BinderSAFE
Headless knowledge base with bidirectional Markdown sync
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The database for tools you build with AI
Local-first, accessible from your editor, scripts, agents, and browser.
[](https://opensource.org/licenses/MIT) [](https://bun.sh) [](https://www.typescriptlang.org/)
What it's for • Getting Started • How it works • Features • Working with Binder • Roadmap
What it's for
Binder is a perfect storage for all sorts of tools and automation built with agents. It especially excels when you need programmatic access and agent or human in the loop. Things like:
- Trackers and pipelines task tracking, hiring or sales. Binder holds the schema for stages, organizes files by status, and logs every change.
- Inboxes and queues of stuff to triage. Support tickets, leads, things an agent works through. Agents read and write over MCP or CLI. Scripts batch-process. Mistakes undo cleanly.
- Catalogs and registries you look things up in: vendors, subscriptions, research, contacts. Records are typed and link to each other. Query from the CLI. Autocomplete in the editor.
- Dashboards and admin panels for small ops tools that don't justify a SaaS or a full app.
binder httpgives you an API and a record browser. Drop inserver.tsfor your own routes. - **
af5461c06677OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add utils --env BINDER_TELEMETRY_KEY=${BINDER_TELEMETRY_KEY} -- npx -y @binder/[email protected]{
"mcpServers": {
"utils": {
"command": "npx",
"args": [
"-y",
"@binder/[email protected]"
],
"env": {
"BINDER_TELEMETRY_KEY": "${BINDER_TELEMETRY_KEY}"
}
}
}
}Exposed tools (52)
52 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Aliases | read | Alternative names |
Attribute | read | Configuration field definition |
Block | read | Single content block such as a paragraph, list, or code block. No headers, blank lines, or horizontal rules allowed. |
Chapters | read | Document chapters |
Code | read | A code block. |
Dataview | read | A query-driven view block. |
Day | read | YYYY-MM-DD (e.g. 2024-03-25) |
Document | read | A top-level note made of ordered blocks. |
Email | read | Email address |
Favorite | read | Favorite item |
Feature | read | Product feature |
Identifier | read | Programmatic identifier starting with a letter, containing letters, digits, hyphens, and underscores (e.g., my-item_v2) |
Image | read | Image URL |
Interval | read | Format is not decided, something to store value of specific period, can be timezone relative or specific |
JSON | read | Any JSON value |
Limit | read | Maximum number of items to return from a query |
Line | read | Single line of text that may contain any punctuation |
List | read | A list container. |
Members | read | Team members |
Month | read | YYYY-MM (e.g. 2024-03) |
Navigation | read | Navigation tree item for document rendering |
Notes | read | Multiple note paragraphs |
Option | read | Option value |
Owners | read | Multiple responsible parties |
Paragraph | read | A text paragraph block. |
Partner | read | Partner user (symmetric 1:1) |
Path | read | File system path. |
Phrase | read | Short text without delimiter punctuation |
Price | read | Item price |
Priority | read | Priority level |
Project | read | Part of project |
Quarter | read | YYYY-Q# (e.g. 2024-Q1) |
Query | read | Query expression. |
Quote | read | A quoted text block. |
Richtext | read | Text with structure and styling |
Role | read | Role in relation |
Section | read | A titled container with nested blocks. |
Setting | read | Workspace configuration setting |
Status | read | Current state |
Steps | read | Instruction steps |
Task | read | Individual unit of work |
Tasks | read | Related tasks |
Team | read | Collaborative group |
Templates | read | Document templates |
Title | read | Entity title |
Type | read | Configuration entity type definition |
URI | read | URI reference to an external resource |
User | read | Individual user account |
View | read | Reference to rendering view |
Week | read | YYYY-W## (e.g. 2024-W12) |
Word | read | Single word without any whitespace characters |
Year | read | YYYY (e.g. 2024) |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (19)
.ignore
.prettierignore
.vscodeignore
const REPO_ROOT = resolve(import.meta.dirname, "../../..");
: join(__dirname, "../../data/blueprints");
import { BINDER_DIR } from "../../config.ts";import type { RuntimeContextWithDb } from "../../runtime.ts";import { createMockRuntimeContextWithDb } from "../../runtime.mock.ts";For browser UIs, webhooks, and integrations. `binder http` starts a local server with a record browser at `http://127.0.0.1:4000`, plus a JSON API:
binder http # http://127.0.0.1:4000
curl 'http://127.0.0.1:4000/api/records?type=Task&status=active&limit=20'
curl -X POST http://127.0.0.1:4000/api/transactions \
const BASE = `http://127.0.0.1:${PORT}`;const binary_string = atob(base64);
vscode-languageclient, @release-it/conventional-changelog, @types/node, @types/vscode, @vscode/vsce, esbuild, ovsx, release-it
@eslint/compat, @eslint/js, @types/bun, eslint, eslint-plugin-import-x, eslint-plugin-unused-imports, globals, prettier
@hono/node-server, @mariozechner/pi-ai, better-sqlite3, hono, posthog-node, @clack/prompts, @modelcontextprotocol/sdk, @release-it/conventional-changelog
better-sqlite3, drizzle-kit, drizzle-orm, yaml, zod, @types/better-sqlite3
date-fns, transliteration
Gates applied: no_behavioural_pass.
af5461c06677full audit observations/trust-audit/mcp-server/mpazik__binder.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | af5461c06677 | SAFE | B | 89 | first audit |
Questions
What is the Binder MCP server?
Headless knowledge base with bidirectional Markdown sync
What tools does Binder expose?
52 in total: 52 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Binder safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Binder need?
It reads BINDER_TELEMETRY_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (af5461c06677), read on 2026-10-08. The repository is watched and re-audited when it changes.