Apple NotesSAFE
Read your Apple Notes with Claude Model Context Protocol
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Read your local Apple Notes database and provide it to Claude Desktop.
Now Claude can search your most forgotten notes and know even more about you.
Noting could go wrong.
Components
Resources
The server implements the ability to read and write to your Apple Notes.
Tools
The server provides multiple prompts:
get-all-notes: Get all notes.read-note: Get full content of a specific note.search-notes: Search through notes.
Missing Features:
- No handling of encrypted notes (ZISPASSWORDPROTECTED)
- No support for pinned notes filtering
- No handling of cloud sync status
- Missing attachment content retrieval
- No support for checklist status (ZHASCHECKLIST)
- No ability to create or edit notes
Quickstart
Install the server
Recommend using uv to install the server locally for Claude.
uvx apple-notes-mcp
OR
uv pip install apple-notes-mcp
Add your config as described below.
Claude Desktop
On MacOS: ~/Library/Application\ Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json
Note: You might need to use the direct path to uv. Use which uv to find the path.
_Development/Unpublished Servers Configuration_
"mcpServers": {
"apple-notes-mcp": {
"command": "uv",
"args": [
"--directory",
"{project_dir}",
"run",
"apple-notes-mcp"
]
}
}_Published Servers Configuration_
"mcpServers": {
"apple-notes-mcp": {
"command": "uvx",
"args": [
"apple-notes-mcp"
]
}
}Mac OS Disk Permissions
You'll need to grant Full Disk Access to the server. This is because the Apple Notes sqlite database is nested deep in the MacOS file system.
I may look at an AppleScript solution in the future if this annoys me further or if I want to start adding/appending
9f5b579ad49aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add apple-notes-mcp -- uvx apple-notes-mcp
{
"mcpServers": {
"apple-notes-mcp": {
"command": "uvx",
"args": [
"apple-notes-mcp"
]
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get-all-notes | read | Get all notes |
read-note | read | Get full content of a specific note |
search-notes | read | Search through notes |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
9f5b579ad49afull audit observations/trust-audit/mcp-server/sirmews__apple-notes-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9f5b579ad49a | SAFE | B | 89 | first audit |
Questions
What is the Apple Notes MCP server?
Read your Apple Notes with Claude Model Context Protocol
What tools does Apple Notes expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Apple Notes safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Apple Notes need?
No credential environment variables were found in its source, so it appears to need none.
How does Apple Notes run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as apple-notes-mcp.
How current is this page?
The grade is for one exact copy of the source (9f5b579ad49a), read on 2026-10-07. The repository is watched and re-audited when it changes.