Atlas / MCP servers / opaqueglass / Syplugin-an

Syplugin-anCAUTION

mcp/opaqueglass/syplugin-an

A plugin that provide simple MCP service for Siyuan-note

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
43 23r · 13w · 7d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

中文

A plugin that provides MCP service for Siyuan Note.

🌻 Features

  • Most tools support the exclude document function.
  • It includes certain input parameter validation and is not a direct API wrapper for SiYuan Note.
  • Ready to use once the plugin is installed and enabled on the desktop client; Docker and mobile platforms are not supported.

✨ Quick Start

  • Download from the marketplace or 1. unzip the package.zip in Release, 2. move the folder to workspace/data/plugins/, 3. and rename the folder to syplugin-anMCPServer;
  • Enable the plugin;
  • The plugin listens on port 16806 by default (Host: 127.0.0.1), please use http://127.0.0.1:16806/sse as the server access address;
⭐ If this is helpful to you, please consider giving it a star!

🛠 Supported Tools (Summary)

For detailed tools, supported excluded documents, and other notes, please refer to the Supported Tools section.
  • Document and block operations: create, read, update, and delete;
  • Database operations:
  • Create databases, add/delete/update database rows, add/delete database columns, and retrieve database structure information;
  • Attribute operations: create, read, update, and delete;
  • Flashcard operations: create flashcards from Markdown content, create flashcards by block ID, delete flashcards by block ID;
  • Template operations: retrieve existing templates, get raw template file content, preview template rendering results, preview Sprig rendering results, create or overwrite templates, render templates and insert at the beginning of a document, delete existing templates;
  • Notebook operations: list notebooks, rename notebooks;

❓ Frequently Asked Questions

  • Q1: How to use it in an MCP client?

Please refer to the subsequent sections.

  • Q2: What are some common MCP clients?
  • Please refer to: [https://github.com/punkpeye/awesome
Read from source at commit 81df15a393b8OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add syplugin-an-mcp-server --env MCP_AUTH_CODE=${MCP_AUTH_CODE} --env SIYUAN_API_KEY=${SIYUAN_API_KEY} --env SIYUAN_API_TOKEN=${SIYUAN_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "syplugin-an-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MCP_AUTH_CODE": "${MCP_AUTH_CODE}",
        "SIYUAN_API_KEY": "${SIYUAN_API_KEY}",
        "SIYUAN_API_TOKEN": "${SIYUAN_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (43)

23 read · 13 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
siyuan_add_database_columnwriteAdd a new column to the database.
siyuan_add_database_row_with_datawriteAdd a new row to the database and get the row ID of the newly added row.
siyuan_append_blockread在指定父块的子块列表最后面插入一个新块,内容为 markdown 格式。
siyuan_append_markdown_to_docreadAppend Markdown content to the end of a document in SiYuan by its ID.
siyuan_create_databasewriteCreate a new database. 返回值包括:avId(数据库ID)和 blockId(数据库所在的块ID),对数据库的操作请求需使用avId。
siyuan_create_flashcardswriteCreate flashcards from one or more block IDs.
siyuan_create_flashcards_with_new_docwriteCreate New Document, and Make Flashcards with Specific Method
siyuan_create_note_with_mdwriteCreate a new note under a parent document in SiYuan with a specified title and Markdown content.
siyuan_create_templatedestructiveCreate a new template file or overwrite an existing one in the SiYuan workspace. This allows users to save reusable content structures for future note creation.
siyuan_delete_block_by_iddestructive根据块ID删除一个块。
siyuan_delete_database_columndestructiveDelete a column from the database.
siyuan_delete_database_rowsdestructiveDelete one or more rows from the database.
siyuan_delete_doc_by_iddestructiveDelete a document in SiYuan by its ID.
siyuan_delete_flashcardsdestructiveDelete flashcards from a deck using their corresponding block IDs.
siyuan_get_available_rag_service_typereadRetrieve the list of currently available RAG (Retrieval-Augmented Generation) services and their IDs in SiYuan Note. Before invoking
siyuan_get_block_attributesreadGet all attributes of a specific block.
siyuan_get_block_backlinksreadRetrieve all documents or blocks that reference a specified document or block within the workspace. The result includes the referencing document
siyuan_get_database_schemareadGet the schema of a specific database.\n\n返回值包括:avId(数据库ID)和 blockId(数据库所在的块ID),对数据库的操作请求使用avId。
siyuan_get_database_view_schemareadGet the schema of a specific view within a database.\n\n返回值包括:avId(数据库ID)和 blockId(数据库所在的块ID),对数据库的操作请求使用avId。
siyuan_get_raw_templatereadRetrieve the raw source content of a specified template file. Useful for inspecting or editing the template structure.
siyuan_insert_blockwrite在指定位置插入一个新块。插入内容必须是 markdown 格式。插入位置可通过
siyuan_list_database_locationsreadFinds all content block IDs where a specific database (avId) is instantiated. Use this to locate the physical positions of a database, including its original instance and all mirrored versions.
siyuan_list_notebookreadList all notebooks in SiYuan and return their metadata(such as id, open status, dailyNoteSavePath etc.).
siyuan_markdown_syntax_helpreadProvides help with the Markdown syntax used in SiYuan, including supported formatting options and usage examples.
siyuan_move_block_by_idwrite移动指定类型的块(如段落、标题、超级块、表格等)到目标位置。注意:此工具不支持移动文档块(Document Block)。
siyuan_prepend_blockread在指定父块的子块列表最前面插入一个新块,内容为 markdown 格式。
siyuan_preview_rendered_templatereadGenerates the rendered Markdown string of a template without modifying the document. Use this to check the output or get the content for further processing before any insertion.
siyuan_query_databasereadSearch for rows in the database with keywords.
siyuan_query_sqlwriteExecute read-only SQL queries to fetch notes and structured data from SiYuan. Mandatory Step: Before writing your SQL, you MUST read the
siyuan_query_syntaxreadProvides documentation about SiYuan
siyuan_read_doc_contentreadRetrieve the content of a document or block by its ID
siyuan_remove_templatedestructiveDelete a specified template file from the workspace. This action is permanent.
siyuan_rename_docwriteRename an existing document in SiYuan by its ID and a new title.
siyuan_rename_notebookwriteRename an existing notebook in SiYuan by its ID and a new title.
siyuan_render_sprig_templatereadRender a Sprig template with the specified content.
siyuan_render_templatereadRenders a template and INSERTS the result directly into the specified document. Use this when you want to modify the document by prepending template-generated content.
siyuan_searchreadPerform a keyword-based full-text search across blocks in SiYuan (e.g., paragraphs, headings). This tool only matches literal text content in document bodies or headings. For dynamic queries (dailynote(i.e. diary), path restrictions, date ranges), use sql with
siyuan_search_existing_databasesreadSearch for existing databases in the current workspace using keywords. This tool is designed to help you find the avId of an existing database, which is required for other database operations.
siyuan_search_templatereadSearch for existing templates within the workspace using a keyword. Returns a list of template names that match the search criteria.
siyuan_sql_helpdocreadProvides documentation about the SiYuan content search database schema relevant to content blocks, including table names, field names, and relationships. This information is essential for constructing effective SQL queries when using the
siyuan_template_function_helpreadProvides help with the template functions available in SiYuan, including their syntax and usage examples.
siyuan_update_blockwrite根据块ID更新现有块的内容,内容应当是 Kramdown 格式。使用markdown格式将丢失块的属性等信息。
siyuan_update_database_row_with_datawriteUpdate an existing row in the database. Columns not explicitly mentioned will remain unchanged unless explicitly updated to blank values. The values of the rollup and template column types cannot be modified using this tool.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/tools/attributeView.ts:212
const domDataBaseStr = `<div contenteditable=\"false\" data-av-id=\"${avId}\" data-av-type=\"table\" data-node-id=\"${blockId}\" data-node-index=\"1\" data-type=\"NodeAttributeView\" class=\"av\" upda
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
siyuan_create_template, siyuan_delete_block_by_id, siyuan_delete_database_column, siyuan_delete_database_rows, siyuan_delete_doc_by_id, siyuan_delete_flashcards, siyuan_remove_template
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintignore
.eslintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintrc.js
.eslintrc.js
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
scripts/.release.py
.release.py
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:18
- The plugin listens on port `16806` by default (Host: `127.0.0.1`), please use `http://127.0.0.1:16806/sse` as the server access address;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:111
2. URL: `http://127.0.0.1:16806/mcp`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:117
2. URL: `http://127.0.0.1:16806/mcp`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:139
npx mcp-remote@next http://127.0.0.1:16806/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:146
npx mcp-remote@next http://127.0.0.1:16806/mcp --header Authorization:${AUTH_HEADER}
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @vue/tsconfig, async-mutex, element-plus, express, ts-loader, v-code-diff, vue
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 81df15a393b8full audit observations/trust-audit/mcp-server/opaqueglass__syplugin-an.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0881df15a393b8CAUTIONB89first audit
06

Questions

What is the Syplugin-an MCP server?

A plugin that provide simple MCP service for Siyuan-note

What tools does Syplugin-an expose?

43 in total: 23 read-only, 13 that write, and 7 that can delete or overwrite (siyuan_create_template, siyuan_delete_block_by_id, siyuan_delete_database_column, siyuan_delete_database_rows, siyuan_delete_doc_by_id). Every one is listed on this page with its risk.

Is Syplugin-an safe to connect to an agent?

With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Syplugin-an need?

It reads MCP_AUTH_CODE, SIYUAN_API_KEY and SIYUAN_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Syplugin-an run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as syplugin-an-mcp-server at 1.2.1.

How current is this page?

The grade is for one exact copy of the source (81df15a393b8), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement