synology-office-mcp (vocweb/synology-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 40 out of 100, grade D. It declares 39 tools. No publisher has claimed this listing.
Self-hosted MCP server that exposes Synology Drive, Spreadsheet, MailPlus, and Calendar as structured tools for AI agents, enabling file, spreadsheet, email, and calendar management via natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
vocweb
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
calendar_create_calendarCreate a new Synology Calendar.
calendar_create_eventcalendar_delete_eventDelete a Synology Calendar event permanently. Requires confirm=true.
calendar_get_eventGet details of a specific Synology Calendar event.
calendar_list_calendarsList all Synology Calendar calendars accessible to the authenticated user.
calendar_list_eventscalendar_update_eventdrive_add_labelAdd a label to a file or folder in Synology Drive.
drive_create_folderCreate a new folder in Synology Drive, optionally creating parent directories.
drive_delete_fileDelete a file or folder in Synology Drive (moves to trash by default). Set confirm=true to execute.
drive_download_fileDownload a file from Synology Drive and return it as base64-encoded content with metadata.
drive_get_file_infoGet detailed metadata (size, owner, ACL, labels) for a specific Drive file or folder.
drive_get_sharing_linkGenerate or retrieve a sharing link for a Synology Drive file with configurable permission and optional expiry.
drive_list_filesList files and folders in a Synology Drive path. Supports pagination, sorting, and glob filtering.
drive_list_labelsList all labels defined in Synology Drive (id, name, color).
drive_move_fileMove or rename a file/folder in Synology Drive. Set confirm=true to execute; omit or set false for a dry-run check.
drive_search_filesSearch for files across Synology Drive by name or keyword, with optional extension filter.
drive_upload_fileUpload a file to Synology Drive from a base64-encoded payload. Max recommended size: 50 MB.
mailplus_get_messageGet the full content of a MailPlus email message, with optional attachment download.
mailplus_list_foldersList all mail folders (IMAP-like folder tree) for the MailPlus account.
mailplus_list_messagesList email messages in a MailPlus folder with pagination, sort, and keyword search.
mailplus_mark_messagesMark MailPlus messages as read, unread, flagged, or unflagged.
mailplus_move_messagesMove MailPlus messages to another folder. Requires confirm=true to execute.
mailplus_send_messageSend an email via Synology MailPlus. Requires confirm=true to execute.
spreadsheet_add_sheetAdd a new sheet tab to an existing Synology Spreadsheet file. Provide either file_id or name.
spreadsheet_append_rowsAppend rows to the end of existing data in a Synology Spreadsheet sheet. Provide either file_id or name. Set confirm=true to execute.
spreadsheet_batch_updateInsert or delete rows/columns in a Synology Spreadsheet. Provide either file_id or name. Set confirm=true to execute.
spreadsheet_createCreate a new empty Synology Spreadsheet (.osheet). Note: the Spreadsheet API has no notion of destination folder; use Drive tools to move the file afterwards if needed.
spreadsheet_delete_sheetDelete a sheet tab from a Synology Spreadsheet. This action cannot be undone. Provide either file_id or name. Set confirm=true to execute.
spreadsheet_delete_filespreadsheet_exportExport a Synology Spreadsheet to xlsx or csv format. Returns the file content as base64. Provide either file_id or name.
spreadsheet_get_infoGet metadata about a Synology Spreadsheet file: sheet names, row and column counts. Provide either file_id or name.
spreadsheet_get_stylesGet cell styling information (fonts, colors, alignment, number formats) for a range in a Synology Spreadsheet. Provide either file_id or name.
spreadsheet_listList all Synology Spreadsheet (.osheet) files in a Drive folder.
spreadsheet_read_sheetRead cell data from a Synology Spreadsheet sheet. Returns headers (first row), data rows, and totals. Provide either file_id or name.
spreadsheet_registerRegister a Synology Spreadsheet so it can be addressed by name in other tools. Provide the alphanumeric ID from the file URL /oo/r/{id}.
spreadsheet_rename_sheetRename a sheet tab in a Synology Spreadsheet. Provide either file_id or name. Set confirm=true to execute.
spreadsheet_write_cellsWrite values to a range of cells in a Synology Spreadsheet sheet. Provide either file_id or name. Set confirm=true to execute.
spreadsheet_write_stylesDisclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
form-data uses unsafe random function in form-data for choosing boundary
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
DOTENV_CONFIG_PATHMCP_SSE_HOST127.0.0.1 Bind address for SSEMCP_SSE_PORT3100 Port for SSEMCP_TRANSPORTstdio stdio or sseSYNO_SS_ID_CACHE_PATHTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
39/39 tools missing one or more hints — calendar_create_calendar (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); calendar_create_event (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); calendar_delete_event (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +36 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Production dependencies are patched
1 critical, 9 high severity in production deps — form-data@4.0.1 (critical), @modelcontextprotocol/sdk@1.11.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/vocweb/synology-mcp-server)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check