MattermostSAFE
Mattermost MCP server to enable Claude to interact with Mattermost Workspaces
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP Server for the Mattermost API, enabling Claude and other MCP clients to interact with Mattermost workspaces.
Features
This MCP server provides tools for interacting with Mattermost, including:
Topic Monitoring
The server includes a topic monitoring system that can:
- Monitor specified channels for messages containing topics of interest
- Run on a configurable schedule (using cron syntax)
- Send notifications when relevant topics are discussed
- Mention you in a specified channel when topics are found
Channel Tools
mattermost_list_channels: List public channels in the workspacemattermost_get_channel_history: Get recent messages from a channel
Message Tools
mattermost_post_message: Post a new message to a channelmattermost_reply_to_thread: Reply to a specific message threadmattermost_add_reaction: Add an emoji reaction to a messagemattermost_get_thread_replies: Get all replies in a thread
Monitoring Tools
mattermost_run_monitoring: Trigger the topic monitoring process immediately
User Tools
mattermost_get_users: Get a list of users in the workspacemattermost_get_user_profile: Get detailed profile information for a user
Setup
- Clone this repository:
git clone https://github.com/yourusername/mattermost-mcp.git cd mattermost-mcp
- Install dependencies:
npm install
- Configure the server:
The repository includes a config.json file with placeholder values. For your actual configuration, create a config.local.json file (which is gitignored) with your real credentials:
{
"mattermostUrl": "https://your-mattermost-instance.com/api/v4",
"token": "your-personal-access-token",
"teamId": "your-team-id",
"monitoring": {
"enabled": false,
"schedule": "*/15 * * * *",
"channels": ["town-square", "off-topic"],
"topics": ["tv series", "champions league"],
"messageLimit": 50
}
}This approach keeps you
991c20637b28OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mattermost-mcp -- npx -y [email protected]
{
"mcpServers": {
"mattermost-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
6 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
mattermost_add_reaction | write | Add a reaction emoji to a message |
mattermost_get_channel_history | read | Get recent messages from a Mattermost channel |
mattermost_get_thread_replies | read | Get all replies in a message thread |
mattermost_get_user_profile | read | Get detailed profile information for a specific user |
mattermost_get_users | read | Get a list of users in the Mattermost workspace with pagination |
mattermost_list_channels | read | List public channels in the Mattermost workspace with pagination |
mattermost_post_message | write | Post a new message to a Mattermost channel |
mattermost_reply_to_thread | read | Reply to a specific message thread in Mattermost |
mattermost_run_monitoring | write | Run the topic monitoring process immediately |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@modelcontextprotocol/sdk, node-cron, node-fetch, @types/node, @types/node-cron, typescript
Gates applied: no_behavioural_pass, no_license.
991c20637b28full audit observations/trust-audit/mcp-server/pvev__mattermost.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 991c20637b28 | SAFE | B | 89 | first audit |
Questions
What is the Mattermost MCP server?
Mattermost MCP server to enable Claude to interact with Mattermost Workspaces
What tools does Mattermost expose?
9 in total: 6 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mattermost safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mattermost need?
No credential environment variables were found in its source, so it appears to need none.
How does Mattermost run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mattermost-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (991c20637b28), read on 2026-10-08. The repository is watched and re-audited when it changes.