Atlas / MCP servers / vortiago / Outline Connector

Outline ConnectorCAUTION

mcp/vortiago/outline-connector

A Model Context Protocol (MCP) server enabling AI assistants to interact with Outline documentation services.

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
1 1r · 0w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
156
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

## 📢 Official Outline MCP Server Available Outline now ships an official MCP server — we recommend using it. Read the docs.

[](https://pypi.org/project/mcp-outline/) [](https://www.python.org/downloads/) [](LICENSE) [](https://github.com/Vortiago/mcp-outline/actions/workflows/ci.yml) [](https://github.com/Vortiago/mcp-outline/pkgs/container/mcp-outline)

A Model Context Protocol server for interacting with Outline document management.

Features

  • Document operations: Search, read, create, edit, archive documents
  • Collections: List, create, manage document hierarchies
  • Comments: Add and view threaded comments
  • Backlinks: Find documents referencing a specific document
  • MCP Resources: Direct content access via URIs (outline://document/{id}, outline://collection/{id}, etc.)
  • Automatic rate limiting: Transparent handling of API limits with retry logic

Prerequisites

Before using this MCP server, you need:

  • An Outline account (cloud hosted or self-hosted)
  • API key from Outline web UI: Settings → API Keys → Create New
  • Python 3.10+ (for non-Docker installations)
Getting your API key: Log into Outline → Click your profile → Settings → API Keys → "New API Key". Copy the generated token.

Quick Start

One-Click Install

Click a button to install with interactive API key prompt:

[](https://vs

Read from source at commit 5bf577a8cf2aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add mcp-outline --env OUTLINE_API_KEY=${OUTLINE_API_KEY} -- uvx mcp-outline==1.10.1
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
bad_toolreadTool with invalid min_role.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (16)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
config/outline.env.example:26
DATABASE_URL=postgres://outline:outline@postgres:5432/outline
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.dev.json
.mcp.dev.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/e2e/conftest.py:209
callback_url = _require_redirect(resp, "Dex login POST")
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/e2e/conftest.py:214
callback_url,
LOWNetwork egress · net.env_exfil · CWE-200, CWE-319
tests/e2e/test_dynamic_tool_list.py:153
os.environ.items() ... httpx.
Why it matters. reads secrets in the same file that sends data out
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2e/test_api_key_header.py:29
E2E_BASE = f"http://127.0.0.1:{E2E_PORT}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2e/test_dynamic_tool_list.py:52
HTTP_BASE = f"http://127.0.0.1:{HTTP_PORT}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_health.py:22
HEALTH_BASE = f"http://127.0.0.1:{HEALTH_PORT}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_health.py:106
api_url="http://192.0.2.1:1/api",
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:47
[![Install in Cursor](https://img.shields.io/badge/Install_in-Cursor-000000?style=flat-square&logoColor=white)](https://cursor.com/en/install-mcp?name=mcp-outline&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncy
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/client-setup.md:28
**One-click install**: [![Install in Cursor](https://img.shields.io/badge/Install_in-Cursor-000000?style=flat-square&logoColor=white)](https://cursor.com/en/install-mcp?name=mcp-outline&config=eyJjb21
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/configuration.md:50
When running in HTTP mode (`sse` or `streamable-http`), multiple users can share a single MCP server, each authenticating with their own Outline API key.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
tests/e2e/conftest.md:4
OI["GET /auth/oidc\nstart OIDC flow"] --> DC["Dex: submit credentials\[email protected] / admin"]
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/dynamic-tool-list.md:97
G -->|"null (full access)"| D
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/dynamic-tool-list.md:106
**last4 collision**: if multiple keys share the same last 4 digits, their scopes are unioned. If any matching key has `scope: null` (full access), the result is treated as full access.

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 5bf577a8cf2afull audit observations/trust-audit/mcp-server/vortiago__outline-connector.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-075bf577a8cf2aCAUTIONB83first audit
06

Questions

What is the Outline Connector MCP server?

A Model Context Protocol (MCP) server enabling AI assistants to interact with Outline documentation services.

What tools does Outline Connector expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Outline Connector safe to connect to an agent?

With care. The audit graded it B (83/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Outline Connector need?

It reads OUTLINE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Outline Connector run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-outline.

How current is this page?

The grade is for one exact copy of the source (5bf577a8cf2a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement