io.github.midosresearch/midos-mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited io.github.midosresearch/midos-mcp (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MidOS MCP Community Library — Knowledge, Skills, and Research as MCP tools.
Install once, connect to any AI client.
pip install midos-mcpRequirement: MidOS knowledge base must be available locally. Set the MIDOS_ROOT environment variable to point to your MidOS installation directory (the one containing knowledge/ and modules/).
export MIDOS_ROOT=/path/to/midos# Start server (stdio — default for Claude Code, Cursor, etc.)
midos-mcp serve
# Start with HTTP transport
midos-mcp serve --http
# Generate config for your AI client
midos-mcp config --generate claude
midos-mcp config --generate cursor
# Check health
midos-mcp healthmidos-mcp serveStart the MCP server with your preferred transport.
midos-mcp serve # stdio (default)
midos-mcp serve --http # Streamable HTTP on 127.0.0.1:8419
midos-mcp serve --sse # Legacy SSE transport
midos-mcp serve --http --host 0.0.0.0 --port 9000| Flag | Transport | Use Case |
|---|---|---|
--stdio | stdio | Claude Code, Cursor, Cline (default) |
--http | Streamable HTTP | Web clients, remote access |
--sse | Server-Sent Events | Legacy clients |
midos-mcp configGenerate ready-to-paste JSON config for any supported MCP client.
midos-mcp config --generate claude # Claude Desktop / Claude Code
midos-mcp config --generate cursor # Cursor IDE
midos-mcp config --generate cline # Cline (VS Code)
midos-mcp config --generate windsurf # Windsurf IDE
midos-mcp config --generate continue # Continue.dev
midos-mcp config --generate zed # Zed Editor
midos-mcp config --generate opencode # OpenCode
midos-mcp config --generate http # Generic HTTP client
# Write to file
midos-mcp config --generate claude -o mcp-config.jsonmidos-mcp healthCheck server health: knowledge base stats, vector store status, dependencies.
midos-mcp health # Human-readable output
midos-mcp health --json # JSON output for scriptsmidos-mcp keysManage API keys for tiered access control.
midos-mcp keys generate --name "my-app" --tier dev
midos-mcp keys list
midos-mcp keys revoke midos_sk_abcTiers: dev (free), pro ($10/mo), admin.
| Variable | Default | Description |
|---|---|---|
MIDOS_ROOT | auto-detect | Path to MidOS installation (required) |
MIDOS_HOST | 127.0.0.1 | HTTP server bind host |
MIDOS_PORT | 8419 | HTTP server bind port |
MIDOS_TRANSPORT | stdio | Default transport |
The server locates the MidOS knowledge base:
MIDOS_ROOT environment variable (recommended)CLAUDE.md + knowledge/If you installed via pip, auto-detect won't find the knowledge base. Either:
# Option A: Clone the repo and point to it
git clone https://github.com/MidOSresearch/midos.git
export MIDOS_ROOT=./midos
# Option B: Point to an existing MidOS directory
export MIDOS_ROOT=/path/to/your/midosVerify with midos-mcp health — it shows the detected root and knowledge counts.
| Client | Config File | Transport |
|---|---|---|
| Claude Desktop | claude_desktop_config.json | stdio |
| Claude Code | .mcp.json | stdio |
| Cursor | .cursor/mcp.json | stdio |
| Cline | cline_mcp_settings.json | stdio |
| Windsurf | ~/.codeium/windsurf/mcp_config.json | stdio |
| Continue.dev | ~/.continue/config.json | stdio |
| Zed | ~/.config/zed/settings.json | stdio |
| OpenCode | opencode.json | SSE |
# Vector store support (LanceDB + embeddings)
pip install midos-mcp[vector]
# Development tools
pip install midos-mcp[dev]MidOS exposes 68 MCP tools across 2 tiers:
| Tier | Tools | Access |
|---|---|---|
| Dev | 34 tools | Free — no API key needed, full content, 500 queries/month |
| Pro | 68 tools | $10/mo — security ops, AOTC, orchestration, maker write ops |
| Tier | Queries/month | Content |
|---|---|---|
| Dev | 500 | Full content (no truncation) |
| Pro | 100,000 | Full content + AOTC + ops packs |
Invalid or expired API keys silently fall back to Dev tier.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.