Atlas / MCP servers / veriteknik / Plugged.in

Plugged.inSAFE

mcp/veriteknik/plugged-in

Plugged.in MCP Server manages all your other MCPs in one MCP.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
32 22r · 8w · 2d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[!IMPORTANT] Project status (October 2026): open source, community-driven. plugged.in, the hosted service, is moving to a new, separately developed platform. After that move, this repository will no longer run plugged.in. The code stays open source under its current license, and the community is welcome to carry it on: issues, pull requests, forks and new maintainers are welcome, and self-hosting remains supported. The cutover date will be announced here. At the cutover, the current service moves to v1.plugged.in and keeps running there until December 31, 2026. What this means This client talks to the plugged.in API. Before the cutover we will release a version that points it to v1.plugged.in. After December 31, 2026, point it at your own pluggedin-app instance.

The Crossroads for AI Data Exchanges A unified MCP hub that gives your AI Knowledge, Memory, and Tools — not just a proxy. Manage and test all MCP servers from a single connection while powering document-aware and memory-augmented workflows across clients.

[](https://github.com/VeriTeknik/pluggedin-mcp/releases) [](https://github.com/VeriTeknik/pluggedin-mcp/stargazers) [](LICENSE) [](https://www.typescriptlang.org/) [![MCP](https://img.shields.io/badge/MCP-Compa

Read from source at commit 133799215d8eOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add pluggedin-mcp-proxy --env PLUGGEDIN_API_KEY=${PLUGGEDIN_API_KEY} --env REQUIRE_API_AUTH=${REQUIRE_API_AUTH} -- npx -y @pluggedin/[email protected]
claude-desktop
{
  "mcpServers": {
    "pluggedin-mcp-proxy": {
      "command": "npx",
      "args": [
        "-y",
        "@pluggedin/[email protected]"
      ],
      "env": {
        "PLUGGEDIN_API_KEY": "${PLUGGEDIN_API_KEY}",
        "REQUIRE_API_AUTH": "${REQUIRE_API_AUTH}"
      }
    }
  }
}
03

Exposed tools (32)

22 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
NotificationsreadYour Plugged.in notifications and activity feed
how_to_use_discoveryreadStep-by-step instructions for discovering and connecting to MCP servers
mcp_discoverreadComprehensive guide for discovering and using MCP tools in Plugged.in
pluggedin_ask_knowledge_basereadAsk questions and get AI-generated answers from your knowledge base. Returns structured JSON with answer, document sources, and metadata.
pluggedin_cbp_feedbackwriteSubmit feedback on a collective pattern to improve quality. Rate patterns as helpful, inaccurate, outdated, or dangerous.
pluggedin_cbp_queryreadQuery collective best practices - privacy-preserving patterns aggregated from the community. Use for proactive warnings before tool calls, post-error suggestions, or contextual enrichment.
pluggedin_clipboard_deletedestructiveDelete clipboard entries by name, index, or clear all entries.
pluggedin_clipboard_getreadGet clipboard entries. Specify name or idx for a single entry, or omit both to list all entries with pagination.
pluggedin_clipboard_listreadList all clipboard entries with metadata. Image values are truncated to first 1000 chars for preview.
pluggedin_clipboard_popreadPop the highest-indexed entry from the clipboard (LIFO behavior). Returns the entry value and removes it.
pluggedin_clipboard_pushwritePush a value to the indexed clipboard with auto-incrementing index. Useful for building ordered pipelines or stack-like operations.
pluggedin_clipboard_setwriteSet a clipboard entry by name (semantic key) or index (array-like). Named entries are upserted; indexed entries fail if index exists. Max 2MB per entry.
pluggedin_create_documentwriteCreate and save AI-generated documents to the user
pluggedin_delete_notificationdestructiveDelete a notification from the Plugged.in system
pluggedin_discover_toolsreadTriggers discovery of tools (and resources/templates) for configured MCP servers in the Pluggedin App.
pluggedin_get_documentreadRetrieve a specific document
pluggedin_list_documentsreadList documents with filtering options from the user
pluggedin_list_notificationsreadList notifications from the Plugged.in system with optional filters for unread only and result limit
pluggedin_mark_notification_donereadMark a notification as done in the Plugged.in system
pluggedin_memory_detailsreadGet full details for selected memories (progressive disclosure Layer 3). Use after pluggedin_memory_search to retrieve complete content for specific memories.
pluggedin_memory_individuationreadGet your individuation score — a measure of memory maturity (0-100). Shows Memory Depth, Learning Velocity, Collective Contribution, and Self-Awareness components with trend and personalized tips. Call with empty object {}.
pluggedin_memory_observereadRecord an observation during a memory session. Observations are classified by the Analytics Agent into memory ring types (procedures, practice, longterm, shocks).
pluggedin_memory_searchreadSearch memories using semantic similarity. Returns lightweight results (50-150 tokens each) for token-efficient progressive disclosure. Use pluggedin_memory_details for full content.
pluggedin_memory_search_with_contextreadSearch memories with archetype-enhanced collective intelligence. Returns both personal memories and collective patterns filtered through Shadow/Sage/Hero/Trickster archetypes based on context.
pluggedin_memory_session_endwriteEnd a memory session and trigger Z-report generation (AI-compressed session summary).
pluggedin_memory_session_startwriteStart a new memory session to begin capturing observations. Returns a session UUID and memory_session_id for subsequent operations.
pluggedin_proxy_capabilitiesreadLearn about the Plugged.in MCP Proxy capabilities and available tools
pluggedin_search_documentsreadSearch for specific documents in your library. Returns document metadata (ID, title, snippet). To retrieve full content, use pluggedin_get_document with the returned document ID.
pluggedin_send_notificationwriteSend custom notifications through the Plugged.in system with optional email delivery. You can provide a custom title or let the system use a localized default.
pluggedin_setupreadGet started with Plugged.in MCP - shows setup instructions and API key configuration (no API key required)
pluggedin_update_documentwriteUpdate or append to an existing AI-generated document (requires API key)
what_pluggedin_can_do_for_mereadDiscover all the powerful features and tools Plugged.in offers to enhance your AI workflows
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
pluggedin_clipboard_delete, pluggedin_delete_notification
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.local.example
.env.local.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.production.local.example
.env.production.local.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/utils/prompts.ts:6
const packageJson = require('../../package.json');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/deepsec-c-proxy.test.ts:79
`${NOTIFICATION_ID}/../../documents/x`,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/deepsec-c-static-handlers.test.ts:27
`${NOTIFICATION_ID}/../../documents/x`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:334
| `MCP_ALLOWED_ORIGINS` | Streamable HTTP: comma-separated browser origins allowed to call the MCP endpoint (requests from other origins get 403; requests without an `Origin` header are unaffected). `
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/deepsec-b-base-url-resolution.test.ts:112
expect(getPluggedinMCPApiBaseUrl('http://192.168.1.10:12005')).toBeUndefined();
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/deepsec-b-validate-api-url.test.ts:15
'http://127.0.0.1:12005',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/deepsec-b-validate-api-url.test.ts:24
'http://192.168.1.10:12005',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/deepsec-b-validate-api-url.test.ts:26
'http://127.0.0.1.attacker.example',
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, commander, express, quick-lru, sanitize-html, slugify, zod, zod-to-json-schema
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
scripts/README.md:44
All scripts load environment variables from `.env.local`:
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 133799215d8efull audit observations/trust-audit/mcp-server/veriteknik__plugged-in.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08133799215d8eSAFEB89first audit
06

Questions

What is the Plugged.in MCP server?

Plugged.in MCP Server manages all your other MCPs in one MCP.

What tools does Plugged.in expose?

32 in total: 22 read-only, 8 that write, and 2 that can delete or overwrite (pluggedin_clipboard_delete, pluggedin_delete_notification). Every one is listed on this page with its risk.

Is Plugged.in safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Plugged.in need?

It reads PLUGGEDIN_API_KEY and REQUIRE_API_AUTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Plugged.in run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @pluggedin/pluggedin-mcp-proxy at 3.0.0.

How current is this page?

The grade is for one exact copy of the source (133799215d8e), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement