Atlas / MCP servers / nirholas / LLM Energy

LLM EnergyBLOCK

mcp/nirholas/llm-energy

Extract documentation for AI agents from any site with llms.txt support. Features MCP server, REST API, batch processing, and multiple export formats.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
19 17r · 2w · 0d
Transport
stdio
License
NOASSERTION
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Extract llms.txt documentation and install.md instructions from any website for AI agents, LLMs, and automation workflows.

llm.energy

llms-full-txt.vercel.app

📖 Overview

llm.energy is a web application and MCP server that fetches, parses, and organizes documentation from websites implementing the llms.txt and install.md standards. It transforms raw documentation into structured, agent-ready formats optimized for large language models, AI assistants, and developer tooling.

Read from source at commit b702e68935b7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add core --env ADMIN_KEY=${ADMIN_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y @llm-energy/[email protected]
claude-desktop
{
  "mcpServers": {
    "core": {
      "command": "npx",
      "args": [
        "-y",
        "@llm-energy/[email protected]"
      ],
      "env": {
        "ADMIN_KEY": "${ADMIN_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
      }
    }
  }
}
03

Exposed tools (19)

17 read · 2 write · 0 destructive.

ToolRiskDescription
EmptywriteStart from scratch
agent-promptreadOptimized prompt for AI assistants
discover_documentation_urlsreadDiscover possible llms.txt locations for a given domain. Checks root domain, docs subdomain, and common paths.
extract_and_summarizereadExtract documentation from a URL and provide a summary of its contents
extract_documentationreadExtract and parse documentation from a website that has llms.txt or llms-full.txt. Returns structured documents ready for AI consumption including individual sections, a full consolidated document, and an agent guide.
fetch_llms_txtreadFetch the raw llms.txt or llms-full.txt content from a website without parsing. Useful for quick access to documentation.
find_api_referencereadExtract documentation and locate API reference sections
full-documentationreadComplete documentation in a single file
get_agent_guidereadGet the AI agent guide (AGENT-GUIDE.md) from a previously extracted URL. This contains instructions on how to use the documentation.
get_docreadGet a specific ${data.siteName} documentation page by title
get_document_sectionreadGet a specific document section from previously extracted documentation by filename.
get_full_documentationreadGet the complete consolidated documentation (llms-full.md) from a previously extracted URL.
getting_started_guidewriteExtract documentation and create a getting started guide
list_docsreadList all available ${data.siteName} documentation pages
list_extracted_documentsreadList all document sections from a previously extracted URL.
search_docsreadSearch ${data.siteName} documentation for a specific topic
topicreadThe API topic or endpoint to find
urlreadThe documentation URL to extract
verify_llms_txtreadCheck if a website has a valid llms.txt or llms-full.txt file. Returns availability status, file location, and basic metadata.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (9 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/lib/exporters/yaml.ts:71
const parsed = yaml.load(yamlString) as YamlExport
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/hooks/useVerification.ts:32
const { autoVerify = false, cacheTtl = 5 * 60 * 1000, pollingInterval = 0 } = options
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/hooks/useVerification.ts:156
const { autoVerify = false, cacheTtl = 5 * 60 * 1000 } = options
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.binary · CWE-1104
public/docs/sitemap.xml.gz
sitemap.xml.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
public/docs/assets/javascripts/lunr/min/lunr.da.min.js:18
!function(e,r){"function"==typeof define&&define.amd?define(r):"object"==typeof exports?module.exports=r():r()(e.lunr)}(this,function(){return function(e){if(void 0===e)throw new Error("Lunr is not pr
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
public/docs/assets/javascripts/lunr/min/lunr.de.min.js:18
!function(e,r){"function"==typeof define&&define.amd?define(r):"object"==typeof exports?module.exports=r():r()(e.lunr)}(this,function(){return function(e){if(void 0===e)throw new Error("Lunr is not pr
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
public/docs/assets/javascripts/lunr/min/lunr.du.min.js:18
!function(e,r){"function"==typeof define&&define.amd?define(r):"object"==typeof exports?module.exports=r():r()(e.lunr)}(this,function(){return function(e){if(void 0===e)throw new Error("Lunr is not pr
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
public/docs/assets/javascripts/lunr/min/lunr.es.min.js:18
!function(e,s){"function"==typeof define&&define.amd?define(s):"object"==typeof exports?module.exports=s():s()(e.lunr)}(this,function(){return function(e){if(void 0===e)throw new Error("Lunr is not pr
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
public/docs/assets/javascripts/lunr/min/lunr.fi.min.js:18
!function(i,e){"function"==typeof define&&define.amd?define(e):"object"==typeof exports?module.exports=e():e()(i.lunr)}(this,function(){return function(i){if(void 0===i)throw new Error("Lunr is not pr
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
public/docs/assets/javascripts/lunr/min/lunr.el.min.js:1
!function(e,t){"function"==typeof define&&define.amd?define(t):"object"==typeof exports?module.exports=t():t()(e.lunr)}(this,function(){return function(e){if(void 0===e)throw new Error("Lunr is not pr
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
public/docs/assets/javascripts/lunr/min/lunr.sa.min.js:1
!function(e,r){"function"==typeof define&&define.amd?define(r):"object"==typeof exports?module.exports=r():r()(e.lunr)}(this,function(){return function(e){if(void 0===e)throw new Error("Lunr is not pr
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs-site/requirements.txt
mkdocs-material, pymdown-extensions
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @tsparticles/react, @tsparticles/slim, @types/js-yaml, @types/react-syntax-highlighter, clsx, framer-motion, js-yaml
Why it matters. 31 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/core/package.json
tsup, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
public/docs/assets/javascripts/bundle.79ae519e.min.js.map
public/docs/assets/javascripts/bundle.79ae519e.min.js.map
Why it matters. 1026989 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha b702e68935b7full audit observations/trust-audit/mcp-server/nirholas__llm-energy.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08b702e68935b7BLOCKD69first audit
06

Questions

What is the LLM Energy MCP server?

Extract documentation for AI agents from any site with llms.txt support. Features MCP server, REST API, batch processing, and multiple export formats.

What tools does LLM Energy expose?

19 in total: 17 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is LLM Energy safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does LLM Energy need?

It reads ADMIN_KEY and ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LLM Energy run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @llm-energy/core at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (b702e68935b7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement