PaellaDOCCAUTION
[Historical v0.x] Original MCP framework — current product at paelladoc.com
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⚠️ Historical — preserved for reference This repository is PaellaDoc v0.x (340+ ⭐, 2024–2025), the original MCP-based framework. The current product is a desktop orchestrator at [paelladoc.com](https://paelladoc.com) with native Claude Code, Codex and Gemini integration, Playwright-verified Golden Gate, and a community at [forum.paelladoc.com](https://forum.paelladoc.com). This repo is preserved as historical reference and is no longer actively maintained.
[Visit the Official Website](https://paelladoc.com)
Perfect AI development, like perfect paella: quality ingredients, structure, and expertise.
⭐ If you find PAELLADOC useful, please consider starring the repo! ⭐ </ =======
[](https://github.com/jlcases/paelladoc) [](https://x.com/i/communities/1907494161458090406) [](https://discord.gg/grKF8EaB)
Version 0.3.7: Hotfix release restoring core project CRUD tools inadvertently omitted in v0.3.6 build. Check the CHANGELOG for details!
"In the AI era, context isn't supplementary to code—it's the primary creation."
PAELLADOC is an AI-First Development framework that implements the [5 Philosophical Principles of AI
fb1bc4409d1cOBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add paelladoc -- uvx paelladoc
{
"mcpServers": {
"paelladoc": {
"command": "uvx",
"args": [
"paelladoc"
]
}
}
}Exposed tools (16)
14 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
code_generation | read | The command uses the script at `.cursor/rules/scripts/extract_repo_content.py` to perform the repository extraction, which leverages repopack-py to convert the codebase to text. |
coding_styles | read | Applies, customizes, or lists coding styles. |
core_continue | read | Loads an existing project |
core_delete_project | destructive | Delete a project and optionally its files. |
core_get_project | read | Get detailed information about a specific project. |
core_help | read | Provides help information about available PAELLADOC commands. |
core_update_project | write | Update specific fields of a project. |
core_verification | read | Checks documentation against templates and project memory. |
generate_context | read | This automatically creates the context file that will be used by GENERATE-DOC for interactive documentation generation. |
generate_doc | read | 3. Wait for user selection |
git_workflows | read | Applies or customizes Git workflows. |
paella_init | read | |
paella_list | read | Retrieves detailed information (ProjectInfo objects) for all PAELLADOC projects stored in the system memory. |
paella_select | read | |
product_management | read | Manages product management features. |
templates | read | Handles the lifecycle of documentation templates. |
Trust audit
CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- none-observed
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
importlib.import_module(sub_package_name)
importlib.import_module(module_name)
core_delete_project
.pre-commit-config.yaml
.menu_enforced
PAELLADOC_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )/../../.." && pwd )"pypandoc, markdown, pyyaml
# Load environment variables
assets/paelladoc-demo.gif
Gates applied: no_behavioural_pass.
fb1bc4409d1cfull audit observations/trust-audit/mcp-server/jlcases__paelladoc.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | fb1bc4409d1c | CAUTION | B | 84 | first audit |
Questions
What is the PaellaDOC MCP server?
[Historical v0.x] Original MCP framework — current product at paelladoc.com
What tools does PaellaDOC expose?
16 in total: 14 read-only, 1 that write, and 1 that can delete or overwrite (core_delete_project). Every one is listed on this page with its risk.
Is PaellaDOC safe to connect to an agent?
With care. The audit graded it B (84/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does PaellaDOC need?
No credential environment variables were found in its source, so it appears to need none.
How does PaellaDOC run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as paelladoc.
How current is this page?
The grade is for one exact copy of the source (fb1bc4409d1c), read on 2026-10-03. The repository is watched and re-audited when it changes.