Atlas / MCP servers / sirmews / Apple Notes

Apple NotesSAFE

mcp/sirmews/apple-notes-3

Read your Apple Notes with Claude Model Context Protocol

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
MIT
Stars
131
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Read your local Apple Notes database and provide it to Claude Desktop.

Now Claude can search your most forgotten notes and know even more about you.

Noting could go wrong.

Components

Resources

The server implements the ability to read and write to your Apple Notes.

Tools

The server provides multiple prompts:

  • get-all-notes: Get all notes.
  • read-note: Get full content of a specific note.
  • search-notes: Search through notes.

Missing Features:

  • No handling of encrypted notes (ZISPASSWORDPROTECTED)
  • No support for pinned notes filtering
  • No handling of cloud sync status
  • Missing attachment content retrieval
  • No support for checklist status (ZHASCHECKLIST)
  • No ability to create or edit notes

Quickstart

Install the server

Recommend using uv to install the server locally for Claude.

uvx apple-notes-mcp

OR

uv pip install apple-notes-mcp

Add your config as described below.

Claude Desktop

On MacOS: ~/Library/Application\ Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json

Note: You might need to use the direct path to uv. Use which uv to find the path.

_Development/Unpublished Servers Configuration_

"mcpServers": {
"apple-notes-mcp": {
"command": "uv",
"args": [
"--directory",
"{project_dir}",
"run",
"apple-notes-mcp"
]
}
}

_Published Servers Configuration_

"mcpServers": {
"apple-notes-mcp": {
"command": "uvx",
"args": [
"apple-notes-mcp"
]
}
}

Mac OS Disk Permissions

You'll need to grant Full Disk Access to the server. This is because the Apple Notes sqlite database is nested deep in the MacOS file system.

I may look at an AppleScript solution in the future if this annoys me further or if I want to start adding/appending

Read from source at commit 9f5b579ad49aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add apple-notes-mcp -- uvx apple-notes-mcp
claude-desktop
{
  "mcpServers": {
    "apple-notes-mcp": {
      "command": "uvx",
      "args": [
        "apple-notes-mcp"
      ]
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
get-all-notesreadGet all notes
read-notereadGet full content of a specific note
search-notesreadSearch through notes
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 9f5b579ad49afull audit observations/trust-audit/mcp-server/sirmews__apple-notes-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-079f5b579ad49aSAFEB89first audit
06

Questions

What is the Apple Notes MCP server?

Read your Apple Notes with Claude Model Context Protocol

What tools does Apple Notes expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Apple Notes safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Apple Notes need?

No credential environment variables were found in its source, so it appears to need none.

How does Apple Notes run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as apple-notes-mcp.

How current is this page?

The grade is for one exact copy of the source (9f5b579ad49a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement