Atlas / MCP servers / lanes-sh / link

linkCAUTION

mcp/lanes-sh/link

Lanes Link is a private, self-hostable MCP that connects your accounts, memory and skills to every AI agent you use.

Verdict
CAUTION
Grade
F
Trust score
38 /100
Exposed tools
125 107r · 10w · 8d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@lanes-sh/link) [](LICENSE) [](https://github.com/lanes-sh/link/actions/workflows/ci.yml)

One endpoint you own, holding everything your agents need to know you: connections, memory, tasks, files, contacts, and secrets.

Connect your mail, calendar, files and notes once. Every agent you use, Claude, ChatGPT, and anything else that speaks MCP, reaches all of it through that one endpoint. Change your AI and you keep your context, because none of it ever lived in the agent.

Quickstart

Needs Bun 1.3.11+ and a Lanes sign-in.

$ bun install -g @lanes-sh/link
$ lanes auth login
$ lanes link profile add personal
$ lanes link start
ok    serving http://127.0.0.1:7337/mcp
profiles: personal

Leave that running. In a second shell, point every agent you have installed at it:

$ lanes link mcp add
ok    registered lanes-link with Claude Code (user scope)
ok    registered lanes-link with Codex

Your memory, tasks, files, skills, entities and vault work now, with nothing to authorise. Mail and calendar are the next step: lanes link connect gmail.

[Full quickstart](https://lanes.sh/docs/link/quickstart)

Why

  • Connect once, use everywhere. No per-agent integrations, no re-authorising every new tool.
  • You decide what agents can touch. Permi
Read from source at commit 0bff5f253acbOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add link -- npx -y @lanes-sh/[email protected]
claude-desktop
{
  "mcpServers": {
    "link": {
      "command": "npx",
      "args": [
        "-y",
        "@lanes-sh/[email protected]"
      ]
    }
  }
}
03

Exposed tools (125)

107 read · 10 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AirtablereadBases, tables, records, fields, and schema, via Airtable\
AlgoliareadSearch indices, records, queries, and synonyms, via Algolia\
AmplitudereadEvents, charts, cohorts, and user activity, via Amplitude\
ApifyreadActors, runs, datasets, and scraped results, via Apify\
AsanareadTasks, projects, portfolios, and workspaces, via Asana\
AtlassianreadJira issues, Confluence pages, and Compass components, via Atlassian\
AttioreadRecords, lists, notes, and tasks in the CRM, via Attio\
BoxreadFiles, folders, and metadata in Box, via Box\
BuildkitereadPipelines, builds, jobs, and artifacts, via Buildkite\
CalendlyreadScheduled events, invitees, event types, and availability, via Calendly\
CanvareadDesigns, folders, brand templates, assets, and exports, via Canva\
CircleCIreadPipelines, workflows, jobs, and test results, via CircleCI\
ClickUpreadTasks, lists, spaces, docs, and time entries, via ClickUp\
ClosereadLeads, contacts, opportunities, and activities in the CRM, via Close\
ContentfulreadEntries, assets, content types, and spaces, via Contentful\
DatadogreadMetrics, logs, monitors, incidents, and dashboards, via Datadog\
DiscordwritePost announcements, read channels, and triage messages in the servers your bot has been added to, via the Discord v10 HTTP API.
DropboxreadFiles, folders, shared links, and file requests, via Dropbox\
ExpensifyreadExpenses, reports, and receipts, via Expensify\
FigmareadFiles, designs, components, and Dev Mode context, via Figma\
FirefliesreadMeeting transcripts, summaries, and action items, via Fireflies\
FlagsmithreadFeature flags, segments, and environments, via Flagsmith\
GammareadPresentations and documents, generated and read back, via Gamma\
GitHubreadRepositories, issues, pull requests, and workflow runs, via GitHub\
Gmailread
GrafanareadDashboards, datasources, queries, and alert rules, via Grafana\
HerokuwriteApps, dynos, add-ons, releases, and logs, via Heroku\
HubSpotreadCRM contacts, companies, deals, and engagements, via HubSpot\
HygraphreadContent entries, models, and schema, via Hygraph\
InsightlyreadContacts, organisations, opportunities, and projects, via Insightly\
JamreadBug reports, with their console logs, network calls, and repro steps, via Jam\
KlaviyoreadProfiles, lists, segments, campaigns, and flows, via Klaviyo\
LinearreadIssues, projects, comments, and cycles, via Linear\
MercuryreadAccounts, balances, transactions, and cards, via Mercury\
MiroreadBoards, frames, sticky notes, and shapes, via Miro\
MixpanelreadEvents, funnels, retention, and cohorts, via Mixpanel\
MuxreadVideo assets, live streams, and playback analytics, via Mux\
NavanreadTrips, bookings, and travel expenses, via Navan\
NeonreadPostgres projects, branches, SQL, and docs, via Neon\
NetlifyreadSites, deploys, functions, and environment variables, via Netlify\
NotionreadPages, databases, comments, and workspace search, via Notion\
OneDrivereadBrowse, search, read, and organise files in OneDrive, via Microsoft Graph.
PaddlereadProducts, prices, subscriptions, and transactions, via Paddle\
PayPalreadInvoices, orders, payments, subscriptions, and disputes, via PayPal\
PostHogreadEvents, insights, feature flags, and session replays, via PostHog\
PrismareadPostgres databases, schema, and migrations, via Prisma\
RampreadCards, transactions, reimbursements, and spend limits, via Ramp\
RecurlyreadSubscriptions, invoices, and accounts, via Recurly\
RedditwriteRead subreddits, posts, comments, and search, and post, comment, vote, and edit as your account, via the Reddit API.
RemotereadEmployees, contracts, payroll, and time off, via Remote\
RenderreadServices, deploys, logs, and environment variables, via Render\
ReplicatereadModels, predictions, and deployments, via Replicate\
ResendreadTransactional email, domains, and delivery events, via Resend\
RiversidereadRecordings, transcripts, and clips, via Riverside\
RootlyreadIncidents, alerts, retrospectives, and on-call schedules, via Rootly\
RudderStackreadSources, destinations, and event streams, via RudderStack\
SalesloftreadCadences, people, and sales activity, via Salesloft\
SanityreadDocuments, datasets, schema, and content releases, via Sanity\
SentryreadIssues, events, stack traces, and releases, via Sentry\
Sharedread
ShortcutreadStories, epics, iterations, and workflows, via Shortcut\
SlackreadMessages, threads, channels, files, and canvases, via Slack\
SquarereadPayments, orders, catalog, inventory, and customers, via Square\
StoryblokreadStories, components, assets, and spaces, via Storyblok\
StripereadPayments, customers, invoices, subscriptions, and balances, via Stripe\
SupabasereadProjects, database schema, SQL, edge functions, and docs, via Supabase\
TavilyreadWeb search and page content extraction, via Tavily\
TodoistreadTasks, projects, sections, labels, and filters, via Todoist\
VercelreadProjects, deployments, build logs, and domains, via Vercel\
VimeoreadVideos, folders, showcases, and analytics, via Vimeo\
WebflowreadSites, pages, CMS collections, and items, via Webflow\
WhimsicalreadBoards, flowcharts, wireframes, and mind maps, via Whimsical\
WixreadSites, stores, bookings, and CMS data, via Wix\
WorkablereadJobs, candidates, and interviews, via Workable\
ZapierreadZaps, and the actions they reach across thousands of apps, via Zapier\
addwriteRecord something to be done. This is where
authordestructiveRead, create, and delete the skills themselves.
boomreadalways throws
bunqreadBank accounts, balances, transaction history, and payments — including batches and drafts that wait for approval in the bunq app.
composereadSomething the vendor document cannot describe.
delete_notedestructiveRemove a note from this connection.
diffreadThe unified diff
docreada document
echoreadecho
entityreadOne declared entity, addressed by its id.
entryreadOne stored memory entry, addressed by its id.
filereadOne stored file, addressed by its name. Text comes back as text; anything else is described rather than encoded.
findreadFind entities by name, alias, address, type, tag, attribute or relationship. All criteria
forgetdestructiveDelete an entity. Edges pointing at it from other entities are left alone and are reported,
getreadReturn a text file\
get_notereadread a note
grant_policyreadwiden my own permissions
linkwriteAdd one edge to an entity, leaving everything else on it alone. The edge is written only on
listreadEvery file kept in this profile, newest first, with its type and size. This is the whole index — an asset carries no description, so what a file is for belongs in memory.
list_notesreadList the keys of every note stored against this connection.
list_thingsreadFrom the document.
manage.getwriteReturn a skill exactly as stored, frontmatter included — what to edit before writing it back.
manage.listreadEvery skill that exists, with its description and arguments. The prompt list shows only the ones policy permits; this shows what is stored.
manage.removedestructiveRemove a skill and the prompt it provided.
manage.writewriteCreate or replace a skill. The text is a whole Markdown document: YAML frontmatter carrying
monday.comreadBoards, items, groups, columns, and updates, via monday.com\
notereadA stored note, addressed by key.
notes.getreadOne note, by identifier.
notes.listreadIdentifiers of the notes in this account, and a token for the next page.
overviewreadList the accounts reachable in this profile and the providers that could be connected.
procedurereada reusable procedure
providerreadThe console steps, the values needed, and the exact command that connects it.
purgedestructivedestructive
putwriteStore or replace a secret under an id. The item becomes readable only after the endpoint restarts, and only if policy grants
readreadList and read stored files.
removedestructiveRemove a file and its bytes. There is no trash.
review-diffreadReview a diff for correctness
round_tripreadstage a file and name it back
searchreadFind entries whose title, tags, or body contain the query. Case-insensitive substring matching, not ranked relevance.
set_notewritestore a note
stagereadHold a file for a later call, anywhere in this profile. Name one source — data for a file
storereadKeep a file in this profile, permanently and by name. Name exactly one source — path, url, handle, asset, or data — and the endpoint reads the bytes itself. Storing under a name that exists replaces it. A stored file attaches to anything afterwards as {
stylereadstyle
subjectreadwhat about
taskreadOne task, addressed by its id.
unboundedreada resource space too large to enumerate
updatewriteChange a task in place — most often its status. Marking something done is an update, not a delete: the record of having done it is the useful part. Omitted fields are left as they are.
users.drafts.deletedestructive
users.messages.listread
writedestructiveStore and delete files.
04

Trust audit

CAUTIONgrade F · trust 38/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (2 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/knowledge/index.ts:237
print(style.dim(`  The token at "${knowledge.token_ref}" is no longer used; remove it if you like.`));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/operate/outputs.ts:97
print(`  ${token}  ${style.dim(`(${held?.id})`)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/operate/outputs.ts:123
print(style.dim(`      lanes link token issue --me --workspace ${runtime.target}`));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/operate/pair.ts:258
print(pairingLink(token, address));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/operate/pair.ts:345
print(pairingLink(token, endpoint));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/lanes-writing/SKILL.md:164
ok  serving http://127.0.0.1:7337/mcp
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/providers/shared/frontmatter.ts:118
return text.replace(/^/, '');
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/providers/bunq/strategy/strategy.test.ts:56
api_key: 'api-key-from-the-app',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/providers/bunq/strategy/strategy.test.ts:298
JSON.stringify({ token: 'from-another-instance', createdAt: Date.now() }),
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/server/attachments.test.ts:36
token: 'llk_work_token_value',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/server/attachments.test.ts:173
token: 'llk_work_token_value',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/server/attachments.test.ts:255
token: 'llk_work_token_value',
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/profile/identity.test.ts:140
parseConfig(withIdentity('  - { kind: github, value: ghp_000000000000000000000000000000000000 }\n')),
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/profile/load.test.ts:105
['ghp_16C7e42F292c6912E7710c838347Ae178B4a', 'a GitHub token'],
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/profile/load.test.ts:563
'knowledge: { adapter: github, repo: my-org/my-notes, token_ref: github_pat_11ABCDE0Y0abcdefghijkl_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789abcdefghijklmno }',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/cli/commands/connect/assertion.test.ts:28
private_key: '-----BEGIN PRIVATE KEY-----\nMIIB\n-----END PRIVATE KEY-----\n',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/profile/load.test.ts:95
-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/providers/bunq/strategy/keys.test.ts:9
expect(keys.privateKey).toStartWith('-----BEGIN PRIVATE KEY-----');
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/providers/bunq/strategy/strategy.test.ts:180
expect(stored.private_key).toStartWith('-----BEGIN PRIVATE KEY-----');
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/server/read/listener.test.ts:50
const keyStart = out.indexOf('-----BEGIN PRIVATE KEY-----');
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
src/profile/load.test.ts:104
['xoxb-2401234567-abcDEF123456', 'a Slack bot token'],
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
author, delete_note, forget, manage.remove, purge, remove, users.drafts.delete, write
Why it matters. 8 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.bun-version
.bun-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gcloudignore
.gcloudignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/deployments/grants.test.ts:180
return new Function('resource', `return ${condition};`)({ name }) === true;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0bff5f253acbfull audit observations/trust-audit/mcp-server/lanes-sh__link.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080bff5f253acbCAUTIONF38first audit
06

Questions

What is the link MCP server?

Lanes Link is a private, self-hostable MCP that connects your accounts, memory and skills to every AI agent you use.

What tools does link expose?

125 in total: 107 read-only, 10 that write, and 8 that can delete or overwrite (author, delete_note, forget, manage.remove, purge). Every one is listed on this page with its risk.

Is link safe to connect to an agent?

With care. The audit graded it F (38/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does link need?

No credential environment variables were found in its source, so it appears to need none.

How does link run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @lanes-sh/link at 0.16.1.

How current is this page?

The grade is for one exact copy of the source (0bff5f253acb), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement