73
/ 100
1 month ago
glama

Simplenote MCP Server

Integrates Simplenote with Claude Desktop, allowing AI assistants to read, create, update, search, and manage your Simplenote notes as a memory backend or content source.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 6 credentials: GITHUB_TOKEN, DOCKER_TOKEN, ALERT_SMTP_PASSWORD, ALERT_WEBHOOK_SECRET, SIMPLENOTE_PASSWORD, SESSION_SECRET_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

lowyaml@2.3.4GHSA-48c2-rrv3-qjmp

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCOVERAGE_FILE
configCOVERAGE_MIN
configCOVERAGE_STRICT
configVARIABLE_NAME
🔐 secretGITHUB_TOKEN
configDOCKER_USERNAME
🔐 secretDOCKER_TOKEN
configDOCKER_REPOSITORY
configREADME_FILE
configHTTP_PROXY
confighttp_proxy
configHTTPS_PROXY
confighttps_proxy
configNO_PROXY
configno_proxy
configLOG_LEVELINFO Logging level (DEBUG, INFO, WARNING, ERROR)
configMCP_DEBUG
configALERT_SMTP_HOST
configALERT_SMTP_PORT
configALERT_SMTP_USER
🔐 secretALERT_SMTP_PASSWORD
configALERT_EMAIL_FROM
configALERT_EMAIL_TO
configALERT_SMTP_SSL
configALERT_WEBHOOK_URLS
🔐 secretALERT_WEBHOOK_SECRET
configSIMPLENOTE_USERNAME
🔐 secretSIMPLENOTE_PASSWORDyour-password
configSYNC_INTERVAL_SECONDS
configDEFAULT_RESOURCE_LIMIT
configTITLE_MAX_LENGTH
configSNIPPET_MAX_LENGTH
configCACHE_MAX_SIZE
configCACHE_INITIALIZATION_TIMEOUT
configMETRICS_COLLECTION_INTERVAL
configRATE_LIMIT_REQUESTS
configRATE_LIMIT_WINDOW_SECONDS
configRATE_LIMIT_BURST
configHTTP_HOST
configHTTP_PORT
configHTTP_METRICS_PATH
configHTTP_HEALTH_PATH
configHTTP_READY_PATH
configCACHE_HEALTH_CHECKS_ENABLED
configMCP_TRANSPORT
configMCP_HTTP_HOST
configMCP_HTTP_PORT
configMCP_HTTP_PATH
configSIMPLENOTE_LOG_LEVEL
configMCP_LOG_LEVEL
configLOGLEVEL
configLOG_TO_FILE
configSIMPLENOTE_WRITE_BUDGET
configSIMPLENOTE_WRITE_BUDGET_WINDOW
configSIMPLENOTE_OFFLINE_MODEfalse Run in offline mode for testing
🔐 secretSESSION_SECRET_KEY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/docdyhr-simplenote-mcp-server-vw9tmc)](https://m8ven.ai/mcp/docdyhr-simplenote-mcp-server-vw9tmc)
commit: b044e2af58411b602a1929f0855bab4a24f2a188
code hash: 42a31ff3f1052fa086df4340f92d0c15f61a560ee98b6ab652ccd0e03e14e0ef
verified: 6/17/2026, 12:45:08 PM
view raw JSON →