McpdocSAFE
Expose llms-txt to IDEs for development
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Overview
llms.txt is a website index for LLMs, providing background information, guidance, and links to detailed markdown files. IDEs like Cursor and Windsurf or apps like Claude Code/Desktop can use llms.txt to retrieve context for tasks. However, these apps use different built-in tools to read and process files like llms.txt. The retrieval process can be opaque, and there is not always a way to audit the tool calls or the context returned.
MCP offers a way for developers to have full control over tools used by these applications. Here, we create an open source MCP server to provide MCP host applications (e.g., Cursor, Windsurf, Claude Code/Desktop) with (1) a user-defined list of llms.txt files and (2) a simple fetch_docs tool read URLs within any of the provided llms.txt files. This allows the user to audit each tool call as well as the context returned.
llms-txt
You can find llms.txt files for langgraph and langchain here:
#
19600cd52939OBSERVED · 2026-09-26Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcpdoc -- uvx mcpdoc
{
"mcpServers": {
"mcpdoc": {
"command": "uvx",
"args": [
"mcpdoc"
]
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
fetch_docs | read | nonlocal domains, follow_redirects |
get_docs | read | Get langgraph docs. |
list_doc_sources | read | List all available documentation sources. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
* In a terminal after installing [Claude Code](https://docs.anthropic.com/en/docs/agents-and-tools/claude-code/overview), run this command to add the MCP server to your project:
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
19600cd52939full audit observations/trust-audit/mcp-server/langchain-ai__mcpdoc-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | 19600cd52939 | SAFE | B | 89 | first audit |
Questions
What is the Mcpdoc MCP server?
Expose llms-txt to IDEs for development
What tools does Mcpdoc expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcpdoc safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mcpdoc need?
No credential environment variables were found in its source, so it appears to need none.
How does Mcpdoc run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcpdoc.
How current is this page?
The grade is for one exact copy of the source (19600cd52939), read on 2026-09-26. The repository is watched and re-audited when it changes.