Docshub — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Docshub (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that provides AI clients with access to developer documentation via llms.txt files. Exposes tools, resources, and prompts.
You must have uv installed on your machine. (macOS/Linux: `curl -LsSf https://astral.sh/uv/install.sh | sh`)
DocsHub loads its project list from a docs_config.yaml file. Sources are tried in this order:
https:// URL pointing to a raw YAML file (e.g. a file hosted in a GitHub repository)docs_config.yaml in the DocsHub repo (used automatically as a fallback when no other config is found)The YAML format:
projects:
- name: "FastAPI"
description: "FastAPI official documentation"
llms_txt_url: "https://fastapi.tiangolo.com/llms.txt"Using a remote config from a GitHub repository:
Set DOCSHUB_CONFIG to the raw file URL:
DOCSHUB_CONFIG=https://raw.githubusercontent.com/ORG/docshub/main/docs_config.yamlYou can pass this to any AI client as an environment variable in its MCP server configuration (see Client Setup below).
| Variable | Default | Description |
|---|---|---|
DOCSHUB_CONFIG | (none) | Local file path or https:// URL to the config file. |
DOCSHUB_CONFIG_RELOAD_INTERVAL | 900 | Seconds between config reload checks. The server polls this source in the background and notifies clients when the project list changes. Set to 0 to disable polling entirely. |
DOCSHUB_CACHE_TTL | 1800 | Seconds to cache fetched documentation in memory. Subsequent tool calls within the TTL window are served instantly without a network round-trip. Set to 0 to disable caching. |
Claude Desktop, VS Code Cline, and GitHub Copilot CLI use the same JSON format. Add this block to the mcpServers object in each client's config file (see per-client instructions below):
{
"mcpServers": {
"docshub": {
"command": "uvx",
"args": [
"--from", "git+https://github.com/rkratky/docshub",
"docshub"
]
}
}
}To load a remote docs_config.yaml, add an env key:
{
"mcpServers": {
"docshub": {
"command": "uvx",
"args": [
"--from", "git+https://github.com/rkratky/docshub",
"docshub"
],
"env": {
"DOCSHUB_CONFIG": "https://raw.githubusercontent.com/ORG/docshub/main/docs_config.yaml"
}
}
}
}~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.jsonmcpServers object.cline_mcp_settings.json.mcpServers object.GitHub Copilot in VS Code uses VS Code's native MCP configuration, which has a slightly different format.
Option A — User settings (available across all workspaces):
Ctrl+, → Open Settings (JSON) (top-right icon).{
"mcp": {
"servers": {
"docshub": {
"type": "stdio",
"command": "uvx",
"args": [
"--from", "git+https://github.com/rkratky/docshub",
"docshub"
]
}
}
}
}Option B — Workspace settings (scoped to a single project):
Create or edit .vscode/mcp.json in your project root:
{
"servers": {
"docshub": {
"type": "stdio",
"command": "uvx",
"args": [
"--from", "git+https://github.com/rkratky/docshub",
"docshub"
]
}
}
}After saving, open GitHub Copilot Chat — the docshub tools will be available automatically.
Run this command once to register the server at user scope:
claude mcp add --scope user docshub -- \
uvx --from git+https://github.com/rkratky/docshub docshubTo use a remote docs_config.yaml, set the environment variable before running the command or add it to your shell profile:
export DOCSHUB_CONFIG=https://raw.githubusercontent.com/ORG/docshub/main/docs_config.yamlEdit ~/.copilot/mcp-config.json (created automatically by the CLI the first time you run it; you can also create it manually) and add the configuration block above to the mcpServers object.
To use a remote docs_config.yaml, add an env key to the server entry:
{
"mcpServers": {
"docshub": {
"command": "uvx",
"args": [
"--from", "git+https://github.com/rkratky/docshub",
"docshub"
],
"env": {
"DOCSHUB_CONFIG": "https://raw.githubusercontent.com/ORG/docshub/main/docs_config.yaml"
}
}
}
}The config file location can be changed by setting the COPILOT_HOME environment variable.
DocsHub exposes three types of MCP primitives: tools (called automatically by the AI), resources (attached to context on demand), and prompts (predefined conversation starters).
The AI calls these automatically when you ask about documentation:
| Tool | Description |
|---|---|
list_available_docs | Lists configured projects. Always called first to discover what's available. |
get_project_docs | Fetches documentation for a project. Tries llms-full.txt first (complete docs); falls back to llms.txt (an index of page URLs) if unavailable. |
read_doc_page | Fetches a specific page by URL. Only needed when get_project_docs returned an llms.txt index. |
Example: "Check the docs for FastAPI and show me how to write a route."
Performance note: fetched documentation is cached in memory for 30 minutes by default (DOCSHUB_CACHE_TTL); set to0to disable caching. The server also polls the config source in the background every 15 minutes (DOCSHUB_CONFIG_RELOAD_INTERVAL) and notifies connected clients when the project list changes, so doc sets can be added or removed without restarting the server; set to0to disable polling.
Resources provide structured access to the documentation registry and content. Attach them to your conversation context when you want to ground the AI in a specific project's docs.
| URI | Description |
|---|---|
docshub://projects | JSON list of all configured projects with names and descriptions. |
docshub://project/{name}/docs | Raw documentation content for the named project. |
Prompts are predefined conversation starters for common documentation tasks. How to invoke them depends on your AI client (look for a prompt/slash-command picker or similar):
| Prompt | Arguments | Description |
|---|---|---|
query_docs | project_name, question | Answer a specific question using a project's documentation. |
summarize_project | project_name | Produce a structured overview of a project's docs. |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.