LucidBLOCK
An intelligence layer grounding autonomous agents in verified, real-time knowledge at scale.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
__ __ __ _____ _____ ____ / / / / / // ___// _/ / __ \ / / / / / // / / / / / / / / /___/ /_/ // /___ _/ / / /_/ / /_____/\____/ \____//___/ /_____/
An intelligence layer grounding autonomous agents in verified, real-time knowledge at scale.
[](LICENSE) [](#)
What is Lucid?
AI agents hallucinate. They reference deprecated APIs, recommend outdated package versions and state "facts" from stale training data. Lucid fixes this by giving agents a real-time knowledge layer. Every response grounded in verified, live information.
Lucid runs as an MCP server that exposes four tools. When an agent needs documentation, package info, fact verification or API references, it queries Lucid instead of guessing from training data. Skills auto-trigger these tools based on conversation context so the agent doesn't even need to be asked.
Install
Claude Code Plugin
/plugin marketplace add get-Lucid/Lucid
Then install:
/plugin install lucid
OpenClaw Skills
openclaw skills install https://github.com/get-Lucid/Lucid
This installs all five skills (lucid-docs, lucid-packages, lucid-grounding, lucid-api, lucid-freshness) from the skills/ directory.
Setup
- Get an API key at [getlucid.tech/app](https://getlucid.tech/app)
- Set your key:
export LUCID_API_KEY=lk_your_key_here
That's it. The MCP server reads the key from your environment and authenticates every request.
Tools
da45d601d94fOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server --env LUCID_API_KEY=${LUCID_API_KEY} -- npx -y @lucid/[email protected]{
"mcpServers": {
"mcp-server": {
"command": "npx",
"args": [
"-y",
"@lucid/[email protected]"
],
"env": {
"LUCID_API_KEY": "${LUCID_API_KEY}"
}
}
}
}Exposed tools (5)
4 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
lucid_check_package | read | Check the latest version, changelog, and compatibility of any package. Ensures you recommend current, stable versions. |
lucid_fetch_api_ref | read | Fetch the latest API reference for a library or service. Returns structured endpoint docs, type signatures, and usage examples. |
lucid_search_docs | read | Search real-time documentation for any programming language, framework, or library. Returns verified, up-to-date information instead of potentially outdated training data. |
lucid_set_api_key | write | |
lucid_verify_fact | read | Verify a technical claim or fact against real-time sources. Use to ground uncertain statements in verified data. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);const decoded = JSON.parse(atob(base642));
atob(data);
const parsedHeader = JSON.parse(atob(header));
atob(val);
@modelcontextprotocol/sdk, zod, @types/node, esbuild, typescript
Gates applied: no_behavioural_pass.
da45d601d94ffull audit observations/trust-audit/mcp-server/get-lucid__lucid.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | da45d601d94f | BLOCK | D | 69 | first audit |
Questions
What is the Lucid MCP server?
An intelligence layer grounding autonomous agents in verified, real-time knowledge at scale.
What tools does Lucid expose?
5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Lucid safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Lucid need?
It reads LUCID_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Lucid run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @lucid/mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (da45d601d94f), read on 2026-10-07. The repository is watched and re-audited when it changes.