HackMDSAFE
A Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that interfaces with the HackMD API, allowing LLM clients to access and interact with HackMD notes, teams, user profiles, and history data.
Features
- Get user profile information
- Create, read, update, and delete notes
- Manage team notes and collaborate with team members
- Access reading history
- List and manage teams
- Dual transport support: Both HTTP and STDIO transports
- Cloud deployment ready: Support Smithery and other platforms
Requirements
- Node.js 18+
Local Installation (STDIO Transport)
- Add this server to your
mcp.json/claude_desktop_config.json:
{
"mcpServers": {
"hackmd": {
"command": "npx",
"args": ["-y", "hackmd-mcp"],
"env": {
"HACKMD_API_TOKEN": "your_api_token"
}
}
}
}You may also optionally set the HACKMD_API_URL environment variable if you need to use a different HackMD API endpoint.
- Restart your MCP client (e.g., Claude Desktop)
- Use the tools to interact with HackMD
Server Deployment (HTTP Transport)
Self-Hosting
Follow the Local Development instructions to set up the project locally, then run:
pnpm run start:http
This will start the server on port 8081 by default. You can change the port by setting the PORT environment variable.
Cloud Deployment
You can deploy this MCP server to any cloud platform that supports Node.js server applications.
You can also deploy via MCP platforms like Smithery.
Configuration
Environment Variables (STDIO Transport and HTTP Transport server where host provides the config)
When using the STDIO transport or hosting the HTTP transport server, you can pass configuration via environment variables:
HACKMD_API_TOKEN: HackMD API Token (Required for all operations)HACKMD_API_URL: (Optional) HackMD
56abe3102632OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add hackmd-mcp --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} -- npx -y [email protected]claude mcp add hackmd-mcp:1.5.7 --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} -- docker run -i --rm ghcr.io/yuna0x0/hackmd-mcp:1.5.7:NoneExposed tools (12)
6 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_note | write | Create a new note |
create_team_note | write | Create a new note in a team |
delete_note | destructive | Delete a note |
delete_team_note | destructive | Delete a note in a team |
get_history | read | Get user |
get_note | read | Get a note by its ID |
get_user_info | read | Get information about the authenticated user |
list_team_notes | read | List all notes in a team |
list_teams | read | List all teams accessible to the user |
list_user_notes | read | List all notes owned by the user |
update_note | write | Update an existing note |
update_team_note | write | Update an existing note in a team |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
delete_note, delete_team_note
@hackmd/api, @modelcontextprotocol/sdk, cors, dotenv, express, zod, @anthropic-ai/mcpb, @modelcontextprotocol/inspector
Gates applied: no_behavioural_pass.
56abe3102632full audit observations/trust-audit/mcp-server/yuna0x0__hackmd.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 56abe3102632 | SAFE | B | 89 | first audit |
Questions
What is the HackMD MCP server?
A Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants.
What tools does HackMD expose?
12 in total: 6 read-only, 4 that write, and 2 that can delete or overwrite (delete_note, delete_team_note). Every one is listed on this page with its risk.
Is HackMD safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does HackMD need?
It reads HACKMD_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does HackMD run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as hackmd-mcp at 1.5.7.
How current is this page?
The grade is for one exact copy of the source (56abe3102632), read on 2026-10-07. The repository is watched and re-audited when it changes.