Francolabs Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Francolabs Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Connect AI assistants to FrancoLabs — a UX research platform — over the Model Context Protocol. Let Claude, ChatGPT and other MCP clients create and manage studies, browse templates, read participant responses and analytics, run AI-grounded analysis, and turn insights into product opportunities on your behalf.
https://francolabs.vercel.app/mcp2025-06-18)io.github.glauberfrancodesign/francolabsSettings → Connectors → Add custom connector → URL:
https://francolabs.vercel.app/mcpComplete the OAuth consent screen — you choose exactly which scopes to grant and can toggle read-only access.
Enable Developer Mode, then Settings → Connectors → Add → same URL. Authenticate via the OAuth flow.
Generate a Personal Access Token in Settings → Integrations, then:
claude mcp add --transport http francolabs \
"https://francolabs.vercel.app/mcp" \
--header "Authorization: Bearer <your-token>"| Tool | Scope | Description |
|---|---|---|
list_question_types | templates:read | List question/block types and their settings |
list_templates | templates:read | List study templates, optionally by category |
list_workspaces | projects:read | List the workspaces (teams) you belong to and your role in each |
list_projects | projects:read | List your projects |
get_project | projects:read | Get a single project by id |
create_project | projects:write | Create a new project (optionally in a specific workspace) |
list_studies | studies:read | List studies (filter by status/project) |
get_study | studies:read | Get a full study with blocks and settings |
create_study | studies:write | Create a study (auto-scaffolds welcome + thank-you) |
update_study | studies:write | Update title, blocks, settings or project |
set_study_status | studies:write | Launch / pause / resume / complete a study |
delete_study | studies:write | Permanently delete a study and its responses |
list_responses | responses:read | List participant responses (most recent first) |
get_study_analytics | responses:read | Aggregated KPIs: NPS, completion, distributions |
get_study_digest | responses:read | Deterministic, PII-free statistical digest of a study's results |
run_universal_analysis | responses:read | Run/refresh the full AI analysis (digest + grounded synthesis) |
analysis_chat | responses:read | Ask a natural-language question, grounded in the study's analysis |
get_insights | responses:read | List curated insight cards for a study |
upsert_insight | studies:write | Create or update a curated insight card |
generate_study_from_objective | studies:read | Turn a research objective into a typed study skeleton |
review_study_quality | studies:read | Review a study's questionnaire for survey-design issues |
list_opportunities | responses:read | List product opportunities distilled from a study's insights |
create_opportunity_from_insights | studies:write | Distill insights into decision-ready product opportunities |
create_project and create_study write into a workspace — pass workspaceId (see list_workspaces), or omit it to use your oldest workspace by default.
Two resources are also exposed: francolabs://templates and francolabs://question-types.
templates:read · projects:read · projects:write · studies:read · studies:write · responses:read
Tools you didn't grant are hidden from tools/list. A read-only grant blocks every write tool server-side, regardless of scopes.
per-user row-level security; the service role is used only for the token lookup.
RFC 7591 (dynamic client registration) and PKCE S256.
This repository mirrors the server's source for transparency. The server runs as a Supabase Edge Function (src/mcp, src/mcp-oauth, src/_shared).
© FrancoLabs. All rights reserved.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.