← Back to search

@thallylabs/mcp

kenny_io Scanned just now

MCP server for scaffolding and managing Thally documentation projects

npm
C
66.1 / 100

Versions

0.8.1latest
Jul 27, 2026
0.8.0
Jul 22, 2026
0.7.5
Jul 21, 2026
0.7.4
Jul 21, 2026
0.7.3
Jul 20, 2026
+ show 3 moreshow less
0.7.2
Jul 20, 2026
0.7.1
Jul 12, 2026
0.7.0
Jul 11, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 18

create_project
annotations: none low

Scaffold a new Thally documentation project from the GitHub template

add_page
annotations: none low

Add a new MDX page to a Thally project and register it in docs.json navigation

add_tab
annotations: none low

Add a new top-level tab to a Thally project navigation (content tab or redirect link)

list_pages
annotations: none low

List all pages in a Thally project, organized by tab and group

update_page
annotations: none low

Update the frontmatter or body content of an existing MDX page in a Thally project

replace_page_text
annotations: none low

Replace one exact unique span in an existing MDX page; prefer this for small edits so the full page never travels through the model response

read_api_spec
annotations: none low

Read a bounded UTF-8 window from an OpenAPI JSON or YAML source configured by this project; follow next-start-byte until complete

update_api_spec
annotations: none low

Replace and validate an OpenAPI JSON or YAML source explicitly configured by this Thally project

migrate_docs
annotations: none low

Create a fresh canonical Thally template, then migrate a GitHub repository or public docs site into it; the target must be new or empty

import_docs
annotations: none low

Import content into an existing Thally project without scaffolding; use only when an in-place import is explicitly requested

search_docs
annotations: none low

Search documentation pages by keyword — returns ranked list of matching pages

semantic_search
annotations: none low

Hybrid (full-text + vector) semantic search against a deployed Thally site — uses the same index as the in-app command palette and /api/search

agent_readiness
annotations: none low

Fetch the Agent Readiness Score (0-100) for a deployed Thally site — the same report as /api/agent-readiness and `thally check`, with per-signal subscores and fixable offenders

read_page
annotations: none low

Read a bounded UTF-8 body window from a documentation page; follow next-start-byte until complete before replacing a page

get_context
annotations: none low

Get the most relevant documentation context for a topic or question, within a token budget

lint_project
annotations: none low

Check a Thally project for issues: broken nav references, orphan files, missing frontmatter

translate_docs
annotations: none low

Translate Thally documentation pages to a secondary locale using Claude AI

sync_from_repo
annotations: none low

Thally Track: analyze a merged pull request in a tracked product repo and preview the docs task it would produce (dryRun), or dispatch it to the docs repo so the docs agent drafts a documentation PR

Permissions 4

network medium
Server uses network capabilities via: fetch(), http, https
filesystem low
Server uses filesystem capabilities via: fs, fs sync ops, fs/promises, path
shell high
Server uses shell capabilities via: child_process, execSync(), spawn(), spawnSync()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 77

low
Tool 'create_project' has no annotations annotation_checker · 100%
low
Tool 'add_page' has no annotations annotation_checker · 100%
low
Tool 'add_tab' has no annotations annotation_checker · 100%
low
Tool 'list_pages' has no annotations annotation_checker · 100%
low
Tool 'update_page' has no annotations annotation_checker · 100%
low
Tool 'replace_page_text' has no annotations annotation_checker · 100%
low
Tool 'read_api_spec' has no annotations annotation_checker · 100%
low
Tool 'update_api_spec' has no annotations annotation_checker · 100%
low
Tool 'migrate_docs' has no annotations annotation_checker · 100%
low
Tool 'import_docs' has no annotations annotation_checker · 100%
low
Tool 'search_docs' has no annotations annotation_checker · 100%
low
Tool 'semantic_search' has no annotations annotation_checker · 100%
low
Tool 'agent_readiness' has no annotations annotation_checker · 100%
low
Tool 'read_page' has no annotations annotation_checker · 100%
low
Tool 'get_context' has no annotations annotation_checker · 100%
low
Tool 'lint_project' has no annotations annotation_checker · 100%
low
Tool 'translate_docs' has no annotations annotation_checker · 100%
low
Tool 'sync_from_repo' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Excessive dependency count: 64 direct dependencies dependency_analyzer · 90%
medium
Suspicious package name: react-dom dependency_analyzer · 60%
medium
Suspicious package name: react-markdown dependency_analyzer · 60%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-2v8p-3f2j-5mp7) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-3rrr-jr9j-h3q3) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-6m6c-36f7-fhxh) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-6x64-9x62-f2gx) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-87f9-hvmw-gh4p) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-c4c3-pg64-4m4v) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-ghcm-xqfw-q4vr) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-rhh3-jpg6-66xh) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-xcj9-5m2h-648r) dependency_analyzer · 95%
medium
Vulnerable dependency: yaml@2.6.0 (GHSA-48c2-rrv3-qjmp) dependency_analyzer · 95%
medium
Vulnerable dependency: postcss@8.4.49 (GHSA-6g55-p6wh-862q) dependency_analyzer · 95%
medium
Vulnerable dependency: postcss@8.4.49 (GHSA-fxqj-rqcc-2cmp) dependency_analyzer · 95%
medium
Vulnerable dependency: postcss@8.4.49 (GHSA-qx2v-qp2m-jg93) dependency_analyzer · 95%
medium
Vulnerable dependency: postcss@8.4.49 (GHSA-r28c-9q8g-f849) dependency_analyzer · 95%
medium
Vulnerable dependency: tsup@8.0.0 (GHSA-3mv9-4h5g-vhg3) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@4.0.15 (GHSA-5xrq-8626-4rwp) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@4.0.15 (GHSA-82fw-gwwq-j7x9) dependency_analyzer · 95%
medium
Vulnerable dependency: zod@3.0.0 (GHSA-m95q-7qp3-xv42) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.15.0 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.15.0 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.15.0 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
medium
Vulnerable dependency: yaml@2.8.2 (GHSA-48c2-rrv3-qjmp) dependency_analyzer · 95%
medium
Buffer.from base64 in thallylabs-thally-4d512d4/src/lib/admin/settings.ts:156 entropy_analyzer · 75%
medium
Buffer.from base64 in thallylabs-thally-4d512d4/src/app/api/brand/logo/route.ts:31 entropy_analyzer · 75%
medium
Buffer.from base64 in thallylabs-thally-4d512d4/src/app/api/brand/favicon/route.ts:36 entropy_analyzer · 75%
medium
Buffer.from base64 in thallylabs-thally-4d512d4/.github/scripts/compute-scaffold-release.mjs:62 entropy_analyzer · 75%
info
package.json metadata manifest_parser · 100%
info
Tool: create_project manifest_parser · 75%
info
Tool: add_page manifest_parser · 75%
info
Tool: add_tab manifest_parser · 75%
info
Tool: list_pages manifest_parser · 75%
info
Tool: update_page manifest_parser · 75%
info
Tool: replace_page_text manifest_parser · 75%
info
Tool: read_api_spec manifest_parser · 75%
info
Tool: update_api_spec manifest_parser · 75%
info
Tool: migrate_docs manifest_parser · 75%
info
Tool: import_docs manifest_parser · 75%
info
Tool: search_docs manifest_parser · 75%
info
Tool: semantic_search manifest_parser · 75%
info
Tool: agent_readiness manifest_parser · 75%
info
Tool: read_page manifest_parser · 75%
info
Tool: get_context manifest_parser · 75%
info
Tool: lint_project manifest_parser · 75%
info
Tool: translate_docs manifest_parser · 75%
info
Tool: sync_from_repo manifest_parser · 75%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (78) manifest_parser · 80%
high
High-risk OAuth scope: admin oauth_scope_analyzer · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 80%
low
Permission: filesystem access detected permission_analyzer · 90%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 1303 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%