Atlas / MCP servers / nietus / Anki

AnkiCAUTION

mcp/nietus/anki-8

MCP server for Anki: get quizzed, track retention, find leeches and manage your flashcards from Claude and other MCP clients (via AnkiConnect)

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
41 21r · 17w · 3d
Transport
stdio
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/nietus/anki-mcp/actions/workflows/test.yml) [](LICENSE)

Study and manage your Anki collection by talking to Claude (or any MCP client). 35 tools over AnkiConnect: get quizzed in chat, see what is due and how your retention is going, find the cards you keep forgetting, create and clean up notes in bulk, and pause whole groups of cards until you want them back.

[](https://www.youtube.com/watch?v=NZomvkf8bio)

What you can ask

  • "What do I have to study today?" → due counts per deck, streak, reviews this week.
  • "Quiz me on 10 due cards from my Spanish deck." → one question at a time, graded, and recorded in Anki with the next interval.
  • "Which cards do I keep getting wrong? Help me fix them." → leeches, their review history, and rewrites you approve.
  • "Suspend everything tagged HSK5 until my exam, and make it easy to bring back." → named pause that restores exactly those cards, scheduling intact.
  • "Turn this article into cloze cards in my Biology deck." → duplicate-checked bulk add.
  • "Add audio to every card in this deck that doesn't have it." → Azure TTS in bulk.
  • "Move the cards tagged grammar to a new subdeck" / "rename the tag todo to review" / "spread my backlog over the next two weeks".

Bulk changes can be previewed with a dry run, deleting always needs a confirmation step, and when Anki is closed the assistant is told to ask you to open it instead of failing silently.

Install

You need Node.js 18+, Anki running, and the AnkiConnect add-on (code 2055492159).

Claude Desktop

Download anki-mcp.mcpb from the latest release and drag it into Settings → Extensions. Tha

Read from source at commit e42d94ee2f18OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add anki-mcp --env ANKI_CONNECT_KEY=${ANKI_CONNECT_KEY} --env AZURE_API_KEY=${AZURE_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "anki-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANKI_CONNECT_KEY": "${ANKI_CONNECT_KEY}",
        "AZURE_API_KEY": "${AZURE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (41)

21 read · 17 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_bulkwriteCreate many new notes in one call. Duplicates and invalid notes are skipped and reported with the reason. Use dryRun to check before adding.
add_cardwriteCreate ONE new note. For several notes use add_bulk; to change existing notes use update_note_fields.
add_card_with_audiowriteCreate ONE new note with Azure TTS audio generated from one of its fields.
add_cloze_cardswriteCreate cloze notes from text. Either pass
add_imagewriteAttach an image to a note field from a URL, a local file path, or base64 data. The image is stored in Anki
answer_cardsreadRecord the user
bulk_generate_audioreadGenerate audio for many notes at once (e.g. a whole deck). By default only notes whose audio field is empty are processed.
bulk_update_noteswriteUpdate fields of many existing notes in one call.
countreadHow many cards (optional, default 10).
create_deckwriteCreate a deck (use
create_modelwriteCreate a new note type.
deckreadDeck to study (optional, default: all decks).
delete_notesdestructivePermanently delete notes (and all their cards). Two steps: call without confirmToken to preview and get a token, show the preview to the user, then call again with the token after they confirm.
edit_note_type_fielddestructiveAdd, remove, rename or reposition a field of a note type.
find_and_replacereadFind and replace text across notes (plain text or regex), optionally only in some fields. Returns before/after samples; use dryRun to preview.
find_cardsreadSearch cards with an Anki query and return a page of results. Choose the sections you need to keep output small; use
find_leechesreadFind the user
get_card_historyreadFull review log of specific cards (date, button, interval change, time spent), to explain why a card keeps being forgotten.
get_deck_model_inforeadWhich note types a deck uses. Call before adding cards to an existing deck to pick the right modelName and fields.
get_deck_namesreadList all deck names.
get_due_cardsreadGet cards due for review now (learning cards first, then oldest due). Each card includes the interval every button would give (nextIntervals).
get_model_detailsreadFields, card templates and CSS of a note type.
get_model_namesreadList all note type (model) names.
get_new_cardsreadGet new, never-studied cards (suspended cards excluded).
get_retention_statsreadLearning analytics for a deck (subdecks included) over the last N days: true retention (young/mature), reviews per day, average seconds per review.
get_study_overviewreadToday
leech_reviewreadFind the cards I keep forgetting and help fix them.
make_cardsreadTurn a text, article or notes into good flashcards.
manage_tagsreadTag management: list tags (with a deck/filter it returns tag counts for those notes), add/remove tags on notes, rename a tag, or clear unused tags.
move_cardswriteMove cards to another deck (created automatically if it doesn
quiz_mewriteRun a study session: quiz due cards one at a time and record the answers in Anki.
reschedule_cardsdestructiveChange card scheduling: set a due date (e.g. vacation backlog), forget (reset to new) or relearn. Reversible only via undo, so preview with dryRun on broad filters.
suspend_cardswriteDeactivate (suspend) cards so they stop appearing in reviews until unsuspend_cards is called. Scheduling (interval, ease, due date) is kept intact. Pass a label when the user will want to resume this exact group later.
syncwriteSync the collection with AnkiWeb (user must be logged in inside Anki).
textreadThe material to turn into cards.
undowriteUndo the most recent action in Anki (a review, a field edit, a suspend...). One action per call.
unsuspend_cardsreadReactivate (unsuspend) cards with their original scheduling. With a label, resumes exactly the cards paused under it (cards suspended for other reasons stay suspended); list groups with manage_tags { action:
update_card_with_audiowriteGenerate audio for ONE existing note from one of its fields.
update_note_fieldswriteUpdate fields of ONE existing note. For many notes use bulk_update_notes.
update_note_type_stylingwriteReplace the CSS of a note type.
update_note_type_templateswriteReplace the Front/Back HTML of card templates of a note type.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
build/anki.js:5
host: process.env.ANKI_CONNECT_HOST || "http://127.0.0.1",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/anki.ts:6
host: process.env.ANKI_CONNECT_HOST || "http://127.0.0.1",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_notes, edit_note_type_field, reschedule_cards
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:72
| `ANKI_CONNECT_HOST` | `http://127.0.0.1` | AnkiConnect host. |
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, yanki-connect, @anthropic-ai/mcpb, @types/node, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
public/0521.mp4
public/0521.mp4
Why it matters. 20369441 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e42d94ee2f18full audit observations/trust-audit/mcp-server/nietus__anki-8.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e42d94ee2f18CAUTIONB89first audit
06

Questions

What is the Anki MCP server?

MCP server for Anki: get quizzed, track retention, find leeches and manage your flashcards from Claude and other MCP clients (via AnkiConnect)

What tools does Anki expose?

41 in total: 21 read-only, 17 that write, and 3 that can delete or overwrite (delete_notes, edit_note_type_field, reschedule_cards). Every one is listed on this page with its risk.

Is Anki safe to connect to an agent?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Anki need?

It reads ANKI_CONNECT_KEY and AZURE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Anki run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as anki-mcp at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (e42d94ee2f18), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement