.vscode — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .vscode (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server that exposes GroupDocs.Signature as AI-callable tools for Claude, Cursor, GitHub Copilot, and other MCP agents.
Requires .NET 10 SDK.
Run directly with `dnx` (recommended — no install step):
dnx GroupDocs.Signature.Mcp --yesPulls the latest stable release on every invocation. To pin to a specific version (recommended for shared configs and CI), append @<version>:
dnx [email protected] --yesOr install as a global dotnet tool:
dotnet tool install -g GroupDocs.Signature.Mcp
groupdocs-signature-mcpOr run via Docker:
docker run --rm -i \
-v $(pwd)/documents:/data \
ghcr.io/groupdocs-signature/signature-net-mcp:latestThe underlying GroupDocs engine renders signature glyphs (text, QR codes, barcodes) onto document pages via System.Drawing (GDI+). When you run the server natively (via dnx or the global dotnet tool) on Linux or macOS, install the native libgdiplus library and a fonts package first:
| Platform | Setup |
|---|---|
| Windows | Nothing — GDI+ is built into the OS. |
| Linux | sudo apt-get install -y libgdiplus libfontconfig1 ttf-mscorefonts-installer |
| macOS | brew install mono-libgdiplus |
| Docker | Nothing — the image already bundles libgdiplus, libfontconfig1, and ttf-mscorefonts-installer. |
Skipping this on Linux/macOS surfaces as DllNotFoundException: libgdiplus in the tool response. The simplest zero-setup option on Linux/macOS is the Docker image.
| Tool | Description |
|---|---|
Sign | Sign a document with a text, QR code, barcode, or digital certificate signature; saves the signed file as <name>_signed.<ext> |
Verify | Verify signatures in a document (text, QR code, barcode, digital, or all) and return a validity report |
SearchTextSignatures | Find embedded text signatures (stamps, labels, native text annotations) with optional substring filter |
SearchBarcodes | Find barcode signatures (Code39, Code128, EAN, etc.) with optional decoded-text filter and optional inline image |
SearchQrCodes | Find QR code signatures with optional decoded-text filter and optional inline image |
SearchDigitalSignatures | Find digital certificate signatures and return signer, issuer, serial number, validity status |
SearchImageSignatures | Find embedded image signatures (logos, stamp images, picture overlays) and return them as base64 PNGs |
GetDocumentInfo | Return file type, page count, size, and per-page dimensions as JSON (no modification) |
| Variable | Description | Default |
|---|---|---|
GROUPDOCS_MCP_STORAGE_PATH | Base folder for input and output files | current directory |
GROUPDOCS_MCP_OUTPUT_PATH | (Optional) separate folder for output files | GROUPDOCS_MCP_STORAGE_PATH |
GROUPDOCS_LICENSE_PATH | Path to GroupDocs license file | (evaluation mode) |
{
"mcpServers": {
"groupdocs-signature": {
"type": "stdio",
"command": "dnx",
"args": ["GroupDocs.Signature.Mcp", "--yes"],
"env": {
"GROUPDOCS_MCP_STORAGE_PATH": "/path/to/documents"
}
}
}
}To pin to a specific version, replace"GroupDocs.Signature.Mcp"with"[email protected]"inargs. Pinning is recommended for shared / committed configs to avoid surprise upgrades.
NuGet.org generates a ready-to-use mcp.json snippet on the package page. Copy it directly into your .vscode/mcp.json.
Alternatively, add manually to .vscode/mcp.json:
{
"inputs": [
{
"type": "promptString",
"id": "storage_path",
"description": "Base folder for input and output files.",
"password": false
}
],
"servers": {
"groupdocs-signature": {
"type": "stdio",
"command": "dnx",
"args": ["GroupDocs.Signature.Mcp", "--yes"],
"env": {
"GROUPDOCS_MCP_STORAGE_PATH": "${input:storage_path}"
}
}
}
}Same pinning rule as above — swap"GroupDocs.Signature.Mcp"for"[email protected]"to lock to a specific release.
cd docker
docker compose upEdit docker/docker-compose.yml to point volumes at your local documents folder.
MIT — see LICENSE
<!-- mcp-name: io.github.groupdocs-signature/groupdocs-signature-mcp -->
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.