← Back to search Server uses shell capabilities via: spawnSync() Server uses env_vars capabilities via: process.env
@dlvr/mcp
Local MCP server for uploading, downloading, and managing dlvr.sh file deliveries.
npm
B
86.2 / 100
Versions
0.3.2latestJul 17, 2026
0.3.1Jul 14, 2026
0.3.0Jul 14, 2026
0.2.0Jul 13, 2026
0.1.0Jul 11, 2026
Tools 5
dlvr_upload_file annotations: none low
Upload up to 100 local files to dlvr.sh and return one share link.
dlvr_list_uploads annotations: none low
List recent account uploads for the authenticated dlvr.sh account.
dlvr_get_upload annotations: none low
Get metadata for one account-owned dlvr.sh upload.
dlvr_delete_upload annotations: none low
Delete one account-owned dlvr.sh upload and its stored files.
dlvr_download_file annotations: none low
Download a public dlvr.sh share to the local filesystem. Bundles are saved as ZIP files.
Permissions 2
shell high env_vars low Scan Findings 19
low
Tool 'dlvr_download_file' has no annotations
low
Tool 'dlvr_upload_file' has no annotations
low
Tool 'dlvr_list_uploads' has no annotations
low
Tool 'dlvr_get_upload' has no annotations
low
Tool 'dlvr_delete_upload' has no annotations
medium
OAuth implementation without PKCE
info
Sandbox failed to start for behavioral verification
info
package.json metadata
info
Tool: dlvr_download_file
info
Tool: dlvr_upload_file
info
Tool: dlvr_list_uploads
info
Tool: dlvr_get_upload
info
Tool: dlvr_delete_upload
info
Transport: stdio
info
Sandbox failed to start for output poisoning scan
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 13 components
medium
No build provenance detected (SLSA L0)