Atlas / MCP servers / southleft / Company Docs

Company DocsSAFE

mcp/southleft/company-docs

AI-powered company knowledge MCP. Unified place for internal policies, values, documentation, and governance. Agents can search, cite, and answer questions using real company docs.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
—
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Turn any documentation into an AI-searchable knowledge base. Feed it markdown, HTML, PDFs, web pages, or plain text — publish to a database and let anyone on your team query it through AI tools like Claude, Cursor, or Slack. Powered by the Model Context Protocol.

What This Does

  1. Ingest — Point the CLI at your content. It accepts markdown files, HTML pages, PDFs, live URLs, or even an entire website via crawl.
  2. Publish — Run a command that converts your content into searchable vectors and stores it in a database.
  3. Query — Connect any MCP-compatible AI tool to your server. Ask questions in plain English and get answers sourced directly from your documentation.

Two Ways to Use This

There are two distinct roles when working with Company Docs MCP. Most people on your team only need the first one.

If someone already set up the server for your team

You just need a URL. No accounts, no installation, no terminal commands.

  1. Get the server URL from whoever set it up (it looks like https://company-docs-mcp.example.workers.dev/mcp)
  2. Add it to your AI tool:
  3. Claude: Settings > Connectors > Add custom connector > paste the URL
  4. Cursor / Windsurf: Add the URL as a remote MCP server in settings
  5. Start asking questions about your documentation

That's it. Cloudflare, Supabase, and the CLI are only needed by the person who sets up and maintains the server.

If you're setting up the server (admin/maintainer)

The rest of this README is for you. Follow the setup guide below to get everything running.

How the Pieces Fit Together

The system uses three services. All three offer free tiers that are sufficient for most teams.

flowchart TD
A["Your ContentMarkdown, HTML, PDFs, URLs"]
B["Cloudflare Workers AI"]
C[("Supabase")]
D["Your TeamClaude, Cursor, Slack, Chat UI"]
E["Cloudflare Worker"]

A -- "ingest + publish" --> B
Read from source at commit 458eefa75b57OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add company-docs-mcp --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env SLACK_APP_TOKEN=${SLACK_APP_TOKEN} --env SLACK_BOT_TOKEN=${SLACK_BOT_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "company-docs-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "SLACK_APP_TOKEN": "${SLACK_APP_TOKEN}",
        "SLACK_BOT_TOKEN": "${SLACK_BOT_TOKEN}"
      }
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
browse_by_categoryreadBrowse all entries in a specific category
get_all_tagsreadGet a list of all available tags in the knowledge base
search_chunksreadSearch through specific content chunks for detailed information
search_documentationreadSearch through the documentation knowledge base by query, category, or tags
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (8)

MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
QUICKSTART.md:178
echo "xoxb-your-bot-token" | npx wrangler secret put SLACK_BOT_TOKEN
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/ingest/csv-url-parser.ts:7
import { ContentEntry, ContentMetadata, Category } from "../../src/lib/content";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/ingest/csv-url-parser.ts:9
import { generateId } from "../../src/lib/id-generator";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/ingest/html-parser.ts:5
import { ContentEntry, ContentMetadata, SourceType } from "../../src/lib/content";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/ingest/html-parser.ts:6
import { chunkBySection } from "../../src/lib/chunker";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/ingest/html-parser.ts:7
import { generateId } from "../../src/lib/id-generator";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @supabase/supabase-js, dotenv, openai, zod, zod-to-json-schema, @anthropic-ai/sdk, @biomejs/biome
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/DEPLOYMENT.md:194
| `SUPABASE_SERVICE_KEY` | Supabase service role key (full access) | Yes |

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 458eefa75b57full audit observations/trust-audit/mcp-server/southleft__company-docs.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08458eefa75b57SAFEB89first audit
06

Questions

What is the Company Docs MCP server?

AI-powered company knowledge MCP. Unified place for internal policies, values, documentation, and governance. Agents can search, cite, and answer questions using real company docs.

What tools does Company Docs expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Company Docs safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Company Docs need?

It reads CLOUDFLARE_API_TOKEN, OPENAI_API_KEY, SLACK_APP_TOKEN, SLACK_BOT_TOKEN, SLACK_SIGNING_SECRET and SUPABASE_SERVICE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (458eefa75b57), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement