Atlas / MCP servers / theeaglebyte / Skylight

SkylightCAUTION

mcp/theeaglebyte/skylight

MCP server for Skylight family calendar - enables AI assistants to manage calendars, chores, lists, meals, and rewards

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
40 19r · 15w · 6d
Transport
stdio
License
MIT
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server for the Skylight Calendar API. Enables AI assistants like Claude to interact with your Skylight family calendar, chores, lists, and more.

Features

  • Calendar: Query calendar events ("What's on my calendar today?")
  • Chores: View and create chores ("Add emptying dishwasher to chores")
  • Lists: View grocery and to-do lists ("What's on the grocery list?")
  • Tasks: Add items to the task box ("Add XYZ to my task list")
  • Family: View family members and devices
  • Rewards: Check reward points and available rewards

Quick Start

Installation

Option 1: npm package (Recommended)

mcp.json:

{
"mcpServers": {
"skylight": {
"command": "npx",
"args": ["@eaglebyte/skylight-mcp"],
"env": {
"SKYLIGHT_EMAIL": "[email protected]",
"SKYLIGHT_PASSWORD": "your_password",
"SKYLIGHT_FRAME_ID": "your_frame_id"
}
}
}
}

Claude Code:

claude mcp add skylight npx @eaglebyte/skylight-mcp \
-e [email protected] \
-e SKYLIGHT_PASSWORD=your_password \
-e SKYLIGHT_FRAME_ID=your_frame_id

Option 2: From source

git clone https://github.com/TheEagleByte/skylight-mcp.git
cd skylight-mcp && npm install && npm run build

Then use in mcp.json:

{
"mcpServers": {
"skylight": {
"command": "node",
"args": ["/path/to/skylight-mcp/dist/index.js"],
"env": {
"SKYLIGHT_EMAIL": "[email protected]",
"SKYLIGHT_PASSWORD": "your_password",
"SKYLIGHT_FRAME_ID": "your_frame_id"
}
}
}
}

Instructions for AI

Copy this into your AI's custom instructions or system prompt:

You have access to the Skylight MCP server. Skylight is a smart family calendar display that shows calendars, chores, grocery lists, meals, and rewards. Use the Skylight tools to help manage family schedules and organization. Tips
Read from source at commit 6d172be65630OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add skylight-mcp --env SKYLIGHT_AUTH_TYPE=${SKYLIGHT_AUTH_TYPE} --env SKYLIGHT_PASSWORD=${SKYLIGHT_PASSWORD} --env SKYLIGHT_TOKEN=${SKYLIGHT_TOKEN} -- npx -y @eaglebyte/[email protected]
claude-desktop
{
  "mcpServers": {
    "skylight-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@eaglebyte/[email protected]"
      ],
      "env": {
        "SKYLIGHT_AUTH_TYPE": "${SKYLIGHT_AUTH_TYPE}",
        "SKYLIGHT_PASSWORD": "${SKYLIGHT_PASSWORD}",
        "SKYLIGHT_TOKEN": "${SKYLIGHT_TOKEN}"
      }
    }
  }
}
03

Exposed tools (40)

19 read · 15 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_recipe_to_grocery_listwriteAdd a recipe
create_calendar_eventwriteCreate a new calendar event in Skylight. Use this when: - Scheduling a new event:
create_chorewriteAdd a new chore to Skylight. Use this when the user wants to: - Add a new task like
create_listwriteCreate a new list in Skylight. Use this when: - Creating a new shopping/grocery list - Creating a new to-do list Parameters: - label (required): Name of the list (e.g.,
create_list_itemwriteAdd an item to a Skylight list. Use this when: - Adding something to the grocery list:
create_meal_sittingwrite
create_recipewrite
create_rewardwriteCreate a new reward that can be redeemed with points (Plus subscription required). Use this when: - Adding a new reward:
create_taskwriteAdd a task to the Skylight task box. The task box holds unscheduled tasks that can later be assigned to specific dates. Use this when the user says: -
delete_calendar_eventdestructiveDelete a calendar event from Skylight. Use this when: - Canceling an event:
delete_choredestructive
delete_listdestructive
delete_list_itemdestructive
delete_recipedestructiveDelete a recipe - Plus subscription required. Parameters: - recipeId (required): ID of the recipe to delete Note: This permanently removes the recipe.
delete_rewarddestructiveDelete a reward (Plus subscription required). Use this when: - Removing an old reward - Cleaning up unused rewards Parameters: - rewardId (required): ID of the reward to delete (from get_rewards) Note: This permanently removes the reward.
get_albumsreadGet photo albums from Skylight - Plus subscription required. Use this when: - Viewing available photo albums - Getting album IDs for photo management Returns: List of photo albums with their IDs.
get_avatarsreadGet available avatar options for Skylight profiles. Use this when: - Setting up a new family member profile - Changing someone
get_calendar_eventsreadGet calendar events from Skylight. Use this to answer questions like: -
get_choresreadGet chores from Skylight. Use this to answer: -
get_colorsreadGet available color options for Skylight profiles and lists. Use this when: - Choosing a color for a family member profile - Setting a list color - Exploring available color options Returns: List of available colors with their IDs and hex values.
get_devicesreadList Skylight devices in the household. Use this to answer: -
get_family_membersreadGet family members/profiles from Skylight. Shows who can be assigned chores and their profile details. Use this to answer: -
get_frame_inforeadGet Skylight household/frame information. Useful for setup verification and debugging. Use this to answer: -
get_list_itemsreadGet items from a specific Skylight list. Use this to answer: -
get_listsreadGet all lists from Skylight (grocery lists, to-do lists, etc.). Use this to see what lists are available before adding items. Returns list names, types (shopping/to_do), and item counts.
get_meal_categoriesreadGet meal categories (Breakfast, Lunch, Dinner, etc.) - Plus subscription required. Use this when: - Finding category IDs for scheduling meals - Seeing what meal times are available Returns: List of meal categories with IDs.
get_meal_sittingsreadGet scheduled meals for a date range - Plus subscription required. Use this when: - Viewing the meal plan for the week - Checking what
get_recipereadGet details for a specific recipe - Plus subscription required. Parameters: - recipeId (required): ID of the recipe Returns: Recipe details including description.
get_recipesreadGet all saved recipes - Plus subscription required. Use this when: - Browsing available recipes - Finding a recipe ID for meal planning Returns: List of recipes with their details.
get_reward_pointsreadGet reward points balance for family members. Shows how many reward points each family member has earned. Use this to answer: -
get_rewardsreadGet available rewards that can be redeemed with reward points. For family gamification - shows rewards that family members can earn. Use this to answer: -
get_source_calendarsreadGet connected calendar sources synced to Skylight. Use this to answer: -
redeem_rewardreadRedeem a reward using points (Plus subscription required). Use this when: - A family member wants to cash in points:
unredeem_rewardreadCancel a reward redemption (Plus subscription required). Use this when: - A redemption was made by mistake - Undoing a reward claim Parameters: - rewardId (required): ID of the reward to unredeem Returns: The unredeemed reward details.
update_calendar_eventwriteUpdate an existing calendar event. Use this when: - Changing event time:
update_chorewriteUpdate an existing chore in Skylight. Use this when: - Marking a chore as complete:
update_listwriteUpdate an existing list
update_list_itemwriteUpdate a list item (mark complete, rename, move to section). Use this when: - Marking an item as complete:
update_recipewriteUpdate an existing recipe - Plus subscription required. Parameters: - recipeId (required): ID of the recipe - summary: New name - description: New description Returns: The updated recipe.
update_rewardwriteUpdate an existing reward (Plus subscription required). Use this when: - Changing point value:
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/api/generated-types.ts:12006
emoji_icon?: "🐻❄️" | "🐾" | "😀" | null;
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_calendar_event, delete_chore, delete_list, delete_list_item, delete_recipe, delete_reward
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintrc.cjs
.eslintrc.cjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript, tsx, vitest, eslint, @typescript-eslint/eslint-plugin
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CLAUDE.md:36
- `api/auth.ts` - Login endpoint for email/password authentication
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CLAUDE.md:44
1. **Email/Password** (recommended): Set `SKYLIGHT_EMAIL` and `SKYLIGHT_PASSWORD`. Server auto-logs in via POST /api/sessions and uses `Basic base64(userId:token)` format for subsequent requests.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6d172be65630full audit observations/trust-audit/mcp-server/theeaglebyte__skylight.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086d172be65630CAUTIONB89first audit
06

Questions

What is the Skylight MCP server?

MCP server for Skylight family calendar - enables AI assistants to manage calendars, chores, lists, meals, and rewards

What tools does Skylight expose?

40 in total: 19 read-only, 15 that write, and 6 that can delete or overwrite (delete_calendar_event, delete_chore, delete_list, delete_list_item, delete_recipe). Every one is listed on this page with its risk.

Is Skylight safe to connect to an agent?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Skylight need?

It reads SKYLIGHT_AUTH_TYPE, SKYLIGHT_PASSWORD and SKYLIGHT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Skylight run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @eaglebyte/skylight-mcp at 1.1.7.

How current is this page?

The grade is for one exact copy of the source (6d172be65630), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement