Atlas / MCP servers / jlcases / PaellaDOC

PaellaDOCCAUTION

mcp/jlcases/paelladoc

[Historical v0.x] Original MCP framework — current product at paelladoc.com

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
16 14r · 1w · 1d
Transport
stdio
License
AGPL-3.0
Stars
336
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚠️ Historical — preserved for reference This repository is PaellaDoc v0.x (340+ ⭐, 2024–2025), the original MCP-based framework. The current product is a desktop orchestrator at [paelladoc.com](https://paelladoc.com) with native Claude Code, Codex and Gemini integration, Playwright-verified Golden Gate, and a community at [forum.paelladoc.com](https://forum.paelladoc.com). This repo is preserved as historical reference and is no longer actively maintained.

[Visit the Official Website](https://paelladoc.com)

Perfect AI development, like perfect paella: quality ingredients, structure, and expertise.

⭐ If you find PAELLADOC useful, please consider starring the repo! ⭐ </ =======

[](https://github.com/jlcases/paelladoc) [](https://x.com/i/communities/1907494161458090406) [](https://discord.gg/grKF8EaB)

Version 0.3.7: Hotfix release restoring core project CRUD tools inadvertently omitted in v0.3.6 build. Check the CHANGELOG for details!
"In the AI era, context isn't supplementary to code—it's the primary creation."

PAELLADOC is an AI-First Development framework that implements the [5 Philosophical Principles of AI

Read from source at commit fb1bc4409d1cOBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add paelladoc -- uvx paelladoc
claude-desktop
{
  "mcpServers": {
    "paelladoc": {
      "command": "uvx",
      "args": [
        "paelladoc"
      ]
    }
  }
}
03

Exposed tools (16)

14 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
code_generationreadThe command uses the script at `.cursor/rules/scripts/extract_repo_content.py` to perform the repository extraction, which leverages repopack-py to convert the codebase to text.
coding_stylesreadApplies, customizes, or lists coding styles.
core_continuereadLoads an existing project
core_delete_projectdestructiveDelete a project and optionally its files.
core_get_projectreadGet detailed information about a specific project.
core_helpreadProvides help information about available PAELLADOC commands.
core_update_projectwriteUpdate specific fields of a project.
core_verificationreadChecks documentation against templates and project memory.
generate_contextreadThis automatically creates the context file that will be used by GENERATE-DOC for interactive documentation generation.
generate_docread3. Wait for user selection
git_workflowsreadApplies or customizes Git workflows.
paella_initread
paella_listreadRetrieves detailed information (ProjectInfo objects) for all PAELLADOC projects stored in the system memory.
paella_selectread
product_managementreadManages product management features.
templatesreadHandles the lifecycle of documentation templates.
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/paelladoc/adapters/plugins/__init__.py:21
importlib.import_module(sub_package_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/paelladoc/adapters/plugins/core/__init__.py:21
importlib.import_module(module_name)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
core_delete_project
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
legacy/rules/scripts/.menu_enforced
.menu_enforced
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
legacy/rules/core/init_memory.sh:27
PAELLADOC_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )/../../.." && pwd )"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
legacy/rules/scripts/requirements.txt
pypandoc, markdown, pyyaml
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
instructions/repopackpy-output.txt:1182
# Load environment variables
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
assets/paelladoc-demo.gif
assets/paelladoc-demo.gif
Why it matters. 7035171 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha fb1bc4409d1cfull audit observations/trust-audit/mcp-server/jlcases__paelladoc.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-03fb1bc4409d1cCAUTIONB84first audit
06

Questions

What is the PaellaDOC MCP server?

[Historical v0.x] Original MCP framework — current product at paelladoc.com

What tools does PaellaDOC expose?

16 in total: 14 read-only, 1 that write, and 1 that can delete or overwrite (core_delete_project). Every one is listed on this page with its risk.

Is PaellaDOC safe to connect to an agent?

With care. The audit graded it B (84/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does PaellaDOC need?

No credential environment variables were found in its source, so it appears to need none.

How does PaellaDOC run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as paelladoc.

How current is this page?

The grade is for one exact copy of the source (fb1bc4409d1c), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement