SkylightCAUTION
MCP server for Skylight family calendar - enables AI assistants to manage calendars, chores, lists, meals, and rewards
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server for the Skylight Calendar API. Enables AI assistants like Claude to interact with your Skylight family calendar, chores, lists, and more.
Features
- Calendar: Query calendar events ("What's on my calendar today?")
- Chores: View and create chores ("Add emptying dishwasher to chores")
- Lists: View grocery and to-do lists ("What's on the grocery list?")
- Tasks: Add items to the task box ("Add XYZ to my task list")
- Family: View family members and devices
- Rewards: Check reward points and available rewards
Quick Start
Installation
Option 1: npm package (Recommended)
mcp.json:
{
"mcpServers": {
"skylight": {
"command": "npx",
"args": ["@eaglebyte/skylight-mcp"],
"env": {
"SKYLIGHT_EMAIL": "[email protected]",
"SKYLIGHT_PASSWORD": "your_password",
"SKYLIGHT_FRAME_ID": "your_frame_id"
}
}
}
}Claude Code:
claude mcp add skylight npx @eaglebyte/skylight-mcp \ -e [email protected] \ -e SKYLIGHT_PASSWORD=your_password \ -e SKYLIGHT_FRAME_ID=your_frame_id
Option 2: From source
git clone https://github.com/TheEagleByte/skylight-mcp.git cd skylight-mcp && npm install && npm run build
Then use in mcp.json:
{
"mcpServers": {
"skylight": {
"command": "node",
"args": ["/path/to/skylight-mcp/dist/index.js"],
"env": {
"SKYLIGHT_EMAIL": "[email protected]",
"SKYLIGHT_PASSWORD": "your_password",
"SKYLIGHT_FRAME_ID": "your_frame_id"
}
}
}
}Instructions for AI
Copy this into your AI's custom instructions or system prompt:
You have access to the Skylight MCP server. Skylight is a smart family calendar display that shows calendars, chores, grocery lists, meals, and rewards. Use the Skylight tools to help manage family schedules and organization. Tips
6d172be65630OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add skylight-mcp --env SKYLIGHT_AUTH_TYPE=${SKYLIGHT_AUTH_TYPE} --env SKYLIGHT_PASSWORD=${SKYLIGHT_PASSWORD} --env SKYLIGHT_TOKEN=${SKYLIGHT_TOKEN} -- npx -y @eaglebyte/[email protected]{
"mcpServers": {
"skylight-mcp": {
"command": "npx",
"args": [
"-y",
"@eaglebyte/[email protected]"
],
"env": {
"SKYLIGHT_AUTH_TYPE": "${SKYLIGHT_AUTH_TYPE}",
"SKYLIGHT_PASSWORD": "${SKYLIGHT_PASSWORD}",
"SKYLIGHT_TOKEN": "${SKYLIGHT_TOKEN}"
}
}
}
}Exposed tools (40)
19 read · 15 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_recipe_to_grocery_list | write | Add a recipe |
create_calendar_event | write | Create a new calendar event in Skylight. Use this when: - Scheduling a new event: |
create_chore | write | Add a new chore to Skylight. Use this when the user wants to: - Add a new task like |
create_list | write | Create a new list in Skylight. Use this when: - Creating a new shopping/grocery list - Creating a new to-do list Parameters: - label (required): Name of the list (e.g., |
create_list_item | write | Add an item to a Skylight list. Use this when: - Adding something to the grocery list: |
create_meal_sitting | write | |
create_recipe | write | |
create_reward | write | Create a new reward that can be redeemed with points (Plus subscription required). Use this when: - Adding a new reward: |
create_task | write | Add a task to the Skylight task box. The task box holds unscheduled tasks that can later be assigned to specific dates. Use this when the user says: - |
delete_calendar_event | destructive | Delete a calendar event from Skylight. Use this when: - Canceling an event: |
delete_chore | destructive | |
delete_list | destructive | |
delete_list_item | destructive | |
delete_recipe | destructive | Delete a recipe - Plus subscription required. Parameters: - recipeId (required): ID of the recipe to delete Note: This permanently removes the recipe. |
delete_reward | destructive | Delete a reward (Plus subscription required). Use this when: - Removing an old reward - Cleaning up unused rewards Parameters: - rewardId (required): ID of the reward to delete (from get_rewards) Note: This permanently removes the reward. |
get_albums | read | Get photo albums from Skylight - Plus subscription required. Use this when: - Viewing available photo albums - Getting album IDs for photo management Returns: List of photo albums with their IDs. |
get_avatars | read | Get available avatar options for Skylight profiles. Use this when: - Setting up a new family member profile - Changing someone |
get_calendar_events | read | Get calendar events from Skylight. Use this to answer questions like: - |
get_chores | read | Get chores from Skylight. Use this to answer: - |
get_colors | read | Get available color options for Skylight profiles and lists. Use this when: - Choosing a color for a family member profile - Setting a list color - Exploring available color options Returns: List of available colors with their IDs and hex values. |
get_devices | read | List Skylight devices in the household. Use this to answer: - |
get_family_members | read | Get family members/profiles from Skylight. Shows who can be assigned chores and their profile details. Use this to answer: - |
get_frame_info | read | Get Skylight household/frame information. Useful for setup verification and debugging. Use this to answer: - |
get_list_items | read | Get items from a specific Skylight list. Use this to answer: - |
get_lists | read | Get all lists from Skylight (grocery lists, to-do lists, etc.). Use this to see what lists are available before adding items. Returns list names, types (shopping/to_do), and item counts. |
get_meal_categories | read | Get meal categories (Breakfast, Lunch, Dinner, etc.) - Plus subscription required. Use this when: - Finding category IDs for scheduling meals - Seeing what meal times are available Returns: List of meal categories with IDs. |
get_meal_sittings | read | Get scheduled meals for a date range - Plus subscription required. Use this when: - Viewing the meal plan for the week - Checking what |
get_recipe | read | Get details for a specific recipe - Plus subscription required. Parameters: - recipeId (required): ID of the recipe Returns: Recipe details including description. |
get_recipes | read | Get all saved recipes - Plus subscription required. Use this when: - Browsing available recipes - Finding a recipe ID for meal planning Returns: List of recipes with their details. |
get_reward_points | read | Get reward points balance for family members. Shows how many reward points each family member has earned. Use this to answer: - |
get_rewards | read | Get available rewards that can be redeemed with reward points. For family gamification - shows rewards that family members can earn. Use this to answer: - |
get_source_calendars | read | Get connected calendar sources synced to Skylight. Use this to answer: - |
redeem_reward | read | Redeem a reward using points (Plus subscription required). Use this when: - A family member wants to cash in points: |
unredeem_reward | read | Cancel a reward redemption (Plus subscription required). Use this when: - A redemption was made by mistake - Undoing a reward claim Parameters: - rewardId (required): ID of the reward to unredeem Returns: The unredeemed reward details. |
update_calendar_event | write | Update an existing calendar event. Use this when: - Changing event time: |
update_chore | write | Update an existing chore in Skylight. Use this when: - Marking a chore as complete: |
update_list | write | Update an existing list |
update_list_item | write | Update a list item (mark complete, rename, move to section). Use this when: - Marking an item as complete: |
update_recipe | write | Update an existing recipe - Plus subscription required. Parameters: - recipeId (required): ID of the recipe - summary: New name - description: New description Returns: The updated recipe. |
update_reward | write | Update an existing reward (Plus subscription required). Use this when: - Changing point value: |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
emoji_icon?: "🐻❄️" | "🐾" | "😀" | null;
delete_calendar_event, delete_chore, delete_list, delete_list_item, delete_recipe, delete_reward
.eslintrc.cjs
@modelcontextprotocol/sdk, zod, @types/node, typescript, tsx, vitest, eslint, @typescript-eslint/eslint-plugin
- `api/auth.ts` - Login endpoint for email/password authentication
1. **Email/Password** (recommended): Set `SKYLIGHT_EMAIL` and `SKYLIGHT_PASSWORD`. Server auto-logs in via POST /api/sessions and uses `Basic base64(userId:token)` format for subsequent requests.
Gates applied: no_behavioural_pass.
6d172be65630full audit observations/trust-audit/mcp-server/theeaglebyte__skylight.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 6d172be65630 | CAUTION | B | 89 | first audit |
Questions
What is the Skylight MCP server?
MCP server for Skylight family calendar - enables AI assistants to manage calendars, chores, lists, meals, and rewards
What tools does Skylight expose?
40 in total: 19 read-only, 15 that write, and 6 that can delete or overwrite (delete_calendar_event, delete_chore, delete_list, delete_list_item, delete_recipe). Every one is listed on this page with its risk.
Is Skylight safe to connect to an agent?
With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Skylight need?
It reads SKYLIGHT_AUTH_TYPE, SKYLIGHT_PASSWORD and SKYLIGHT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Skylight run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @eaglebyte/skylight-mcp at 1.1.7.
How current is this page?
The grade is for one exact copy of the source (6d172be65630), read on 2026-10-08. The repository is watched and re-audited when it changes.