Nb Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Nb Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server wrapping the nb CLI for LLM-friendly note-taking.
Using nb directly via shell has two problems for LLM assistants:
nb assumes a default notebook, making per-project use awkward.This MCP server solves both by:
Install nb by following the official instructions: nb installation guide.
From crates.io:
cargo install nb-mcp-serverOr download a prebuilt binary from GitHub Releases.
cargo build --releaseWith default notebook from environment:
NB_MCP_NOTEBOOK=myproject ./target/release/nb-mcpOr via CLI argument (takes precedence):
./target/release/nb-mcp --notebook myprojectDisable commit and tag signing in the notebook repository:
./target/release/nb-mcp --notebook myproject --no-commit-signingAllow new notes at the notebook root instead of requiring a folder:
./target/release/nb-mcp --notebook myproject --allow-top-level-notesPrint the installed version:
./target/release/nb-mcp --versionShow the resolved notebook path and state directory:
./target/release/nb-mcp --show-pathsAdd to your MCP client configuration (e.g., .mcp.json):
{
"mcpServers": {
"nb": {
"command": "/path/to/nb-mcp",
"args": ["--notebook", "myproject"]
}
}
}The canonical access path is the multiplexed nb tool with a command parameter, which reduces the token footprint of the MCP server. The args field must be a JSON object. Stringified JSON payloads are rejected. Unknown args fields are rejected instead of ignored; use the exact command schema fields or documented aliases. Returned identifiers such as coordination/mcp/1 or myproject:coordination/mcp/1 are nb selectors, not filesystem paths in the current repository. Notebook storage is managed by nb configuration. The notebook argument must be a bare notebook name. Use folder for folder paths and id / selector for note selectors. Existing-item commands accept copied selectors such as myproject:coordination/mcp/1, but reject conflicts with a separate notebook argument.
All commands are also available as direct first-class tools with typed schemas: add, show, edit, delete, move, list, search, todo, do, undo, tasks, bookmark, folders, mkdir, import, status, notebooks. These bypass the multiplexed command dispatch. The multiplexed nb tool remains as the compact/backcompat compatibility surface.
| Command | Description | Key Arguments |
|---|---|---|
nb.add | Create a note | title, content, tags[], folder required by default |
nb.show | Read a note | id (alias: selector) |
nb.edit | Update a note | id (alias: selector), content, mode (replace default, append, prepend) |
nb.delete | Delete a note | id (alias: selector) |
nb.move | Move or rename a note | id (alias: selector), destination |
nb.list | List notes | folder, tags[], limit ([ ] / [x] indicate todo status; leading glyphs are item markers) |
nb.search | Full-text search | queries[] (required), mode (any default, all), tags[] |
| Command | Description | Key Arguments |
|---|---|---|
nb.todo | Create a todo | folder required by default, title, optional description (alias: content), optional tasks[], tags[] |
nb.do | Mark complete | id (alias: selector), optional task_number |
nb.undo | Reopen | id (alias: selector), optional task_number |
nb.tasks | List todos | optional status (open or closed), optional recursive (true default) |
| Command | Description | Key Arguments |
|---|---|---|
nb.bookmark | Save a URL | url, folder required by default, title, tags[], comment |
nb.import | Import file/URL | source, folder required by default, filename, convert |
nb.folders | List folders | parent |
nb.mkdir | Create folder | path |
nb.notebooks | List notebooks only | (none) |
nb.status | Notebook info | (none) |
Create a note with code:
{
"command": "nb.add",
"args": {
"title": "API Design Notes",
"content": "# API Design\n\nUse `GET /items` for listing.\n\n```python\nresponse = client.get('/items')\n```",
"tags": ["design", "api"],
"folder": "docs"
}
}Search for notes:
{
"command": "nb.search",
"args": {
"queries": ["API", "design"],
"mode": "any",
"tags": ["design"]
}
}For multi-LLM projects, consider using consistent tag prefixes (optional). Example categories and prefixes:
| Category | Pattern | Examples |
|---|---|---|
| Collaborator | llm-<name> | llm-claude, llm-gpt |
| Component | component-<name> | component-api, component-ui |
| Task type | task-<type> | task-bug, task-feature |
| Status | status-<state> | status-review, status-blocked |
Priority order:
notebook argument (highest)--notebook flagNB_MCP_NOTEBOOK environment variableIf no notebook can be resolved, commands fail with a configuration error. The server does not fall back to nb's default notebook.
If the resolved notebook does not exist, the server creates it automatically. Use --no-create-notebook to disable automatic creation.
Logs are written to ~/.local/state/nb-mcp/{project}--{worktree}.log (XDG-compliant).
For Git worktrees, logs are named after both the master project and the worktree basename to avoid collisions between multiple MCP server instances.
Use --show-paths to print the resolved notebook path and state directory.
By default, note-creating commands require a folder argument so agents do not accidentally litter project notebook roots. This applies to nb.add, nb.todo, nb.bookmark, and nb.import. Use nb.mkdir to create new folders and nb.folders to list existing folders.
Set NB_MCP_ALLOW_TOP_LEVEL_NOTES=true or pass --allow-top-level-notes to permit root-level note creation.
Mutating commands warn after successful writes when the notebook argument targets a notebook other than the project default. Cross-notebook writes remain allowed for collaboration across teams, but the warning helps catch accidental notebook/folder confusion.
The notebook argument accepts only bare notebook names, not selector syntax. For example, use notebook: "other-team" with folder: "todos/mcp", not notebook: "other-team:todos/mcp".
Control log level with RUST_LOG:
RUST_LOG=debug nb-mcp --notebook myprojectUse --no-commit-signing to disable commit and tag signing in the notebook repository. The server updates the notebook repository's local Git config so signing prompts do not block MCP tool calls.
See the contribution guide and code of conduct:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.