Mindnode Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mindnode Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
English | 日本語
An MCP server that lets an AI assistant (Claude, etc.) read and write your [MindNode](https://mindnode.com) mind maps directly — by parsing the .mindnode file format itself. No AppleScript, no Shortcuts, no export/import dance.
Ask your assistant to "read my project map", "add these three ideas under Marketing", "connect the API node to the Auth node", or "turn this outline into a new mind map" — and it operates on the real files MindNode syncs.
Why this exists: MindNode dropped its AppleScript dictionary, and its Shortcuts/URL-scheme automation is thin. But a.mindnodedocument is just a package whosecontents.xmlis an Apple binary plist — a clean recursive node tree. Read/write that, and you get full programmatic control.
current MindNode releases)
git clone https://github.com/masamitsu-konya/mindnode-mcp.git
cd mindnode-mcp
uv syncRegister it with Claude Code (user scope = available everywhere):
claude mcp add --scope user mindnode -- uv --directory "$PWD" run mindnode-mcpThen start a new session and run /mcp (or claude mcp list) to confirm it shows mindnode ✔ Connected.
By default it finds your MindNode documents in the iCloud container automatically. Point it elsewhere with the MINDNODE_DOCS_DIR environment variable (a local library, or a fixture folder for testing).
Talk to your assistant in plain language — it picks the right tool. Examples:
| You say | What happens |
|---|---|
| "List my mind maps" | list_documents → names + dates, newest first |
| "Read my Project Plan map" | read_document → the full node tree as JSON |
| "Search all my maps for 'pricing'" | search_nodes → every matching node + its document |
| "Add 'Hire a designer' under the Team node in Roadmap" | add_node |
| "Connect 'Frontend' to 'API' with the label 'calls'" | add_connection |
| "Tag the 'Launch' node as #urgent" | add_tag (creates the tag if new) |
| "Mark 'Ship v1' as done" | set_task |
| "Attach ~/Desktop/wireframe.png to the Design node" | attach_image |
| "Make a new map 'Q3 Goals' with branches Sales, Product, Hiring" | create_map |
Nodes can be referenced by their text (a case-insensitive substring is enough) or by their exact id (ids come back from read_document).
| Tool | Kind | What it does |
|---|---|---|
list_documents | read | All .mindnode files, newest first |
read_document | read | Mind maps as {id, text, note?, task?, tags?, attachment?, children?} trees, plus connections and the document's tag list |
search_nodes | read | Substring search over node text + notes, in one document or all |
add_node | write | Add a node under a parent (by id or text), with optional note |
add_connection | write | Cross-link two existing nodes with an optional label and arrow direction |
add_tag / remove_tag | write | Tag / untag a node (tags are document-wide and auto-created) |
set_task | write | Turn a node into a checkbox task and set done / todo |
attach_image | write | Attach a local image to a node (copied into the package's resources/) |
create_map | write | Create a new .mindnode from a title + (optionally nested) outline |
Free links between any two nodes, independent of the parent/child tree (stored at canvas.crossConnections[]). add_connection(document, start, end, label?, direction?) — direction ∈ forward (default) / backward / both / none. read_document returns each as {id, start_id, end_id, start_text, end_text, direction, label?}.
read_document surfaces these per node (and lists all tag names at the top):
canvas.tags[] defines {tagID, name, color},node.tags[] references tagIDs. add_tag auto-defines a tag of that name if it doesn't exist, then attaches it (idempotent).
node.task = {state, uuids}, where state 1 = todo, 2 = done.set_task(document, node, done) toggles it.
type}; image bytes live in resources/<fileName>. attach_image` copies the file in and links it, clamping display width to 300px (matching MindNode).
A .mindnode document is a package directory. Its contents.xml — despite the extension — is an Apple binary plist holding the mind map (format version 9):
canvas.mindMaps[].mainNode # root node of each map
├─ nodeID # UUID
├─ title.text # the node's text, stored as small HTML
├─ note / task / tags / attachment
└─ subnodes[] # children (same shape, recursive)
canvas.crossConnections[] # free links between nodes
canvas.tags[] # tag definitionsThe server reads and writes this with Python's standard plistlib, so it needs no third-party plist libraries. Node text round-trips through a minimal HTML encode/decode (with proper escaping).
These tools mutate your real files, so every write:
contents.xml to a timestamped .bak-* first,create_map clones an existing document as a structural skeleton (keeping all opaque auxiliary files valid) and overwrites only the node tree.
Caveat — document open in MindNode. Writes go straight to disk. If MindNode (or another device via iCloud) has the same document open, its next autosave can clobber the change, or you may get an iCloud conflict copy. Close the document in MindNode before writing, or reopen it afterwards to pick up the edit. Backups make this recoverable, but it's cleaner to avoid.
uv run python tests/smoke.pyThe smoke test exercises reads against your real documents (read-only) and all writes against throwaway temp copies — it never modifies your actual maps. It also asserts that generated structures (nodes, connections, tags, tasks, image attachments) match the schema of real MindNode files key-for-key.
MIT © 2026 Masamitsu Konya
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.