Atlas / MCP servers / get-lucid / Lucid

LucidBLOCK

mcp/get-lucid/lucid

An intelligence layer grounding autonomous agents in verified, real-time knowledge at scale.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
5 4r · 1w · 0d
Transport
stdio
License
MIT
Stars
75
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

__    __  __ _____ _____ ____
/ /   / / / // ___//  _/ / __ \
/ /   / / / // /    / /  / / / /
/ /___/ /_/ // /___ _/ /  / /_/ /
/_____/\____/ \____//___/ /_____/

An intelligence layer grounding autonomous agents in verified, real-time knowledge at scale.

[](LICENSE) [](#)

What is Lucid?

AI agents hallucinate. They reference deprecated APIs, recommend outdated package versions and state "facts" from stale training data. Lucid fixes this by giving agents a real-time knowledge layer. Every response grounded in verified, live information.

Lucid runs as an MCP server that exposes four tools. When an agent needs documentation, package info, fact verification or API references, it queries Lucid instead of guessing from training data. Skills auto-trigger these tools based on conversation context so the agent doesn't even need to be asked.

Install

Claude Code Plugin

/plugin marketplace add get-Lucid/Lucid

Then install:

/plugin install lucid

OpenClaw Skills

openclaw skills install https://github.com/get-Lucid/Lucid

This installs all five skills (lucid-docs, lucid-packages, lucid-grounding, lucid-api, lucid-freshness) from the skills/ directory.

Setup

  1. Get an API key at [getlucid.tech/app](https://getlucid.tech/app)
  2. Set your key:
export LUCID_API_KEY=lk_your_key_here

That's it. The MCP server reads the key from your environment and authenticates every request.

Tools

Read from source at commit da45d601d94fOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server --env LUCID_API_KEY=${LUCID_API_KEY} -- npx -y @lucid/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@lucid/[email protected]"
      ],
      "env": {
        "LUCID_API_KEY": "${LUCID_API_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
lucid_check_packagereadCheck the latest version, changelog, and compatibility of any package. Ensures you recommend current, stable versions.
lucid_fetch_api_refreadFetch the latest API reference for a library or service. Returns structured endpoint docs, type signatures, and usage examples.
lucid_search_docsreadSearch real-time documentation for any programming language, framework, or library. Returns verified, up-to-date information instead of potentially outdated training data.
lucid_set_api_keywrite
lucid_verify_factreadVerify a technical claim or fact against real-time sources. Use to ground uncertain statements in verified data.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp-server/dist/index.js:2941
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:7795
const decoded = JSON.parse(atob(base642));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:12331
atob(data);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:12392
const parsedHeader = JSON.parse(atob(header));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:16051
atob(val);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, zod, @types/node, esbuild, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha da45d601d94ffull audit observations/trust-audit/mcp-server/get-lucid__lucid.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07da45d601d94fBLOCKD69first audit
06

Questions

What is the Lucid MCP server?

An intelligence layer grounding autonomous agents in verified, real-time knowledge at scale.

What tools does Lucid expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Lucid safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Lucid need?

It reads LUCID_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Lucid run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @lucid/mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (da45d601d94f), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement