StashBaseCAUTION
An open-source, local-first writing workspace where you can write with Claude Code and Codex, drawing on your own sources and past work.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Like an IDE, but for writing.
[](https://stashbase.ai) [](https://github.com/liliu-z/stashbase/releases/latest) [](LICENSE) [](https://discord.gg/zsRZH4PTq9)
StashBase is an open-source, local-first writing workspace where you can write with Claude and Codex, drawing on your own sources and past work.
- 🔎 From files to context. Give your agent fast, accurate search across your
sources with text extraction and semantic search.
- 📝 Doc diff ≠ Code diff. Read edits in the flow of your document, without
jumping between old and new lines.
- ✍️ Make it sound like you. Use your past writing and edits to guide new
drafts and preserve your voice.
Product Preview
https://github.com/user-attachments/assets/4ba282a3-85d2-4a08-b7af-562a1e71e716
Document Diff
Review suggested edits directly in the document as you read it. Paragraphs and formatting stay in place, deleted words and phrases are struck through in red, and additions are highlighted in green. Revisions appear within the surrounding prose rather than as a line-by-line code patch.
Accept or reject individual changes, or use Accept All and Reject All to take the whole set. Rejecting everything leaves the file exactly as it was. Ask your Agent to revise an open Markdown document and it proposes rather than overwrites, so nothing reaches the file until you accept a change.
Agent file diffs and editor save-conflict comparisons are separate features and still work the way they did.
Get Started
macOS 12+ (Apple Silicon and Intel) and Windows 10+ (x64) are the primary platforms. Linux x86_64 Debian 12+ / Ubuntu 22.04+ is
00063de50f75OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add renderer --env GH_TOKEN=${GH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env HOMEBREW_GITHUB_API_TOKEN=${HOMEBREW_GITHUB_API_TOKEN} --env STASHBASE_OAUTH_RETURN_TOKEN=${STASHBASE_OAUTH_RETURN_TOKEN} -- npx -y @stashbase/[email protected]{
"mcpServers": {
"renderer": {
"command": "npx",
"args": [
"-y",
"@stashbase/[email protected]"
],
"env": {
"GH_TOKEN": "${GH_TOKEN}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}",
"HOMEBREW_GITHUB_API_TOKEN": "${HOMEBREW_GITHUB_API_TOKEN}",
"STASHBASE_OAUTH_RETURN_TOKEN": "${STASHBASE_OAUTH_RETURN_TOKEN}"
}
}
}
}Exposed tools (12)
6 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_project | write | Create a NEW project folder and register it in StashBase so it |
delete_file | destructive | Delete a visible file by absolute path. Also removes note bundles or |
edit_file | write | Patch a Markdown, HTML, JSON, or UTF-8 plain-text file by exact string replacement. By default |
list_directory | read | List visible files and folders within one registered project. Pass an absolute folder/subfolder path to |
list_projects | read | Return StashBase project locations as |
move_file | write | Rename or move a file within the same folder. Keeps note attachment bundles together, |
read_file | read | Read a file from StashBase by absolute path |
reindex | read | Reconcile search data with the files currently on disk, then report |
release-notes | read | Prepare release notes |
search_project | read | Search one registered project, including current prepared text for PDFs, DOCX, and images. |
suggest_edits | write | Propose a revision to a Markdown file without writing it. Send the whole revised document, |
write_file | destructive | Create or overwrite a Markdown, HTML, JSON, or UTF-8 plain-text file. Creates parent folders as |
Trust audit
CAUTIONgrade D · trust 67/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
icon.icns
'UEsDBBQAAAAIAKaK8VzXeYTq8QAAALgBAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbH2QzU7DMBCE730Ky9cqccoBIZSkB36OwKE8wMreJFb9J69b2rdn00KREOVozXwz62nXB+/EHjPZGDq5qhspMOhobBg7+b55ru6koALBgIsBO3lEkut+0W6OCUkwHKiTUynpXin
.replace(/[ ]/g, ' ')
token: 'sbk_9f3c1d7a4e05b28c617d',
rotateToken: async () => ({ ...http, token: 'sbk_2b80e64af19c37d5ac0e' }),const secret = 'fixture-private-password';
const password = 'packaged-smoke-secret';
'ghp_abcdefghijklmnopqrstuvwxyz123456',
delete_file, write_file
.oxlintrc.json
.jscpd.json
} = require('../../dist/electron/bug-report/review-ipc.cjs');} from '../../shared/protocols/electron/bug-report-review.ts';
} = require('../../dist/electron/bug-report/review-preload.cjs');} from '../../shared/protocols/electron/bug-report-review.ts';
} = require('../../dist/electron/external-navigation/handler.cjs');Same-machine access uses `http://127.0.0.1:8090/mcp` and stays on loopback.
serverOrigin: 'http://127.0.0.1:8090',
assert.equal(csp, productionContentSecurityPolicy('http://127.0.0.1:8090'));'frame-src http://127.0.0.1:8090/asset/ http://127.0.0.1:8090/asset-derived/',
"img-src 'self' data: blob: http://127.0.0.1:8090/api/gallery/image",
@anthropic-ai/claude-agent-sdk, @modelcontextprotocol/sdk, @noble/hashes, better-sqlite3, electron-updater, express, mammoth, multer
openai, numpy, blake3
@base-ui/react, @codemirror/commands, @codemirror/lang-json, @codemirror/language, @codemirror/language-data, @codemirror/merge, @codemirror/state, @codemirror/view
| [Account and settings](../design-docs/capabilities/account-settings.md) | Node owns persistent settings, account state, and external credentials; renderer owns scoped interaction. See [credentials a
Gates applied: no_behavioural_pass.
00063de50f75full audit observations/trust-audit/mcp-server/liliu-z__stashbase.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 00063de50f75 | CAUTION | D | 67 | first audit |
Questions
What is the StashBase MCP server?
An open-source, local-first writing workspace where you can write with Claude Code and Codex, drawing on your own sources and past work.
What tools does StashBase expose?
12 in total: 6 read-only, 4 that write, and 2 that can delete or overwrite (delete_file, write_file). Every one is listed on this page with its risk.
Is StashBase safe to connect to an agent?
With care. The audit graded it D (67/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does StashBase need?
It reads GH_TOKEN, GITHUB_TOKEN, HOMEBREW_GITHUB_API_TOKEN, STASHBASE_OAUTH_RETURN_TOKEN and STASHBASE_SHUTDOWN_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does StashBase run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @stashbase/renderer at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (00063de50f75), read on 2026-10-06. The repository is watched and re-audited when it changes.