LightCMSCAUTION
Self-hosted CMS that works human or headless: full admin UI plus REST and MCP APIs, built-in semantic search and site chat, and content forking, versioning, diff/merge review, templates, approvals, and static page generation.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/jonradoff/lightcms/actions/workflows/ci.yml) [](https://codecov.io/gh/jonradoff/lightcms) [](https://goreportcard.com/report/github.com/jonradoff/lightcms) [](https://glama.ai/mcp/servers/jonradoff/lightcms)
LightCMS is a Go-powered content management system built for the AI era. It's simultaneously AI-native (semantic search, built-in Claude-powered chat widget, MCP server for agent control), agentically controllable (Claude Code and any MCP client can read, write, publish, and bulk-import content via 130 MCP tools), and agentically updatable (the codebase is clean, well-structured Go — coding agents can safely extend it). For teams that want a CMS that works with AI rather than around it.
What's New in v7.3 — SEO & AI
df62bd4fa0a2OBSERVED · 2026-10-08Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (22)
const token = "cf-secret-token-0123456789"
{Token: "cohere-training-data-crawler", Vendor: "Cohere", Purpose: CrawlerPurposeTraining, UAMatch: "cohere-training-data-crawler"},{Token: "Meta-ExternalFetcher", Vendor: "Meta", Purpose: CrawlerPurposeUserFetch, UAMatch: "meta-externalfetcher"},.goreleaser.yaml
src, err := os.ReadFile("../../cmd/server/main.go")src, err := os.ReadFile("../../cmd/server/main.go"){"directory traversal", "../../../etc/passwd"},{"embedded traversal", "/images/../../secret"},_, err := svc.UploadAsset(ctx, pngData, "test.png", "/../../../etc/test.png", "")
Data: map[string]interface{}{"body": `<a href="` + internal.URL + `/admin">a</a> <a href="http://169.254.169.254/latest/meta-data/">b</a>`}})if !strings.Contains(body, internal.URL+"/admin") || !strings.Contains(body, "169.254.169.254") || !strings.Contains(body, `"totalBrokenLinks": 2`) {Data: map[string]interface{}{"body": `<a href="` + internal.URL + `/admin">a</a> <a href="http://169.254.169.254/latest/meta-data/">b</a>`}})if _, err := ParseFeed(context.Background(), "http://127.0.0.1:0/nope"); err == nil {if _, err := ws.Create(ctx, "hook", "https://127.0.0.1:0/unreachable", "secret", []string{"content.published"}, true); err != nil {- Keys created before v2.0 remain functional as system-level keys with full access
- **admin**: Full access — manage users, templates, settings, audit logs, all API keys
| **admin** | Full access: manage users, templates, theme, settings, audit log, all API keys |
- **`Strict-Transport-Security` follows server configuration** (secure cookies and an `https://` base URL) instead of the `X-Forwarded-Proto` request header, which any client can send.
- **Admin forms work over plain HTTP in local development.** With `secure_cookies: false`, every admin POST on `http://localhost` failed with "Invalid or missing CSRF token" because the CSRF library a
- **Agent governance**: API keys accept a `scopes` permission allowlist and a `sandbox_only` flag (server-enforced fork-only writes). Every MCP session gets an agent-session ID; `GET /api/v1/agent-ses
5. Visit http://localhost:8082/cm and log in with your email and password
Gates applied: no_behavioural_pass.
df62bd4fa0a2full audit observations/trust-audit/mcp-server/jonradoff__lightcms.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | df62bd4fa0a2 | CAUTION | C | 75 | first audit |
Questions
What is the LightCMS MCP server?
Self-hosted CMS that works human or headless: full admin UI plus REST and MCP APIs, built-in semantic search and site chat, and content forking, versioning, diff/merge review, templates, approvals, and static page generation.
Is LightCMS safe to connect to an agent?
With care. The audit graded it C (75/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does LightCMS need?
It reads LIGHTCMS_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does LightCMS run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (df62bd4fa0a2), read on 2026-10-08. The repository is watched and re-audited when it changes.