LegalContextCAUTION
LegalContext is an open-source Model Context Protocol (MCP) server that creates a secure, standardized bridge between law firms' document management systems (specifically Clio) and AI assistants (starting with Claude Desktop)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/protomated-legal-context)
LegalContext is an open-source Model Context Protocol (MCP) server that creates a secure bridge between a law firm's Clio document management system and Claude Desktop AI assistant.
Features
- Secure Document Access: Connects to Clio API to access legal documents while maintaining complete security and confidentiality
- Local Processing: All document processing happens locally within your firm's infrastructure, ensuring client data never leaves your security perimeter
- MCP Integration: Seamlessly integrates with Claude Desktop through the Model Context Protocol (MCP)
- Semantic Search: Uses LanceDB for efficient vector search, enabling Claude to find the most relevant documents based on meaning, not just keywords
- Citation Tracking: All Claude responses include proper citations to your source documents
- Free Tier Limitations: Includes reasonable limits for the free version (100 documents, 50 queries/day)
Why LegalContext?
For legal professionals, the intersection of AI capabilities and client confidentiality creates a significant challenge:
- The AI Hallucination Problem: Large language models like Claude can provide incorrect or fabricated information. This is particularly dangerous in legal contexts where accuracy is paramount.
- The Client Confidentiality Dilemma: Traditional AI tools require uploading documents to external servers, potentially compromising client confidentiality and attorney-client privilege.
LegalContext solves both problems by:
2bf0b61da485OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add legal-context --env CLIO_CLIENT_SECRET=${CLIO_CLIENT_SECRET} --env SECRET_KEY=${SECRET_KEY} -- npx -y @protomated/[email protected]{
"mcpServers": {
"legal-context": {
"command": "npx",
"args": [
"-y",
"@protomated/[email protected]"
],
"env": {
"CLIO_CLIENT_SECRET": "${CLIO_CLIENT_SECRET}",
"SECRET_KEY": "${SECRET_KEY}"
}
}
}
}Exposed tools (11)
11 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
case_law_search | read | Searches for relevant case law and legal precedents matching specified criteria with jurisdiction and date filters. |
contract_risk_analysis | read | Analyzes legal contracts to identify potential risks, liabilities, and non-standard clauses with severity ratings. |
document_content | read | Retrieves and displays the full content of a legal document with statistics and metadata summary. |
document_metadata | read | Retrieves comprehensive metadata information about a specific legal document. |
document_search | read | Searches through the firm\ |
document_summarization | read | Creates concise summaries of legal documents highlighting key provisions, terms, and important details. |
index_document | read | Indexes a document for semantic search by processing its content and storing embeddings. |
legal_query | read | |
precedent_analysis | read | Provides detailed analysis of legal precedents with success rates of arguments and similarity to other cases. |
rag_query | read | |
semantic_document_search | read | Performs semantic vector search across indexed documents to find content similar to the query, regardless of exact keyword matches. |
Trust audit
CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (19)
console.log(`4. Copy the Client ID and Client Secret to your .env file`);
logger.debug(`Loaded tokens with access token: ${this.tokens.access_token ? '****' + this.tokens.access_token.substring(this.tokens.access_token.length - 4) : 'Missing'}`);logger.debug(`Token created at: ${this.tokens.created_at ? new Date(this.tokens.created_at * 1000).toISOString() : 'Unknown'}`);logger.debug(`Has refresh token: ${this.tokens.refresh_token ? 'Yes' : 'No'}`);logger.debug(`Token expires in: ${tokens.expires_in ? tokens.expires_in : 'unknown'} seconds`);CLIO_REDIRECT_URI=http://127.0.0.1:3001/clio/auth/callback
"CLIO_REDIRECT_URI:http://127.0.0.1:3001/clio/auth/callback:OAuth callback URL (must match Clio settings)"
echo -e "3. Set the redirect URI to exactly: ${CYAN}${CLIO_REDIRECT_URI:-http://127.0.0.1:3001/clio/auth/callback}${NC}".aidigestignore
.aiignore
.releaserc.json
const hash = crypto.createHash('md5');return crypto.createHash('md5').update(text).digest('hex');const contentHash = crypto.createHash('md5').update(documentBuffer).digest('hex');"CLIO_REDIRECT_URI": "http://127.0.0.1:3001/clio/auth/callback",
- **Redirect URI**: `http://127.0.0.1:3001/clio/auth/callback`
@lancedb/lancedb, @modelcontextprotocol/sdk, @node-rs/argon2, @xenova/transformers, apache-arrow, dotenv, langchain, node-cron
- **Clio**: A Clio account with API access and registered application credentials
curl -fsSL https://bun.sh/install | bash
Gates applied: no_behavioural_pass.
2bf0b61da485full audit observations/trust-audit/mcp-server/protomated__legalcontext-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2bf0b61da485 | CAUTION | C | 77 | first audit |
Questions
What is the LegalContext MCP server?
LegalContext is an open-source Model Context Protocol (MCP) server that creates a secure, standardized bridge between law firms' document management systems (specifically Clio) and AI assistants (starting with Claude Desktop)
What tools does LegalContext expose?
11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is LegalContext safe to connect to an agent?
With care. The audit graded it C (77/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does LegalContext need?
It reads CLIO_CLIENT_SECRET and SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does LegalContext run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @protomated/legal-context at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (2bf0b61da485), read on 2026-10-08. The repository is watched and re-audited when it changes.