AnkiCAUTION
MCP server for Anki: get quizzed, track retention, find leeches and manage your flashcards from Claude and other MCP clients (via AnkiConnect)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/nietus/anki-mcp/actions/workflows/test.yml) [](LICENSE)
Study and manage your Anki collection by talking to Claude (or any MCP client). 35 tools over AnkiConnect: get quizzed in chat, see what is due and how your retention is going, find the cards you keep forgetting, create and clean up notes in bulk, and pause whole groups of cards until you want them back.
[](https://www.youtube.com/watch?v=NZomvkf8bio)
What you can ask
- "What do I have to study today?" → due counts per deck, streak, reviews this week.
- "Quiz me on 10 due cards from my Spanish deck." → one question at a time, graded, and recorded in Anki with the next interval.
- "Which cards do I keep getting wrong? Help me fix them." → leeches, their review history, and rewrites you approve.
- "Suspend everything tagged HSK5 until my exam, and make it easy to bring back." → named pause that restores exactly those cards, scheduling intact.
- "Turn this article into cloze cards in my Biology deck." → duplicate-checked bulk add.
- "Add audio to every card in this deck that doesn't have it." → Azure TTS in bulk.
- "Move the cards tagged
grammarto a new subdeck" / "rename the tagtodotoreview" / "spread my backlog over the next two weeks".
Bulk changes can be previewed with a dry run, deleting always needs a confirmation step, and when Anki is closed the assistant is told to ask you to open it instead of failing silently.
Install
You need Node.js 18+, Anki running, and the AnkiConnect add-on (code 2055492159).
Claude Desktop
Download anki-mcp.mcpb from the latest release and drag it into Settings → Extensions. Tha
e42d94ee2f18OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add anki-mcp --env ANKI_CONNECT_KEY=${ANKI_CONNECT_KEY} --env AZURE_API_KEY=${AZURE_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"anki-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANKI_CONNECT_KEY": "${ANKI_CONNECT_KEY}",
"AZURE_API_KEY": "${AZURE_API_KEY}"
}
}
}
}Exposed tools (41)
21 read · 17 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_bulk | write | Create many new notes in one call. Duplicates and invalid notes are skipped and reported with the reason. Use dryRun to check before adding. |
add_card | write | Create ONE new note. For several notes use add_bulk; to change existing notes use update_note_fields. |
add_card_with_audio | write | Create ONE new note with Azure TTS audio generated from one of its fields. |
add_cloze_cards | write | Create cloze notes from text. Either pass |
add_image | write | Attach an image to a note field from a URL, a local file path, or base64 data. The image is stored in Anki |
answer_cards | read | Record the user |
bulk_generate_audio | read | Generate audio for many notes at once (e.g. a whole deck). By default only notes whose audio field is empty are processed. |
bulk_update_notes | write | Update fields of many existing notes in one call. |
count | read | How many cards (optional, default 10). |
create_deck | write | Create a deck (use |
create_model | write | Create a new note type. |
deck | read | Deck to study (optional, default: all decks). |
delete_notes | destructive | Permanently delete notes (and all their cards). Two steps: call without confirmToken to preview and get a token, show the preview to the user, then call again with the token after they confirm. |
edit_note_type_field | destructive | Add, remove, rename or reposition a field of a note type. |
find_and_replace | read | Find and replace text across notes (plain text or regex), optionally only in some fields. Returns before/after samples; use dryRun to preview. |
find_cards | read | Search cards with an Anki query and return a page of results. Choose the sections you need to keep output small; use |
find_leeches | read | Find the user |
get_card_history | read | Full review log of specific cards (date, button, interval change, time spent), to explain why a card keeps being forgotten. |
get_deck_model_info | read | Which note types a deck uses. Call before adding cards to an existing deck to pick the right modelName and fields. |
get_deck_names | read | List all deck names. |
get_due_cards | read | Get cards due for review now (learning cards first, then oldest due). Each card includes the interval every button would give (nextIntervals). |
get_model_details | read | Fields, card templates and CSS of a note type. |
get_model_names | read | List all note type (model) names. |
get_new_cards | read | Get new, never-studied cards (suspended cards excluded). |
get_retention_stats | read | Learning analytics for a deck (subdecks included) over the last N days: true retention (young/mature), reviews per day, average seconds per review. |
get_study_overview | read | Today |
leech_review | read | Find the cards I keep forgetting and help fix them. |
make_cards | read | Turn a text, article or notes into good flashcards. |
manage_tags | read | Tag management: list tags (with a deck/filter it returns tag counts for those notes), add/remove tags on notes, rename a tag, or clear unused tags. |
move_cards | write | Move cards to another deck (created automatically if it doesn |
quiz_me | write | Run a study session: quiz due cards one at a time and record the answers in Anki. |
reschedule_cards | destructive | Change card scheduling: set a due date (e.g. vacation backlog), forget (reset to new) or relearn. Reversible only via undo, so preview with dryRun on broad filters. |
suspend_cards | write | Deactivate (suspend) cards so they stop appearing in reviews until unsuspend_cards is called. Scheduling (interval, ease, due date) is kept intact. Pass a label when the user will want to resume this exact group later. |
sync | write | Sync the collection with AnkiWeb (user must be logged in inside Anki). |
text | read | The material to turn into cards. |
undo | write | Undo the most recent action in Anki (a review, a field edit, a suspend...). One action per call. |
unsuspend_cards | read | Reactivate (unsuspend) cards with their original scheduling. With a label, resumes exactly the cards paused under it (cards suspended for other reasons stay suspended); list groups with manage_tags { action: |
update_card_with_audio | write | Generate audio for ONE existing note from one of its fields. |
update_note_fields | write | Update fields of ONE existing note. For many notes use bulk_update_notes. |
update_note_type_styling | write | Replace the CSS of a note type. |
update_note_type_templates | write | Replace the Front/Back HTML of card templates of a note type. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
host: process.env.ANKI_CONNECT_HOST || "http://127.0.0.1",
host: process.env.ANKI_CONNECT_HOST || "http://127.0.0.1",
delete_notes, edit_note_type_field, reschedule_cards
| `ANKI_CONNECT_HOST` | `http://127.0.0.1` | AnkiConnect host. |
@modelcontextprotocol/sdk, dotenv, yanki-connect, @anthropic-ai/mcpb, @types/node, typescript, vitest
public/0521.mp4
Gates applied: no_behavioural_pass.
e42d94ee2f18full audit observations/trust-audit/mcp-server/nietus__anki-8.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e42d94ee2f18 | CAUTION | B | 89 | first audit |
Questions
What is the Anki MCP server?
MCP server for Anki: get quizzed, track retention, find leeches and manage your flashcards from Claude and other MCP clients (via AnkiConnect)
What tools does Anki expose?
41 in total: 21 read-only, 17 that write, and 3 that can delete or overwrite (delete_notes, edit_note_type_field, reschedule_cards). Every one is listed on this page with its risk.
Is Anki safe to connect to an agent?
With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Anki need?
It reads ANKI_CONNECT_KEY and AZURE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Anki run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as anki-mcp at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (e42d94ee2f18), read on 2026-10-08. The repository is watched and re-audited when it changes.