Freshjots Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Freshjots Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server for Fresh Jots. It exposes your Fresh Jots notes as MCP tools, so any MCP client — Claude Desktop, Claude Code, Cursor, and others — can read and write them directly. Point your AI agent's output at a Fresh Jots note, log your coding sessions, or let an assistant search and update your notebook, all through the API.
MCP is an open standard for connecting AI assistants to external tools and data — think of it as a universal adapter, so one integration works across every compatible client.
The server talks to the Fresh Jots REST API over a bearer token and exposes these tools:
Notes — list_notes, read_note, create_note, append_to_note, update_note, delete_note, move_note
Folders — list_folders, create_folder, rename_folder, delete_folder
The standout is `append_to_note`: it appends to a note addressed by an exact filename (e.g. ai-sessions.txt) and creates the note on first write. Call it repeatedly to accumulate a log — AI session transcripts, cron output, a running journal — in one place.
Notes are plain text through the API: rich (Trix) notes can be listed and read, but only plain notes can be created or edited here.
mn_….Until this is published to npm, build it from source:
git clone https://github.com/Goran-Arsov/freshjots-mcp.git
cd freshjots-mcp
npm install # also builds via the prepare script
npm run build # or build explicitlyThe runnable server is then dist/index.js.
The server reads its token from the environment:
FRESHJOTS_TOKEN (required) — your mn_… API token. FRESHJOTS_API_TOKEN is also accepted.FRESHJOTS_BASE_URL (optional) — defaults to https://freshjots.com/api/v1. Override for a self-hosted or staging instance.Add to claude_desktop_config.json (Settings → Developer → Edit Config):
{
"mcpServers": {
"freshjots": {
"command": "node",
"args": ["/absolute/path/to/freshjots-mcp/dist/index.js"],
"env": { "FRESHJOTS_TOKEN": "mn_your_token_here" }
}
}
}claude mcp add freshjots --scope user \
-e FRESHJOTS_TOKEN='${FRESHJOTS_TOKEN}' \
-- node /absolute/path/to/freshjots-mcp/dist/index.jsUsing '${FRESHJOTS_TOKEN}' (single-quoted) stores the reference, not the secret — Claude Code expands it from your shell environment at launch, so keep export FRESHJOTS_TOKEN=mn_… in your shell profile. Or pass the literal token with -e FRESHJOTS_TOKEN=mn_… if you prefer it in the config.
Add to ~/.cursor/mcp.json (or a project .cursor/mcp.json):
{
"mcpServers": {
"freshjots": {
"command": "node",
"args": ["/absolute/path/to/freshjots-mcp/dist/index.js"],
"env": { "FRESHJOTS_TOKEN": "mn_your_token_here" }
}
}
}Once published to npm, command: "npx", args: ["-y", "freshjots-mcp"] will replace the local path in any of the above.
npm run build # compile TypeScript to dist/
npm test # unit tests (fetch stubbed; no network)
node smoke.mjs # live end-to-end test against the real API — needs FRESHJOTS_TOKEN;
# creates only clearly-marked [mcp-test] notes/folders and deletes themMIT © Goran Arsov
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.