Nutrient Document EngineCAUTION
A Model Context Protocol (MCP) server implementation exposes document processing capabilities through natural language, supporting both direct human interaction and AI agent tool calling.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@nutrient-sdk/document-engine-mcp-server)
Connect AI agents to document processing.
This MCP server exposes document processing capabilities through natural language, supporting both direct human interaction and AI agent tool calling.
Which MCP Server Should I Use?
You are in the Document Engine MCP Server repo. Choose this when you need self-hosted/on-prem document workflows and deployment control.
- Ecosystem overview: Nutrient AI Infrastructure
- Product landing page: Nutrient MCP Server
Example Conversations
Once configured, you (or your agent) can interact with documents through natural language:
You: "What documents do I have available?" AI: "I can see you have 3 documents: annual-report.pdf, contract-draft.pdf, and tax-form-2023.pdf. Would you like me to analyze any of these?"
You: "Extract all the names and phone numbers from these invoices" AI: "I found 12 contacts: John Smith (555-0123), Sarah Johnson (555-0456)..."
You: "Redact all social security numbers from these tax forms" AI: *"I've id
c6d6cf59ffbaOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add document-engine-mcp-server --env DOCUMENT_ENGINE_API_AUTH_TOKEN=${DOCUMENT_ENGINE_API_AUTH_TOKEN} --env DASHBOARD_PASSWORD=${DASHBOARD_PASSWORD} -- npx -y @nutrient-sdk/[email protected]Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (23)
8 0 obj<</BaseFont/Helvetica-Bold/Encoding 10 0 R/Name/HeBo/Subtype/Type1/Type/Font>>endobj9 0 obj<</BaseFont/Helvetica/Encoding 10 0 R/Name/Helv/Subtype/Type1/Type/Font>>endobj10 0 obj<</Differences[
137 0 obj[/ICCBased 82 0 R]endobj138 0 obj<</AIS false/BM/Normal/CA 1.0/OP false/OPM 1/SA true/SMask/None/Type/ExtGState/ca 1.0/op false>>endobj147 0 obj<</BaseEncoding/WinAnsiEncoding/Differences[27/
finance.xlsx
.prettierrc.json
import { MarkdownText } from "../../markdown-text";import { MarkdownText } from "../../markdown-text";import { TooltipIconButton } from "../../tooltip-icon-button";import { DocumentEngineClient } from '../../api/Client.js';} from '../../api/DocumentEngineSchema.js';
8 0 obj<</BaseFont/Helvetica-Bold/Encoding 10 0 R/Name/HeBo/Subtype/Type1/Type/Font>>endobj9 0 obj<</BaseFont/Helvetica/Encoding 10 0 R/Name/Helv/Subtype/Type1/Type/Font>>endobj10 0 obj<</Differences[
137 0 obj[/ICCBased 82 0 R]endobj138 0 obj<</AIS false/BM/Normal/CA 1.0/OP false/OPM 1/SA true/SMask/None/Type/ExtGState/ca 1.0/op false>>endobj147 0 obj<</BaseEncoding/WinAnsiEncoding/Differences[27/
@elastic/elasticsearch, @langchain/anthropic, @langchain/cohere, @langchain/community, @langchain/core, @langchain/langgraph, @langchain/langgraph-checkpoint, @langchain/mcp-adapters
@langchain/core, @langchain/langgraph, @langchain/langgraph-api, @langchain/langgraph-cli, @langchain/langgraph-sdk, @radix-ui/react-avatar, @radix-ui/react-dialog, @radix-ui/react-label
@eslint/eslintrc, @tsconfig/recommended, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, concurrently, eslint, eslint-config-prettier, eslint-plugin-import
@langchain/core, @langchain/langgraph, @langchain/mcp-adapters, @langchain/openai, dotenv, mime-types, zod
@openai/agents, dotenv, mime-types, zod
`MCP_HTTP_AUTH_TOKEN`; the server refuses to start without a nonempty token. Clients must send the
assets/ocr.pdf
assets/report.pdf
examples/assets/ocrTest.pdf
resources/claude-document-engine-mcp.gif
src/api/document-engine-api.yml
Gates applied: no_behavioural_pass.
c6d6cf59ffbafull audit observations/trust-audit/mcp-server/pspdfkit__nutrient-document-engine.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c6d6cf59ffba | CAUTION | B | 85 | first audit |
Questions
What is the Nutrient Document Engine MCP server?
A Model Context Protocol (MCP) server implementation exposes document processing capabilities through natural language, supporting both direct human interaction and AI agent tool calling.
Is Nutrient Document Engine safe to connect to an agent?
With care. The audit graded it B (85/100) and found 23 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Nutrient Document Engine need?
It reads DASHBOARD_PASSWORD, DOCUMENT_ENGINE_API_AUTH_TOKEN, MCP_HTTP_AUTH_TOKEN and NEXT_PUBLIC_LANGSMITH_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Nutrient Document Engine run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @nutrient-sdk/document-engine-mcp-server at 0.0.3.
How current is this page?
The grade is for one exact copy of the source (c6d6cf59ffba), read on 2026-10-07. The repository is watched and re-audited when it changes.