-PARSER_CN.md:78
assert parse(base) == parse("" + base) == parse(base.replace("\n", "\r\n")) == parse(base.replace("\n", "\r"))
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
geml-parser/codemap/serve.mjs:152
const pre = await fetch(`http://127.0.0.1:${port}/`, { method: "HEAD" });
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
geml-parser/codemap/serve.mjs:172
const r = await fetch(`http://127.0.0.1:${port}/`, { method: "HEAD" });
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
geml-parser/codemap/serve.mjs:288
urlPath = decodeURIComponent(new URL(req.url, `http://127.0.0.1:${port}`).pathname);
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
geml-parser/src/media-verbs.ts:848
for (const block of text.replace(/^/, "").split(/\r?\n\s*\r?\n/)) {
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
geml_delete
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
geml-parser/test/fixtures/react-app/index.scip
index.scip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
integrations/codex-plugin/.codexignore
.codexignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
integrations/vscode/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
geml-parser-rs/src/host.rs:162
assert_eq!(h.read("a/d.geml", "../../x.geml"), None);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
geml-parser-rs/wasm/conformance.mjs:9
import { runConformance, manifest } from "../../geml-parser/test/conformance/_runner.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
geml-parser-rs/wasm/edits.mjs:9
import { manifest, runEdits } from "../../geml-parser/test/conformance/_edits.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
geml-parser-rs/wasm/profiles.mjs:14
const spec = new URL("../../spec/", import.meta.url);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
geml-parser/test/codemap.test.mjs:1627
...scipDoc("../../../src/helper.ts", [
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
geml-parser/test/cov-render.test.mjs:1040
"index.geml#a": { n: "a", src: "https://evil.example/beacon#L1-L2" },
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
geml-parser/test/graph-style.test.mjs:319
const style = parseGraphStyle('=== style-rule {match="geml-code-graph" palette="#fff url(https://beacon.example/x) red rgb(1,2,3) #12345678 expression(x)"}\n===\n');
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
geml-parser/test/graph-style.test.mjs:321
const none = parseGraphStyle('=== style-rule {match="geml-code-graph" palette="url(https://beacon.example/x)"}\n===\n');
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
integrations/chrome-geml-viewer/test/media-player.test.mjs:170
"https://evil.example/beacon.mp4", "https:/evil.example/beacon.mp4", "//evil.example/x.mp4",
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
integrations/chrome-geml-viewer/test/security.test.mjs:128
for (const [src, kindWord] of [["//evil/beacon", "image"], ["https://evil.example/x.png", "image"], ["https://evil.example/clip.mp4", "video"]]) {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/design/plans/2026-09-27-geml-media-explainer-slice.md:720
url: `http://127.0.0.1:${server.address().port}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/design/plans/2026-09-27-geml-media-explainer-slice.md:1689
浏览器打开 `http://127.0.0.1:8765/scenes/stage.html?scene=s07&preview=1&d=14`,底部可拖。
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
geml-parser/test/sec-parser.test.mjs:1304
"ϳavascript:alert(1)",       // GREEK LETTER YOT homoglyph for `j`
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
geml-parser/test/sec-parser.test.mjs:1305
"јavascript:alert(1)",       // CYRILLIC SMALL LETTER JE
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
geml-parser/test/conformance/impl2.mjs:665
const normalized = src.replace(/^/, "").replace(/\r\n?/g, "\n").replace(/\u0000/g, "�");

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3dc7a8eb24fffull audit observations/trust-audit/mcp-server/geml-spec__geml.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083dc7a8eb24ffBLOCKD67first audit
06

Questions

What is the geml MCP server?

One format, two readers. People and AI agents now co-write the same document. Legible for people; addressable, verifiable, and versioned for machines. GEML is plain text — organized by one typed block for everything, remembered by a .gemlhistory sidecar.

What tools does geml expose?

12 in total: 9 read-only, 2 that write, and 1 that can delete or overwrite (geml_delete). Every one is listed on this page with its risk.

Is geml safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (67/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does geml need?

It reads LOGSEQ_API_SERVER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does geml run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as geml at 1.1.6.

How current is this page?

The grade is for one exact copy of the source (3dc7a8eb24ff), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement