Atlas / MCP servers / mpazik / Binder

BinderSAFE

mcp/mpazik/binder

Headless knowledge base with bidirectional Markdown sync

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
52 52r · 0w · 0d
Transport
—
License
MIT
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The database for tools you build with AI

Local-first, accessible from your editor, scripts, agents, and browser.

[](https://opensource.org/licenses/MIT) [](https://bun.sh) [](https://www.typescriptlang.org/)

What it's for • Getting Started • How it works • Features • Working with Binder • Roadmap

What it's for

Binder is a perfect storage for all sorts of tools and automation built with agents. It especially excels when you need programmatic access and agent or human in the loop. Things like:

  • Trackers and pipelines task tracking, hiring or sales. Binder holds the schema for stages, organizes files by status, and logs every change.
  • Inboxes and queues of stuff to triage. Support tickets, leads, things an agent works through. Agents read and write over MCP or CLI. Scripts batch-process. Mistakes undo cleanly.
  • Catalogs and registries you look things up in: vendors, subscriptions, research, contacts. Records are typed and link to each other. Query from the CLI. Autocomplete in the editor.
  • Dashboards and admin panels for small ops tools that don't justify a SaaS or a full app. binder http gives you an API and a record browser. Drop in server.ts for your own routes.
  • **
Read from source at commit af5461c06677OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add utils --env BINDER_TELEMETRY_KEY=${BINDER_TELEMETRY_KEY} -- npx -y @binder/[email protected]
claude-desktop
{
  "mcpServers": {
    "utils": {
      "command": "npx",
      "args": [
        "-y",
        "@binder/[email protected]"
      ],
      "env": {
        "BINDER_TELEMETRY_KEY": "${BINDER_TELEMETRY_KEY}"
      }
    }
  }
}
03

Exposed tools (52)

52 read · 0 write · 0 destructive.

ToolRiskDescription
AliasesreadAlternative names
AttributereadConfiguration field definition
BlockreadSingle content block such as a paragraph, list, or code block. No headers, blank lines, or horizontal rules allowed.
ChaptersreadDocument chapters
CodereadA code block.
DataviewreadA query-driven view block.
DayreadYYYY-MM-DD (e.g. 2024-03-25)
DocumentreadA top-level note made of ordered blocks.
EmailreadEmail address
FavoritereadFavorite item
FeaturereadProduct feature
IdentifierreadProgrammatic identifier starting with a letter, containing letters, digits, hyphens, and underscores (e.g., my-item_v2)
ImagereadImage URL
IntervalreadFormat is not decided, something to store value of specific period, can be timezone relative or specific
JSONreadAny JSON value
LimitreadMaximum number of items to return from a query
LinereadSingle line of text that may contain any punctuation
ListreadA list container.
MembersreadTeam members
MonthreadYYYY-MM (e.g. 2024-03)
NavigationreadNavigation tree item for document rendering
NotesreadMultiple note paragraphs
OptionreadOption value
OwnersreadMultiple responsible parties
ParagraphreadA text paragraph block.
PartnerreadPartner user (symmetric 1:1)
PathreadFile system path.
PhrasereadShort text without delimiter punctuation
PricereadItem price
PriorityreadPriority level
ProjectreadPart of project
QuarterreadYYYY-Q# (e.g. 2024-Q1)
QueryreadQuery expression.
QuotereadA quoted text block.
RichtextreadText with structure and styling
RolereadRole in relation
SectionreadA titled container with nested blocks.
SettingreadWorkspace configuration setting
StatusreadCurrent state
StepsreadInstruction steps
TaskreadIndividual unit of work
TasksreadRelated tasks
TeamreadCollaborative group
TemplatesreadDocument templates
TitlereadEntity title
TypereadConfiguration entity type definition
URIreadURI reference to an external resource
UserreadIndividual user account
ViewreadReference to rendering view
WeekreadYYYY-W## (e.g. 2024-W12)
WordreadSingle word without any whitespace characters
YearreadYYYY (e.g. 2024)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.ignore
.ignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
integrations/vscode/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/scripts/lsp-test.ts:9
const REPO_ROOT = resolve(import.meta.dirname, "../../..");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/lib/blueprint.ts:26
: join(__dirname, "../../data/blueprints");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/lsp/handlers/completion.test.ts:14
import { BINDER_DIR } from "../../config.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/lsp/handlers/completion.test.ts:15
import type { RuntimeContextWithDb } from "../../runtime.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/lsp/handlers/completion.test.ts:16
import { createMockRuntimeContextWithDb } from "../../runtime.mock.ts";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:241
For browser UIs, webhooks, and integrations. `binder http` starts a local server with a record browser at `http://127.0.0.1:4000`, plus a JSON API:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/guides/http-server.md:21
binder http              # http://127.0.0.1:4000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/guides/http-server.md:62
curl 'http://127.0.0.1:4000/api/records?type=Task&status=active&limit=20'
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/guides/http-server.md:74
curl -X POST http://127.0.0.1:4000/api/transactions \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/cli/tests/http-static.test.ts:35
const BASE = `http://127.0.0.1:${PORT}`;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
packages/utils/src/encoding.ts:21
const binary_string = atob(base64);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
integrations/vscode/package.json
vscode-languageclient, @release-it/conventional-changelog, @types/node, @types/vscode, @vscode/vsce, esbuild, ovsx, release-it
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@eslint/compat, @eslint/js, @types/bun, eslint, eslint-plugin-import-x, eslint-plugin-unused-imports, globals, prettier
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
@hono/node-server, @mariozechner/pi-ai, better-sqlite3, hono, posthog-node, @clack/prompts, @modelcontextprotocol/sdk, @release-it/conventional-changelog
Why it matters. 35 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/repo/package.json
better-sqlite3, drizzle-kit, drizzle-orm, yaml, zod, @types/better-sqlite3
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/utils/package.json
date-fns, transliteration
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha af5461c06677full audit observations/trust-audit/mcp-server/mpazik__binder.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08af5461c06677SAFEB89first audit
06

Questions

What is the Binder MCP server?

Headless knowledge base with bidirectional Markdown sync

What tools does Binder expose?

52 in total: 52 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Binder safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Binder need?

It reads BINDER_TELEMETRY_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (af5461c06677), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement