Atlas / MCP servers / lostintangent / GistPad

GistPadSAFE

mcp/lostintangent/gistpad

๐Ÿ““ An MCP server for managing your personal knowledge, daily notes, and re-usable prompts via GitHub Gists

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
30 13r ยท 12w ยท 5d
Transport
stdio
License
MIT
Stars
209
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server for managing and sharing your personal knowledge, daily notes, and reuseable prompts via GitHub Gists. It's a companion to the GistPad VS Code extension and GistPad.dev (for web/mobile), which allows you to access and edit your gists from any MCP-enabled AI product (e.g. GitHub Copilot, Claude Desktop).

  • ๐Ÿƒ Getting started
  • ๐Ÿ› ๏ธ Included tools
  • ๐Ÿ“ Included resources
  • ๐Ÿ’ฌ Reusable prompts
  • ๐Ÿ’ป CLI reference

๐Ÿƒ Getting started

  1. Using VS Code?
  2. Install the GistPad extension and then reload VS Code
Note: This requires VS Code 1.101.0+, so if you're on an older version, it's time to upgrade!
  1. Open the GistPad tab and sign-in with your GitHub account. After that, you can begin using GistPad from Copilot chat (in Agent mode) without doing any extra setup or token management ๐Ÿ’ช
  1. Other MCP clients...
  2. Generate a personal access token that includes only the gist scope: https://github.com/settings/tokens/new
  3. Add the equivalent of the following to your client's MCP config file (or via an "Add MCP server" GUI/TUI):
{
"mcpServers": {
"gistpad": {
"command": "npx",
"args": ["-y", "gistpad-mcp"],
"env": {
"GITHUB_TOKEN": ""
}
}
}
}

Once your client it setup, you can start having fun with gists + MCP! ๐Ÿฅณ For example, try things like...

  1. Exploring content
  2. How many gists have I edited this month?
  3. What's the summary of my gist?
  1. Creating content
  2. Create a new gist about
  3. Update my gist to call out
  1. Daily todos
  2. What are my unfinished todos for today?
  3. Add a new todo for
  1. Collaboration
  2. `Add
Read from source at commit 147d25422c94OBSERVED ยท 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source โ€” not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add gistpad-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "gistpad-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (30)

13 read ยท 12 write ยท 5 destructive. Blast radius: 5 tools can delete or overwrite โ€” an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_gist_commentwriteAdd a comment to a gist
add_gist_filewriteAdd a new file to a gist
add_gist_promptwriteAdd a new prompt to your gist-based prompts collection
archive_gistreadArchive a gist by ID
create_gistwriteCreate a new GitHub Gist
delete_daily_notedestructiveDelete a specific daily note by date
delete_gistdestructiveDelete a GitHub Gist by ID
delete_gist_commentdestructiveDelete a comment from a gist
delete_gist_filedestructiveDelete a file from a gist
delete_gist_promptdestructiveDelete a prompt from your gist-based prompts collection
duplicate_gistwriteCreate a copy of an existing gist
edit_gist_commentwriteUpdate the content of an existing gist comment
edit_gist_filewriteEdit a file in a gist using find-and-replace. More efficient than update_gist_file
get_daily_notereadGet the contents for a specific/existing daily note
get_gistreadGet the full contents of a GitHub Gist by ID (including file contents).
get_todays_notewriteGet or create the daily note for today
list_archived_gistsreadList all of your archived gists
list_daily_notesreadList all of your existing/historical daily notes
list_gist_commentsreadList all comments on a gist
list_gist_promptsreadList the prompts in your gist-based prompts collection
list_gistsreadList all of your GitHub Gists (excluding daily notes, prompts, and archived gists)
list_starred_gistsreadList all your starred gists
refresh_gistsreadRefresh the server
rename_gist_filewriteRename a file in a gist
star_gistreadStar a gist
unarchive_gistreadUnarchive a gist
unstar_gistreadUnstar a gist
update_gist_descriptionwriteUpdate a GitHub Gist
update_gist_filewriteUpdate the content of a file in a gist
update_todays_notewriteUpdate the existing content of today
04

Trust audit

SAFEgrade B ยท trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path ยท mcp.destructive_tools ยท CWE-22, CWE-59
delete_daily_note, delete_gist, delete_gist_comment, delete_gist_file, delete_gist_prompt
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain ยท supply.unpinned ยท CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, gray-matter, zod, @types/node, @typescript/native-preview, oxfmt, oxlint, tsx
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 ยท audit v0.4.1 ยท source sha 147d25422c94full audit observations/trust-audit/mcp-server/lostintangent__gistpad.json ยท Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06147d25422c94SAFEB89first audit
06

Questions

What is the GistPad MCP server?

๐Ÿ““ An MCP server for managing your personal knowledge, daily notes, and re-usable prompts via GitHub Gists

What tools does GistPad expose?

30 in total: 13 read-only, 12 that write, and 5 that can delete or overwrite (delete_daily_note, delete_gist, delete_gist_comment, delete_gist_file, delete_gist_prompt). Every one is listed on this page with its risk.

Is GistPad safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GistPad need?

No credential environment variables were found in its source, so it appears to need none.

How does GistPad run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as gistpad-mcp at 0.5.0.

How current is this page?

The grade is for one exact copy of the source (147d25422c94), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement