Atlas / MCP servers / linofcp007 / juridico-pt

juridico-ptBLOCK

mcp/linofcp007/juridico-pt

Advogado pessoal e empresarial em Portugal — plugin Claude Code + servidor MCP (referencias, templates, playbooks, checklists e calculadoras juridicas). PT/EN.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
38 38r · 0w · 0d
Transport
stdio
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Skill personalizada para o Claude atuar como assistente jurídico pessoal e empresarial em Portugal (não substitui advogado inscrito na Ordem dos Advogados) — para qualquer empresa (ENI, Unipessoal Lda, Lda, SA; qualquer setor e dimensão) e para particulares, adaptando-se ao perfil da empresa guardado no projeto.

Disponível em todas as IAs

Além da Skill para Claude, o Jurídico PT corre como servidor MCP (mcp-server/), ligando-se a Cursor, Windsurf, Codex, Gemini CLI e ChatGPT/OpenAI — além de Claude. Um servidor único expõe as calculadoras (tools), as referências/templates (resources) e a persona (prompt). Guia completo em INSTALL.md; configs por plataforma em integrations/.

{ "mcpServers": { "juridico-pt": { "command": "node", "args": ["/CAMINHO/ABSOLUTO/juridico-pt/mcp-server/dist/index.js"] } } }

Instalação

Há três formas de o usar no Claude. Escolhe pela app onde trabalhas:

Read from source at commit ac37667ba466OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add juridico-pt -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "juridico-pt": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (38)

38 read · 0 write · 0 destructive.

ToolRiskDescription
apagar_perfilread
ativar_perfilread
calc_compensacao_despedimentoread
calc_creditos_laboraisread
calc_custas_injuncaoread
calc_custo_trabalhadorread
calc_imposto_selo_herancaread
calc_imtread
calc_ircread
calc_irs_simplificadoread
calc_iva_operacaoread
calc_juros_loteread
calc_juros_moraread
calc_legitimaread
calc_prazoread
calc_prescricaoread
calc_procedimento_ccpread
calc_salario_liquidoread
calc_taxa_justicaread
calendario_obrigacoesread
concluir_prazoread
exportar_documentoread
guardar_perfil_empresaread
ler_referenciaread
listar_areas_juridicasread
listar_checklistsread
listar_perfisread
listar_playbooksread
listar_prazosread
listar_templatesread
obter_checklistread
obter_perfil_empresaread
obter_playbookread
obter_templateread
painel_clientesread
procurar_conteudoread
registar_prazoread
verificar_atualidaderead
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp-server/dist/index.js:2948
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.jsonc
.markdownlint.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.specs/advogado-pt-v1-1-empresas/.state.json
.state.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.specs/advogado-pt-v1-2-1-correcoes/.state.json
.state.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.specs/advogado-pt-v1-2-operacional/.state.json
.state.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.specs/juridico-pt-v2-0/.state.json
.state.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test/hooks.test.mjs:19
import { detetarDocumentoJuridico } from "../../hooks/juridico-hook.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test/hooks.test.mjs:129
import { mensagemSessionStart } from "../../hooks/juridico-hook.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test/v12.test.mjs:28
import { mensagemSessionStart } from "../../hooks/juridico-hook.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test/v121.test.mjs:37
import { mensagemSessionStart } from "../../hooks/juridico-hook.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test/v121.test.mjs:316
["obter_template", { nome: "../../package" }],
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:8199
const decoded = JSON.parse(atob(base642));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:12735
atob(data);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:12796
const parsedHeader = JSON.parse(atob(header));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/dist/index.js:16478
atob(val);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, zod, @types/node, esbuild, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
mcp-server/content/templates/contrato-saas-b2b.md:46
*The Customer is responsible for its Users' conduct and for keeping access credentials confidential, and shall promptly notify the Provider of any unauthorised use it becomes aware of.*
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/juridico-pt/assets/templates/contrato-saas-b2b.md:46
*The Customer is responsible for its Users' conduct and for keeping access credentials confidential, and shall promptly notify the Provider of any unauthorised use it becomes aware of.*
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha ac37667ba466full audit observations/trust-audit/mcp-server/linofcp007__juridico-pt.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ac37667ba466BLOCKD69first audit
06

Questions

What is the juridico-pt MCP server?

Advogado pessoal e empresarial em Portugal — plugin Claude Code + servidor MCP (referencias, templates, playbooks, checklists e calculadoras juridicas). PT/EN.

What tools does juridico-pt expose?

38 in total: 38 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is juridico-pt safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does juridico-pt need?

No credential environment variables were found in its source, so it appears to need none.

How does juridico-pt run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as juridico-pt at 2.0.2.

How current is this page?

The grade is for one exact copy of the source (ac37667ba466), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement