Atlas / Skills / jeremylongshore / Granola Local Dev Loop

Granola Local Dev LoopSAFE

skills/jeremylongshore/granola-local-dev-loop

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.13.0
Hosts
2 documented
License
MIT
Stars
2,823
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
cursormentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: granola-local-dev-loop
description: 'Access Granola meeting data programmatically for developer workflows.

  Use when reading notes from the local cache, building MCP integrations,

  extracting action items into code, or syncing meeting outcomes to dev tools.

  Trigger: "granola dev workflow", "granola MCP", "granola local cache",

  "granola developer", "granola programmatic".

  '
allowed-tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Grep
version: 1.13.0
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- granola
- workflow
- developer
compatibility: Designed for Claude Code
---
# Granola Local Dev Loop

## Overview

Access Granola meeting data programmatically using three methods: the local cache file (zero-auth, offline), the MCP server (AI agent integration), or the Enterprise API (workspace-wide access). Build developer workflows that turn meeting outcomes into code tasks, documentation, and project artifacts.

## Prerequisites

- Granola installed with meetings captured
- Node.js 18+ or Python 3.10+ for scripts
- For MCP: Claude Code, Cursor, or another MCP-compatible client
- For Enterprise API: Business/Enterprise plan + API key

## Instructions

### Step 1 — Read the Local Cache (Zero Auth)

Granola stores meeting data in a local JSON cache file:

```bash
# macOS cache location
CACHE_FILE="$HOME/Library/Application Support/Granola/cache-v3.json"

# Check if cache exists and get size
ls -lh "$CACHE_FILE"
```

The cache has a double-JSON structure (JSON string inside JSON):

```python
#!/usr/bin/env python3
"""Extract meetings from Granola local cache."""
import json
from pathlib import Path

CACHE_PATH = Path.home() / "Library/Application Support/Granola/cache-v3.json"

def load_granola_cache():
    raw = json.loads(CACHE_PATH.read_text())
    # Cache contains a JSON string that needs secondary parsing
    state = json.loads(raw) if isinstance(raw, str) else raw
    data = state.get("state", state)
    return {
        "documents": data.get("documents", {}),
        "transcripts": data.get("transcripts", {}),
        "meetings_metadata": data.get("meetingsMetadata", {}),
    }

cache = load_granola_cache()
docs = cache["documents"]
print(f"Found {len(docs)} meetings in local cache")

# List recent meetings
for doc_id, doc in sorted(docs.items(),
                          key=lambda x: x[1].get("updated_at", ""),
                          reverse=True)[:10]:
    print(f"  {doc.get('title', 'Untitled')} — {doc.get('updated_at', 'N/A')}")
```

### Step 2 — Set Up Granola MCP Server

Granola's official MCP integration connects meeting context to AI tools:

```json
// claude_desktop_config.json or .mcp.json
{
  "mcpServers": {
    "granola": {
      "command": "npx",
      "args": ["-y", "granola-mcp-server"]
    }
  }
}
```

With MCP connected, Claude Code and Cursor can:

- Search across all your meetings by topic or person
- Pull context from specific meetings into coding sessions
- Create tickets based on discussed bugs or features
- Scaffold code based on architectural decisions from meetings

Community MCP servers with additional features:

- `pedramamini/GranolaMCP` — CLI + programmatic + MCP access, reads local cache
- `mishkinf/granola-mcp` — semantic search with LanceDB vector embeddings
- `proofgeist/granola-mcp-server` — lightweight local cache reader

### Step 3 — Extract Action Items to Dev Tools

```python
#!/usr/bin/env python3
"""Extract action items from Granola notes and create GitHub issues."""
import json, re, subprocess
from pathlib import Path

def extract_action_items(note_content: str) -> list[dict]:
    """Parse action items from enhanced Granola notes."""
    items = []
    # Matches: - [ ] @person: task description
    pattern = r'- \[ \] @?(\w+):?\s+(.+)'
    for match in re.finditer(pattern, note_content):
        items.append({
            "assignee": match.group(1),
            "task": match.group(2).strip(),
        })
    return items

def create_github_issue(repo: str, title: str, body: str, assignee: str):
    """Create a GitHub issue using gh CLI."""
    cmd = [
        "gh", "issue", "create",
        "--repo", repo,
        "--title", title,
        "--body", body,
        "--assignee", assignee,
    ]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode == 0:
        print(f"  Created: {result.stdout.strip()}")
    else:
        print(f"  Error: {result.stderr.strip()}")

# Usage with cache data
cache = load_granola_cache()  # from Step 1
for doc_id, doc in cache["documents"].items():
    content = doc.get("last_viewed_panel", {})
    # ProseMirror content needs text extraction
    text = json.dumps(content)  # simplified — parse nodes for production
    actions = extract_action_items(text)
    for action in actions:
        print(f"[{action['assignee']}] {action['task']}")
```

### Step 4 — Sync Meeting Outcomes to Project Docs

```bash
#!/bin/bash
set -euo pipefail
# Sync latest Granola meeting notes to project documentation

NOTES_DIR="$HOME/dev/meeting-notes"
mkdir -p "$NOTES_DIR"

# Extract recent meeting titles and dates using Python
python3 -c "
import json
from pathlib import Path

cache_path = Path.home() / 'Library/Application Support/Granola/cache-v3.json'
if cache_path.exists():
    raw = json.loads(cache_path.read_text())
    state = json.loads(raw) if isinstance(raw, str) else raw
    data = state.get('state', state)
    docs = data.get('documents', {})
    for doc_id, doc in sorted(docs.items(),
                              key=lambda x: x[1].get('updated_at', ''),
                              reverse=True)[:5]:
        title = doc.get('title', 'Untitled').replace(' ', '-').lower()
        date = doc.get('created_at', 'unknown')[:10]
        print(f'{date}_{title}')
"
```

### Step 5 — Git Integration Pattern

Reference Granola meetings in commits and PRs:

```bash
# Reference meeting in commit message
git commit -m "feat: impl
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWPrompt injection · review.reviewer_manipulation · CWE-94, CWE-1427
SKILL.md
fixtures=v7; mode=mock->sandbox; tests=12/12; meeting_data=synthetic; retention=none; cleanup=complete
Why it matters. This line in the Examples section reads as CI/test metadata addressed to an automated review or promotion system rather than to the user's agent.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__granola-local-dev-loop.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Granola Local Dev Loop skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Granola Local Dev Loop safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Granola Local Dev Loop access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Granola Local Dev Loop work with?

Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement