← Index

io.github.lozit/mcp-standardnotes

io.github.lozit/mcp-standardnotes·v0.3.6·Security

End-to-end encrypted access to a Standard Notes vault (protocol 004, local stdio only).

Trust verdict · v1 advisory · method
NOT YET SCREENEDno verdict on file

Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.

Own this server? Screen its description →

Environment variables
SN_EMAIL
required

Standard Notes account email. The password is prompted once via `npx mcp-standardnotes-login` and the session is persisted in the OS keychain.

SN_SERVER_URL

Standard Notes sync server URL. Defaults to the official cloud if unset.

SN_CERT_FINGERPRINT

Optional SHA-256 TLS certificate fingerprint for pinning a self-hosted server.

MCP quality score · maturity, not trust · methodology
freshness
25
completeness
15
installability
25
documentation
15
stability
5
Alternatives in Security