Atlas / MCP servers / protomated / LegalContext

LegalContextCAUTION

mcp/protomated/legalcontext-1

LegalContext is an open-source Model Context Protocol (MCP) server that creates a secure, standardized bridge between law firms' document management systems (specifically Clio) and AI assistants (starting with Claude Desktop)

Verdict
CAUTION
Grade
C
Trust score
77 /100
Exposed tools
11 11r · 0w · 0d
Transport
stdio
License
MPL-2.0
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/protomated-legal-context)

LegalContext is an open-source Model Context Protocol (MCP) server that creates a secure bridge between a law firm's Clio document management system and Claude Desktop AI assistant.

Features

  • Secure Document Access: Connects to Clio API to access legal documents while maintaining complete security and confidentiality
  • Local Processing: All document processing happens locally within your firm's infrastructure, ensuring client data never leaves your security perimeter
  • MCP Integration: Seamlessly integrates with Claude Desktop through the Model Context Protocol (MCP)
  • Semantic Search: Uses LanceDB for efficient vector search, enabling Claude to find the most relevant documents based on meaning, not just keywords
  • Citation Tracking: All Claude responses include proper citations to your source documents
  • Free Tier Limitations: Includes reasonable limits for the free version (100 documents, 50 queries/day)

Why LegalContext?

For legal professionals, the intersection of AI capabilities and client confidentiality creates a significant challenge:

  1. The AI Hallucination Problem: Large language models like Claude can provide incorrect or fabricated information. This is particularly dangerous in legal contexts where accuracy is paramount.
  1. The Client Confidentiality Dilemma: Traditional AI tools require uploading documents to external servers, potentially compromising client confidentiality and attorney-client privilege.

LegalContext solves both problems by:

Read from source at commit 2bf0b61da485OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add legal-context --env CLIO_CLIENT_SECRET=${CLIO_CLIENT_SECRET} --env SECRET_KEY=${SECRET_KEY} -- npx -y @protomated/[email protected]
claude-desktop
{
  "mcpServers": {
    "legal-context": {
      "command": "npx",
      "args": [
        "-y",
        "@protomated/[email protected]"
      ],
      "env": {
        "CLIO_CLIENT_SECRET": "${CLIO_CLIENT_SECRET}",
        "SECRET_KEY": "${SECRET_KEY}"
      }
    }
  }
}
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
case_law_searchreadSearches for relevant case law and legal precedents matching specified criteria with jurisdiction and date filters.
contract_risk_analysisreadAnalyzes legal contracts to identify potential risks, liabilities, and non-standard clauses with severity ratings.
document_contentreadRetrieves and displays the full content of a legal document with statistics and metadata summary.
document_metadatareadRetrieves comprehensive metadata information about a specific legal document.
document_searchreadSearches through the firm\
document_summarizationreadCreates concise summaries of legal documents highlighting key provisions, terms, and important details.
index_documentreadIndexes a document for semantic search by processing its content and storing embeddings.
legal_queryread
precedent_analysisreadProvides detailed analysis of legal precedents with success rates of arguments and similarity to other cases.
rag_queryread
semantic_document_searchreadPerforms semantic vector search across indexed documents to find content similar to the query, regardless of exact keyword matches.
04

Trust audit

CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
setup.ts:275
console.log(`4. Copy the Client ID and Client Secret to your .env file`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clio/apiClient.ts:140
logger.debug(`Loaded tokens with access token: ${this.tokens.access_token ? '****' + this.tokens.access_token.substring(this.tokens.access_token.length - 4) : 'Missing'}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clio/apiClient.ts:141
logger.debug(`Token created at: ${this.tokens.created_at ? new Date(this.tokens.created_at * 1000).toISOString() : 'Unknown'}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clio/apiClient.ts:142
logger.debug(`Has refresh token: ${this.tokens.refresh_token ? 'Yes' : 'No'}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clio/authStatus.ts:32
logger.debug(`Token expires in: ${tokens.expires_in ? tokens.expires_in : 'unknown'} seconds`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:16
CLIO_REDIRECT_URI=http://127.0.0.1:3001/clio/auth/callback
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
install.sh:74
"CLIO_REDIRECT_URI:http://127.0.0.1:3001/clio/auth/callback:OAuth callback URL (must match Clio settings)"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
install.sh:187
echo -e "3. Set the redirect URI to exactly: ${CYAN}${CLIO_REDIRECT_URI:-http://127.0.0.1:3001/clio/auth/callback}${NC}"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.aidigestignore
.aidigestignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.aiignore
.aiignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/documents/documentIndexer.ts:362
const hash = crypto.createHash('md5');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/documents/documentProcessor.ts:192
return crypto.createHash('md5').update(text).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/documents/documentProcessor.ts:268
const contentHash = crypto.createHash('md5').update(documentBuffer).digest('hex');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:176
"CLIO_REDIRECT_URI": "http://127.0.0.1:3001/clio/auth/callback",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:222
- **Redirect URI**: `http://127.0.0.1:3001/clio/auth/callback`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@lancedb/lancedb, @modelcontextprotocol/sdk, @node-rs/argon2, @xenova/transformers, apache-arrow, dotenv, langchain, node-cron
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:58
- **Clio**: A Clio account with API access and registered application credentials
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:107
curl -fsSL https://bun.sh/install | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2bf0b61da485full audit observations/trust-audit/mcp-server/protomated__legalcontext-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082bf0b61da485CAUTIONC77first audit
06

Questions

What is the LegalContext MCP server?

LegalContext is an open-source Model Context Protocol (MCP) server that creates a secure, standardized bridge between law firms' document management systems (specifically Clio) and AI assistants (starting with Claude Desktop)

What tools does LegalContext expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is LegalContext safe to connect to an agent?

With care. The audit graded it C (77/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does LegalContext need?

It reads CLIO_CLIENT_SECRET and SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LegalContext run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @protomated/legal-context at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (2bf0b61da485), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement