An MCP server for AFFiNE that exposes workspaces, documents, databases, comments, and more to AI assistants over stdio or HTTP, supporting both AFFiNE Cloud and self-hosted deployments.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
irfanhak123
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
markdown-it is has a Regular Expression Denial of Service (ReDoS)
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
AFFINE_ADMIN_EMAILAFFINE_ADMIN_PASSWORDAFFINE_ALLOW_INSECURE_HTTPAFFINE_BASE_URLe =https://your-affine-instance.com \AFFINE_CLIENT_VERSIONAFFINE_COMPREHENSIVE_ASSUME_FOCUSED_COVERAGEAFFINE_EMAILe =you@example.com \AFFINE_GRAPHQL_PATHAFFINE_HEADERS_JSONAFFINE_LOGIN_AT_STARTAFFINE_MCP_HTTP_ALLOW_QUERY_TOKENAFFINE_MCP_HTTP_ALLOW_UNAUTHENTICATEDAFFINE_PASSWORDe =your-password \AFFINE_WS_ACK_TIMEOUT_MSAFFINE_WS_CLIENT_VERSIONAFFINE_WS_CONNECT_TIMEOUT_MSAPPEND_BLOCK_PROFILEGITHUB_REF_NAMEGITHUB_SHAMCP_TOOL_TIMEOUT_MSXDG_CONFIG_HOMEThis stores credentials in $/affine-mcp/config when XDG_CONFIG_HOME is set, otherwise in ~/.config/affine-mcp/config, with mode 600.Dependencies
19 dependencies, 1 flagged: @playwright/test
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
49/49 tools missing one or more hints — sign_in (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); upload_blob (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); delete_blob (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +46 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 0/49 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Secrets not logged
1 secret value sent to console.log
Redact or omit secret values from log output.
Production dependencies are patched
0 critical, 1 high severity in production deps — form-data@4.0.4 (high), markdown-it@14.1.0 (low)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
1/12 production deps stale: node-fetch@2023-11-30 (2.7y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/irfanhak123-affine-mcp-server-2j8q2o)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check