Atlas / MCP servers / yuna0x0 / HackMD

HackMDSAFE

mcp/yuna0x0/hackmd

A Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 6r · 4w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
68
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that interfaces with the HackMD API, allowing LLM clients to access and interact with HackMD notes, teams, user profiles, and history data.

Features

  • Get user profile information
  • Create, read, update, and delete notes
  • Manage team notes and collaborate with team members
  • Access reading history
  • List and manage teams
  • Dual transport support: Both HTTP and STDIO transports
  • Cloud deployment ready: Support Smithery and other platforms

Requirements

  • Node.js 18+

Local Installation (STDIO Transport)

  1. Add this server to your mcp.json / claude_desktop_config.json:
{
"mcpServers": {
"hackmd": {
"command": "npx",
"args": ["-y", "hackmd-mcp"],
"env": {
"HACKMD_API_TOKEN": "your_api_token"
}
}
}
}

You may also optionally set the HACKMD_API_URL environment variable if you need to use a different HackMD API endpoint.

  1. Restart your MCP client (e.g., Claude Desktop)
  2. Use the tools to interact with HackMD

Server Deployment (HTTP Transport)

Self-Hosting

Follow the Local Development instructions to set up the project locally, then run:

pnpm run start:http

This will start the server on port 8081 by default. You can change the port by setting the PORT environment variable.

Cloud Deployment

You can deploy this MCP server to any cloud platform that supports Node.js server applications.

You can also deploy via MCP platforms like Smithery.

Configuration

Environment Variables (STDIO Transport and HTTP Transport server where host provides the config)

When using the STDIO transport or hosting the HTTP transport server, you can pass configuration via environment variables:

  • HACKMD_API_TOKEN: HackMD API Token (Required for all operations)
  • HACKMD_API_URL: (Optional) HackMD
Read from source at commit 56abe3102632OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add hackmd-mcp --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} -- npx -y [email protected]
claude-code (oci)
claude mcp add hackmd-mcp:1.5.7 --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} --env HACKMD_API_TOKEN=${HACKMD_API_TOKEN} -- docker run -i --rm ghcr.io/yuna0x0/hackmd-mcp:1.5.7:None
03

Exposed tools (12)

6 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_notewriteCreate a new note
create_team_notewriteCreate a new note in a team
delete_notedestructiveDelete a note
delete_team_notedestructiveDelete a note in a team
get_historyreadGet user
get_notereadGet a note by its ID
get_user_inforeadGet information about the authenticated user
list_team_notesreadList all notes in a team
list_teamsreadList all teams accessible to the user
list_user_notesreadList all notes owned by the user
update_notewriteUpdate an existing note
update_team_notewriteUpdate an existing note in a team
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_note, delete_team_note
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@hackmd/api, @modelcontextprotocol/sdk, cors, dotenv, express, zod, @anthropic-ai/mcpb, @modelcontextprotocol/inspector
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 56abe3102632full audit observations/trust-audit/mcp-server/yuna0x0__hackmd.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0756abe3102632SAFEB89first audit
06

Questions

What is the HackMD MCP server?

A Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants.

What tools does HackMD expose?

12 in total: 6 read-only, 4 that write, and 2 that can delete or overwrite (delete_note, delete_team_note). Every one is listed on this page with its risk.

Is HackMD safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does HackMD need?

It reads HACKMD_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does HackMD run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as hackmd-mcp at 1.5.7.

How current is this page?

The grade is for one exact copy of the source (56abe3102632), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement