LSDCAUTION
LSD Model Context Protocol
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Immediately gather an aggregation of high quality info directly from a website just by giving LSD the link via Claude MCP.
You will see Claude connect to the internet and:
- Write LSD SQL
- Self-correct LSD SQL
- Run LSD SQL that's connected to cloud browsers
Demo
Here's a demo of what that looks like in action:
We treated Claude to psychedelic therapy on LSD and now it can just do things. Here's a longer video on YouTube
Contents
- Quickstart
- Dependencies
- Giving Claude LSD
- Claude on LSD
- Failed to start MCP server
- First time running an MCP server
- Missing executable
- Incomplete path
- What is MCP?
- What is LSD?
- Contact
- Smithery
- Installing via Smithery
Quickstart
Dependencies
To run the MCP server, you'll need both Python and uv installed. To use the MCP server, you'll need to download either the Claude desktop app or another MCP client.
To use LSD, you'll need to sign up and create an API key so your queries are privately associated to only your account. You can do so for free with a Google account.
Giving Claude LSD
- Clone this repository onto your computer
$ git clone https://github.com/lsd-so/lsd-mcp.git $ cd lsd-mcp
- Update the values in the
.envfile withLSD_USERcontaining the email you have an account on LSD with andLSD_API_KEYcontaining the API key you obtained from the p
1ac55f08f1d3OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add lsd-mcp --env LSD_API_KEY=${LSD_API_KEY} -- uvx lsd-mcp{
"mcpServers": {
"lsd-mcp": {
"command": "uvx",
"args": [
"lsd-mcp"
],
"env": {
"LSD_API_KEY": "${LSD_API_KEY}"
}
}
}
}Exposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
run_lsd | write | Runs LSD SQL using user credentials in .env |
search_trips | read | Returns a list of objects with LSD trips available to the user and what each of them do. |
use_trip | read | Invokes a trip on LSD based on its identifier using the [ACCORDING TO] keywords. |
view_lsd | read |
Trust audit
CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (8)
.env
.env
media/5x speed.gif
media/5x speed.mov
media/5x_speed.gif
media/github_trending.gif
media/prompt.gif
Gates applied: no_behavioural_pass, no_license.
1ac55f08f1d3full audit observations/trust-audit/mcp-server/lsd-so__lsd.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1ac55f08f1d3 | CAUTION | B | 82 | first audit |
Questions
What is the LSD MCP server?
LSD Model Context Protocol
What tools does LSD expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is LSD safe to connect to an agent?
With care. The audit graded it B (82/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does LSD need?
It reads LSD_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (1ac55f08f1d3), read on 2026-10-07. The repository is watched and re-audited when it changes.