GistPadSAFE
๐ An MCP server for managing your personal knowledge, daily notes, and re-usable prompts via GitHub Gists
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server for managing and sharing your personal knowledge, daily notes, and reuseable prompts via GitHub Gists. It's a companion to the GistPad VS Code extension and GistPad.dev (for web/mobile), which allows you to access and edit your gists from any MCP-enabled AI product (e.g. GitHub Copilot, Claude Desktop).
- ๐ Getting started
- ๐ ๏ธ Included tools
- ๐ Included resources
- ๐ฌ Reusable prompts
- ๐ป CLI reference
๐ Getting started
- Using VS Code?
- Install the GistPad extension and then reload VS Code
Note: This requires VS Code 1.101.0+, so if you're on an older version, it's time to upgrade!
- Open the
GistPadtab and sign-in with your GitHub account. After that, you can begin using GistPad from Copilot chat (inAgentmode) without doing any extra setup or token management ๐ช
- Other MCP clients...
- Generate a personal access token that includes only the
gistscope: https://github.com/settings/tokens/new - Add the equivalent of the following to your client's MCP config file (or via an "Add MCP server" GUI/TUI):
{
"mcpServers": {
"gistpad": {
"command": "npx",
"args": ["-y", "gistpad-mcp"],
"env": {
"GITHUB_TOKEN": ""
}
}
}
}Once your client it setup, you can start having fun with gists + MCP! ๐ฅณ For example, try things like...
- Exploring content
How many gists have I edited this month?What's the summary of my gist?
- Creating content
Create a new gist aboutUpdate my gist to call out
- Daily todos
What are my unfinished todos for today?Add a new todo for
- Collaboration
- `Add
147d25422c94OBSERVED ยท 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source โ not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add gistpad-mcp -- npx -y [email protected]
{
"mcpServers": {
"gistpad-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (30)
13 read ยท 12 write ยท 5 destructive. Blast radius: 5 tools can delete or overwrite โ an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_gist_comment | write | Add a comment to a gist |
add_gist_file | write | Add a new file to a gist |
add_gist_prompt | write | Add a new prompt to your gist-based prompts collection |
archive_gist | read | Archive a gist by ID |
create_gist | write | Create a new GitHub Gist |
delete_daily_note | destructive | Delete a specific daily note by date |
delete_gist | destructive | Delete a GitHub Gist by ID |
delete_gist_comment | destructive | Delete a comment from a gist |
delete_gist_file | destructive | Delete a file from a gist |
delete_gist_prompt | destructive | Delete a prompt from your gist-based prompts collection |
duplicate_gist | write | Create a copy of an existing gist |
edit_gist_comment | write | Update the content of an existing gist comment |
edit_gist_file | write | Edit a file in a gist using find-and-replace. More efficient than update_gist_file |
get_daily_note | read | Get the contents for a specific/existing daily note |
get_gist | read | Get the full contents of a GitHub Gist by ID (including file contents). |
get_todays_note | write | Get or create the daily note for today |
list_archived_gists | read | List all of your archived gists |
list_daily_notes | read | List all of your existing/historical daily notes |
list_gist_comments | read | List all comments on a gist |
list_gist_prompts | read | List the prompts in your gist-based prompts collection |
list_gists | read | List all of your GitHub Gists (excluding daily notes, prompts, and archived gists) |
list_starred_gists | read | List all your starred gists |
refresh_gists | read | Refresh the server |
rename_gist_file | write | Rename a file in a gist |
star_gist | read | Star a gist |
unarchive_gist | read | Unarchive a gist |
unstar_gist | read | Unstar a gist |
update_gist_description | write | Update a GitHub Gist |
update_gist_file | write | Update the content of a file in a gist |
update_todays_note | write | Update the existing content of today |
Trust audit
SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
delete_daily_note, delete_gist, delete_gist_comment, delete_gist_file, delete_gist_prompt
@modelcontextprotocol/sdk, gray-matter, zod, @types/node, @typescript/native-preview, oxfmt, oxlint, tsx
Gates applied: no_behavioural_pass.
147d25422c94full audit observations/trust-audit/mcp-server/lostintangent__gistpad.json ยท Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 147d25422c94 | SAFE | B | 89 | first audit |
Questions
What is the GistPad MCP server?
๐ An MCP server for managing your personal knowledge, daily notes, and re-usable prompts via GitHub Gists
What tools does GistPad expose?
30 in total: 13 read-only, 12 that write, and 5 that can delete or overwrite (delete_daily_note, delete_gist, delete_gist_comment, delete_gist_file, delete_gist_prompt). Every one is listed on this page with its risk.
Is GistPad safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GistPad need?
No credential environment variables were found in its source, so it appears to need none.
How does GistPad run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as gistpad-mcp at 0.5.0.
How current is this page?
The grade is for one exact copy of the source (147d25422c94), read on 2026-10-06. The repository is watched and re-audited when it changes.