Atlas / MCP servers / sammorrowdrums / ReMarkable

ReMarkableCAUTION

mcp/sammorrowdrums/remarkable-1

MCP server for accessing reMarkable tablet data - sync files, extract text from highlights, and browse your reMarkable cloud

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
14 11r · 3w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
242
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Access a reMarkable library from MCP clients such as Claude, VS Code Copilot, OpenWebUI, and other compatible tools.

Features

  • Browse folders and recent documents.
  • Search names, tags, and extracted text.
  • Read typed text, PDF and EPUB text, highlights, and annotations.
  • Render notebooks and annotated PDFs as PNG or SVG.
  • Export one document as a complete PDF or sectioned Markdown resource.
  • Run handwriting OCR through Google Vision or Tesseract.
  • Upload files and manage folders in supported transports.
  • Render Markdown as PDF and upload it to the tablet.
  • Open an interactive canvas in clients that support MCP Apps.
  • Serve MCP over stdio or local Streamable HTTP.
  • Serve MCP 2026-07-28 and every earlier SDK-supported revision from one

stable SDK 2.x MCPServer.

Quick Install

Prerequisite: install uv

The commands below use uvx, which is included with `uv`. Page images are rasterized with PyMuPDF; no system Cairo, browser, or graphics runtime needs to be installed on macOS, Linux, or Windows.

macOS and Linux

Use the official standalone installer:

curl -LsSf https://astral.sh/uv/install.sh | sh

Or install with Homebrew:

brew install uv

Windows

Use the official standalone installer from PowerShell:

powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

Or install with WinGet:

winget install --id=astral-sh.uv -e

Choose a connection

Start with the first mode that fits your setup.

Read from source at commit 5cafe21b6245OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add remarkable-mcp --env REMARKABLE_TOKEN=${REMARKABLE_TOKEN} -- None remarkable-mcp==0.1.0
03

Exposed tools (14)

11 read · 3 write · 0 destructive.

ToolRiskDescription
my_toolreadif client_supports_elicitation(ctx):
remarkable_browseread
remarkable_canvasread
remarkable_exportread
remarkable_imageread
remarkable_markdown_to_pdfread
remarkable_mkdirread
remarkable_movewrite
remarkable_readread
remarkable_recentread
remarkable_renamewrite
remarkable_searchread
remarkable_statusread
remarkable_uploadwrite
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (16)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/usb-web-setup.md:149
- **Advanced users:** SSH — Fastest, but requires developer mode enabled
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test_server.py:5752
client = SSHClient(key_path="~/.ssh/id_ed25519")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test_server.py:5756
expected_key = os.path.expanduser("~/.ssh/id_ed25519")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test_server.py:5904
monkeypatch.setenv("REMARKABLE_SSH_KEY", "~/.ssh/rm_key")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test_server.py:5907
assert client.key_path == os.path.expanduser("~/.ssh/rm_key")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test_server.py:6680
"~/.ssh/remarkable",
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test_exporters.py:274
filename="../../Unsafe?.pdf",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:104
- The tablet should be accessible at `http://10.11.99.1`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:321
Then add `http://127.0.0.1:8000/mcp` as the MCP server URL in OpenWebUI. The
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:360
proxy_pass http://127.0.0.1:8000;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/usb-web-setup.md:28
Open a web browser and go to: [http://10.11.99.1](http://10.11.99.1)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/usb-web-setup.md:119
# Change the USB host (default: http://10.11.99.1)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
remarkable_mcp/sync.py:256
hasher.update(bytes.fromhex(entry["hash"]))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
test_mcp_v2.py:166
assert base64.b64decode(resource.contents[0].blob).startswith(b"%PDF")
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/development.md:197
| system `ssh` and `scp` | Direct tablet access; `sshpass` is optional for password auth |
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:38
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 5cafe21b6245full audit observations/trust-audit/mcp-server/sammorrowdrums__remarkable-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-065cafe21b6245CAUTIONC79first audit
06

Questions

What is the ReMarkable MCP server?

MCP server for accessing reMarkable tablet data - sync files, extract text from highlights, and browse your reMarkable cloud

What tools does ReMarkable expose?

14 in total: 11 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ReMarkable safe to connect to an agent?

With care. The audit graded it C (79/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does ReMarkable need?

It reads GOOGLE_VISION_API_KEY, REMARKABLE_SSH_KEY, REMARKABLE_SSH_PASSWORD and REMARKABLE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ReMarkable run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as remarkable-mcp.

How current is this page?

The grade is for one exact copy of the source (5cafe21b6245), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement