linkCAUTION
Lanes Link is a private, self-hostable MCP that connects your accounts, memory and skills to every AI agent you use.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@lanes-sh/link) [](LICENSE) [](https://github.com/lanes-sh/link/actions/workflows/ci.yml)
One endpoint you own, holding everything your agents need to know you: connections, memory, tasks, files, contacts, and secrets.
Connect your mail, calendar, files and notes once. Every agent you use, Claude, ChatGPT, and anything else that speaks MCP, reaches all of it through that one endpoint. Change your AI and you keep your context, because none of it ever lived in the agent.
Quickstart
Needs Bun 1.3.11+ and a Lanes sign-in.
$ bun install -g @lanes-sh/link $ lanes auth login $ lanes link profile add personal $ lanes link start ok serving http://127.0.0.1:7337/mcp profiles: personal
Leave that running. In a second shell, point every agent you have installed at it:
$ lanes link mcp add ok registered lanes-link with Claude Code (user scope) ok registered lanes-link with Codex
Your memory, tasks, files, skills, entities and vault work now, with nothing to authorise. Mail and calendar are the next step: lanes link connect gmail.
[Full quickstart](https://lanes.sh/docs/link/quickstart)
Why
- Connect once, use everywhere. No per-agent integrations, no re-authorising every new tool.
- You decide what agents can touch. Permi
0bff5f253acbOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add link -- npx -y @lanes-sh/[email protected]
{
"mcpServers": {
"link": {
"command": "npx",
"args": [
"-y",
"@lanes-sh/[email protected]"
]
}
}
}Exposed tools (125)
107 read · 10 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Airtable | read | Bases, tables, records, fields, and schema, via Airtable\ |
Algolia | read | Search indices, records, queries, and synonyms, via Algolia\ |
Amplitude | read | Events, charts, cohorts, and user activity, via Amplitude\ |
Apify | read | Actors, runs, datasets, and scraped results, via Apify\ |
Asana | read | Tasks, projects, portfolios, and workspaces, via Asana\ |
Atlassian | read | Jira issues, Confluence pages, and Compass components, via Atlassian\ |
Attio | read | Records, lists, notes, and tasks in the CRM, via Attio\ |
Box | read | Files, folders, and metadata in Box, via Box\ |
Buildkite | read | Pipelines, builds, jobs, and artifacts, via Buildkite\ |
Calendly | read | Scheduled events, invitees, event types, and availability, via Calendly\ |
Canva | read | Designs, folders, brand templates, assets, and exports, via Canva\ |
CircleCI | read | Pipelines, workflows, jobs, and test results, via CircleCI\ |
ClickUp | read | Tasks, lists, spaces, docs, and time entries, via ClickUp\ |
Close | read | Leads, contacts, opportunities, and activities in the CRM, via Close\ |
Contentful | read | Entries, assets, content types, and spaces, via Contentful\ |
Datadog | read | Metrics, logs, monitors, incidents, and dashboards, via Datadog\ |
Discord | write | Post announcements, read channels, and triage messages in the servers your bot has been added to, via the Discord v10 HTTP API. |
Dropbox | read | Files, folders, shared links, and file requests, via Dropbox\ |
Expensify | read | Expenses, reports, and receipts, via Expensify\ |
Figma | read | Files, designs, components, and Dev Mode context, via Figma\ |
Fireflies | read | Meeting transcripts, summaries, and action items, via Fireflies\ |
Flagsmith | read | Feature flags, segments, and environments, via Flagsmith\ |
Gamma | read | Presentations and documents, generated and read back, via Gamma\ |
GitHub | read | Repositories, issues, pull requests, and workflow runs, via GitHub\ |
Gmail | read | |
Grafana | read | Dashboards, datasources, queries, and alert rules, via Grafana\ |
Heroku | write | Apps, dynos, add-ons, releases, and logs, via Heroku\ |
HubSpot | read | CRM contacts, companies, deals, and engagements, via HubSpot\ |
Hygraph | read | Content entries, models, and schema, via Hygraph\ |
Insightly | read | Contacts, organisations, opportunities, and projects, via Insightly\ |
Jam | read | Bug reports, with their console logs, network calls, and repro steps, via Jam\ |
Klaviyo | read | Profiles, lists, segments, campaigns, and flows, via Klaviyo\ |
Linear | read | Issues, projects, comments, and cycles, via Linear\ |
Mercury | read | Accounts, balances, transactions, and cards, via Mercury\ |
Miro | read | Boards, frames, sticky notes, and shapes, via Miro\ |
Mixpanel | read | Events, funnels, retention, and cohorts, via Mixpanel\ |
Mux | read | Video assets, live streams, and playback analytics, via Mux\ |
Navan | read | Trips, bookings, and travel expenses, via Navan\ |
Neon | read | Postgres projects, branches, SQL, and docs, via Neon\ |
Netlify | read | Sites, deploys, functions, and environment variables, via Netlify\ |
Notion | read | Pages, databases, comments, and workspace search, via Notion\ |
OneDrive | read | Browse, search, read, and organise files in OneDrive, via Microsoft Graph. |
Paddle | read | Products, prices, subscriptions, and transactions, via Paddle\ |
PayPal | read | Invoices, orders, payments, subscriptions, and disputes, via PayPal\ |
PostHog | read | Events, insights, feature flags, and session replays, via PostHog\ |
Prisma | read | Postgres databases, schema, and migrations, via Prisma\ |
Ramp | read | Cards, transactions, reimbursements, and spend limits, via Ramp\ |
Recurly | read | Subscriptions, invoices, and accounts, via Recurly\ |
Reddit | write | Read subreddits, posts, comments, and search, and post, comment, vote, and edit as your account, via the Reddit API. |
Remote | read | Employees, contracts, payroll, and time off, via Remote\ |
Render | read | Services, deploys, logs, and environment variables, via Render\ |
Replicate | read | Models, predictions, and deployments, via Replicate\ |
Resend | read | Transactional email, domains, and delivery events, via Resend\ |
Riverside | read | Recordings, transcripts, and clips, via Riverside\ |
Rootly | read | Incidents, alerts, retrospectives, and on-call schedules, via Rootly\ |
RudderStack | read | Sources, destinations, and event streams, via RudderStack\ |
Salesloft | read | Cadences, people, and sales activity, via Salesloft\ |
Sanity | read | Documents, datasets, schema, and content releases, via Sanity\ |
Sentry | read | Issues, events, stack traces, and releases, via Sentry\ |
Shared | read | |
Shortcut | read | Stories, epics, iterations, and workflows, via Shortcut\ |
Slack | read | Messages, threads, channels, files, and canvases, via Slack\ |
Square | read | Payments, orders, catalog, inventory, and customers, via Square\ |
Storyblok | read | Stories, components, assets, and spaces, via Storyblok\ |
Stripe | read | Payments, customers, invoices, subscriptions, and balances, via Stripe\ |
Supabase | read | Projects, database schema, SQL, edge functions, and docs, via Supabase\ |
Tavily | read | Web search and page content extraction, via Tavily\ |
Todoist | read | Tasks, projects, sections, labels, and filters, via Todoist\ |
Vercel | read | Projects, deployments, build logs, and domains, via Vercel\ |
Vimeo | read | Videos, folders, showcases, and analytics, via Vimeo\ |
Webflow | read | Sites, pages, CMS collections, and items, via Webflow\ |
Whimsical | read | Boards, flowcharts, wireframes, and mind maps, via Whimsical\ |
Wix | read | Sites, stores, bookings, and CMS data, via Wix\ |
Workable | read | Jobs, candidates, and interviews, via Workable\ |
Zapier | read | Zaps, and the actions they reach across thousands of apps, via Zapier\ |
add | write | Record something to be done. This is where |
author | destructive | Read, create, and delete the skills themselves. |
boom | read | always throws |
bunq | read | Bank accounts, balances, transaction history, and payments — including batches and drafts that wait for approval in the bunq app. |
compose | read | Something the vendor document cannot describe. |
delete_note | destructive | Remove a note from this connection. |
diff | read | The unified diff |
doc | read | a document |
echo | read | echo |
entity | read | One declared entity, addressed by its id. |
entry | read | One stored memory entry, addressed by its id. |
file | read | One stored file, addressed by its name. Text comes back as text; anything else is described rather than encoded. |
find | read | Find entities by name, alias, address, type, tag, attribute or relationship. All criteria |
forget | destructive | Delete an entity. Edges pointing at it from other entities are left alone and are reported, |
get | read | Return a text file\ |
get_note | read | read a note |
grant_policy | read | widen my own permissions |
link | write | Add one edge to an entity, leaving everything else on it alone. The edge is written only on |
list | read | Every file kept in this profile, newest first, with its type and size. This is the whole index — an asset carries no description, so what a file is for belongs in memory. |
list_notes | read | List the keys of every note stored against this connection. |
list_things | read | From the document. |
manage.get | write | Return a skill exactly as stored, frontmatter included — what to edit before writing it back. |
manage.list | read | Every skill that exists, with its description and arguments. The prompt list shows only the ones policy permits; this shows what is stored. |
manage.remove | destructive | Remove a skill and the prompt it provided. |
manage.write | write | Create or replace a skill. The text is a whole Markdown document: YAML frontmatter carrying |
monday.com | read | Boards, items, groups, columns, and updates, via monday.com\ |
note | read | A stored note, addressed by key. |
notes.get | read | One note, by identifier. |
notes.list | read | Identifiers of the notes in this account, and a token for the next page. |
overview | read | List the accounts reachable in this profile and the providers that could be connected. |
procedure | read | a reusable procedure |
provider | read | The console steps, the values needed, and the exact command that connects it. |
purge | destructive | destructive |
put | write | Store or replace a secret under an id. The item becomes readable only after the endpoint restarts, and only if policy grants |
read | read | List and read stored files. |
remove | destructive | Remove a file and its bytes. There is no trash. |
review-diff | read | Review a diff for correctness |
round_trip | read | stage a file and name it back |
search | read | Find entries whose title, tags, or body contain the query. Case-insensitive substring matching, not ranked relevance. |
set_note | write | store a note |
stage | read | Hold a file for a later call, anywhere in this profile. Name one source — data for a file |
store | read | Keep a file in this profile, permanently and by name. Name exactly one source — path, url, handle, asset, or data — and the endpoint reads the bytes itself. Storing under a name that exists replaces it. A stored file attaches to anything afterwards as { |
style | read | style |
subject | read | what about |
task | read | One task, addressed by its id. |
unbounded | read | a resource space too large to enumerate |
update | write | Change a task in place — most often its status. Marking something done is an update, not a delete: the record of having done it is the useful part. Omitted fields are left as they are. |
users.drafts.delete | destructive | |
users.messages.list | read | |
write | destructive | Store and delete files. |
Trust audit
CAUTIONgrade F · trust 38/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
print(style.dim(` The token at "${knowledge.token_ref}" is no longer used; remove it if you like.`));print(` ${token} ${style.dim(`(${held?.id})`)}`);print(style.dim(` lanes link token issue --me --workspace ${runtime.target}`));print(pairingLink(token, address));
print(pairingLink(token, endpoint));
ok serving http://127.0.0.1:7337/mcp
return text.replace(/^/, '');
api_key: 'api-key-from-the-app',
JSON.stringify({ token: 'from-another-instance', createdAt: Date.now() }),token: 'llk_work_token_value',
token: 'llk_work_token_value',
token: 'llk_work_token_value',
parseConfig(withIdentity(' - { kind: github, value: ghp_000000000000000000000000000000000000 }\n')),['ghp_16C7e42F292c6912E7710c838347Ae178B4a', 'a GitHub token'],
'knowledge: { adapter: github, repo: my-org/my-notes, token_ref: github_pat_11ABCDE0Y0abcdefghijkl_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789abcdefghijklmno }',private_key: '-----BEGIN PRIVATE KEY-----\nMIIB\n-----END PRIVATE KEY-----\n',
-----BEGIN RSA PRIVATE KEY-----
expect(keys.privateKey).toStartWith('-----BEGIN PRIVATE KEY-----');expect(stored.private_key).toStartWith('-----BEGIN PRIVATE KEY-----');const keyStart = out.indexOf('-----BEGIN PRIVATE KEY-----');['xoxb-2401234567-abcDEF123456', 'a Slack bot token'],
author, delete_note, forget, manage.remove, purge, remove, users.drafts.delete, write
.bun-version
.gcloudignore
return new Function('resource', `return ${condition};`)({ name }) === true;Gates applied: no_behavioural_pass.
0bff5f253acbfull audit observations/trust-audit/mcp-server/lanes-sh__link.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0bff5f253acb | CAUTION | F | 38 | first audit |
Questions
What is the link MCP server?
Lanes Link is a private, self-hostable MCP that connects your accounts, memory and skills to every AI agent you use.
What tools does link expose?
125 in total: 107 read-only, 10 that write, and 8 that can delete or overwrite (author, delete_note, forget, manage.remove, purge). Every one is listed on this page with its risk.
Is link safe to connect to an agent?
With care. The audit graded it F (38/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does link need?
No credential environment variables were found in its source, so it appears to need none.
How does link run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @lanes-sh/link at 0.16.1.
How current is this page?
The grade is for one exact copy of the source (0bff5f253acb), read on 2026-10-08. The repository is watched and re-audited when it changes.