Atlas / MCP servers / khromov / Llmctx

LlmctxBLOCK

mcp/khromov/llmctx

Svelte developer documentation as an MCP and in llms.txt format

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
2 2r · 0w · 0d
Transport
sse · streamable-http
License
MIT
Stars
158
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

svelte-llm

LLM presets and MCP for Svelte 5 and SvelteKit. Visit the site at svelte-llm.stanislav.garden.

MCP Endpoint

This service provides an MCP (Model Context Protocol) endpoint for use with AI assistants:

  • Streamable HTTP (Claude Desktop and most other clients): https://svelte-llm.stanislav.garden/mcp/mcp
  • SSE (Older clients that don't support Streamable): https://svelte-llm.stanislav.garden/mcp/sse
  • Create a .env file with the content:
GITHUB_TOKEN=
DB_URL=postgres://admin:admin@localhost:5432/db
  • Create a Classic GitHub token. It must have public_repo permissions.
  • Enter this in the .env file.
  • Run docker-compose up
  • Run:
nvm use
npm i
npm run dev
  • Run database migrations: visit http://localhost:5173/api/migrate in your browser after starting the dev server.

You can also visit http://localhost:5173/admin to see all the "hidden" endpoints (default password = "secret")

Debug MCP

NODE_TLS_REJECT_UNAUTHORIZED=0 NODE_OPTIONS="--insecure-http-parser" npx @modelcontextprotocol/inspector

http://127.0.0.1:6274

You can also use GitHub Copilot in Agent mode to try the agent locally, see .vscode/mcp.json for info on how that works.

Misc

OG image from https://dynamic-og-image-generator.vercel.app/

Read from source at commit c59a799c128cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add llmctx.com -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "llmctx.com": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
get_documentationreadRetrieves full documentation content for Svelte 5 or SvelteKit sections. Supports flexible search by title (e.g.,
list_sectionsreadLists all available Svelte 5 and SvelteKit documentation sections in a structured format. Returns sections as a list of
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (12)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
scripts/clear-db.js:6
const DB_URL = 'postgres://admin:admin@localhost:5432/db'
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/lib/server/db.ts:15
connectionString: env.DB_URL || 'postgres://admin:admin@localhost:5432/db',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:17
DB_URL=postgres://admin:admin@localhost:5432/db
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
sse,streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cocoignore
.cocoignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/routes/api/migrate/+server.ts:25
const migrationsPath = dev ? `${__dirname}/../../../../migrations` : '/app/migrations'
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:40
http://127.0.0.1:6274
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @octokit/rest, @sveltejs/adapter-node, @sveltejs/kit, @sveltejs/vite-plugin-svelte, @testing-library/jest-dom, @testing-library/svelte, @types/eslint
Why it matters. 33 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CLAUDE.md:117
- `CONTENT_SYNC_SECRET_KEY` - Secret key for content sync endpoint
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
mcp-publisher
mcp-publisher
Why it matters. 5863890 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:42
- Visit `/admin` - Access admin panel (default password: "secret")
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c59a799c128cfull audit observations/trust-audit/mcp-server/khromov__llmctx.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c59a799c128cBLOCKD69first audit
06

Questions

What is the Llmctx MCP server?

Svelte developer documentation as an MCP and in llms.txt format

What tools does Llmctx expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Llmctx safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Llmctx need?

No credential environment variables were found in its source, so it appears to need none.

How does Llmctx run?

It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as llmctx.com at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (c59a799c128c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement