ClankiSAFE
An MCP server for connecting LLMs with Anki Flashcards.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/jasperket-clanki) [](https://opensource.org/licenses/MIT)
An MCP server that enables AI assistants like Claude to interact with Anki flashcard decks through the Model Context Protocol (MCP).
Features
- Create and manage Anki decks
- Create basic notes with front/back content
- Create cloze notes
- Create many notes at once in a single request
- Attach images and audio from URLs - automatically downloaded and embedded
- HTML formatting support in note fields
- Update existing notes and cloze deletions
- Add and manage tags
- Search for notes with Anki's query syntax
- Delete notes permanently
- View deck contents and note information
- Full integration with AnkiConnect
Prerequisites
- Anki installed and running
- AnkiConnect plugin installed in Anki
- Node.js 16 or higher
Installation
- Clone this repository:
git clone https://github.com/yourusername/clanki.git cd clanki
- Install dependencies:
npm install
- Build the project:
npm run build
Setup
- Make sure Anki is running and the AnkiConnect plugin is installed and enabled.
- Note the absolute path to
build/index.jsin your clanki checkout. Every
client below needs it, and none of them accept a relative path — they do not run from your project directory, so ./build/index.js will not resolve.
# from the clanki directory
node -e "console.log(require('path').resolve('build/index.js'))"On Windows this prints backslashes. They are fine as-is for the two CLI commands below, but must be doubled or swapped for forward slashes if you paste the path into a JSON config — see the Claude Desktop note.
- Register the server w
96e35a6162beOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add clanki -- npx -y [email protected]
{
"mcpServers": {
"clanki": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (8)
1 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create-card | write | Create a new note in a specified deck. Supports HTML formatting in text fields. You can attach multiple images and audio files from URLs - they will be automatically downloaded and embedded in the note. |
create-cards-bulk | write | Create multiple basic notes in a single call. Use this instead of calling create-card repeatedly — it sends one request to Anki regardless of how many notes are in the batch. Does not support images or audio: use create-card for notes that need media. |
create-cloze-card | write | Create a new cloze note in a specified deck. Use {{c1::text}} syntax for cloze deletions (e.g., {{c1::Paris}} is the capital of France). Supports HTML formatting and can attach multiple images and audio files from URLs - they will be automatically downloaded and embedded. |
create-cloze-cards-bulk | write | Create multiple cloze notes in a single call. Use this instead of calling create-cloze-card repeatedly — it sends one request to Anki regardless of how many notes are in the batch. Does not support images or audio: use create-cloze-card for notes that need media. |
create-deck | write | Create a new Anki deck |
find-cards | read | Search for notes using Anki |
update-card | write | Update an existing note |
update-cloze-card | write | Update an existing cloze note |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
in the collection, query AnkiConnect directly on `http://127.0.0.1:8765`
curl -X POST http://127.0.0.1:8765 -d "{\"action\":\"version\",\"version\":6}"| `CLANKI_ANKI_CONNECT_URL` | `http://127.0.0.1:8765` |
curl -X POST http://127.0.0.1:8765 -d "{\"action\":\"version\",\"version\":6}"Invoke-RestMethod -Uri http://127.0.0.1:8765 -Method Post -Body '{"action":"version","version":6}'@modelcontextprotocol/sdk, zod, @types/node, typescript, vitest
Gates applied: no_behavioural_pass.
96e35a6162befull audit observations/trust-audit/mcp-server/jasperket__clanki.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 96e35a6162be | SAFE | B | 89 | first audit |
Questions
What is the Clanki MCP server?
An MCP server for connecting LLMs with Anki Flashcards.
What tools does Clanki expose?
8 in total: 1 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Clanki safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Clanki need?
No credential environment variables were found in its source, so it appears to need none.
How does Clanki run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as clanki at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (96e35a6162be), read on 2026-10-08. The repository is watched and re-audited when it changes.