Citadel Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Citadel Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Code Mode MCP server that gives AI coding agents curated, per-stack documentation as typed tools.
Citadel is built to be forked and tailored. The hosted package ships with a small starter set of stacks, but the real value comes from packaging the docs your agents actually need. Each stack is a tiny module — adding one is mostly mechanical.
Install the MCP server for all your coding agents:
npx add-mcp citadel-mcp@latestAdd -y to skip the confirmation prompt and install to all detected agents already in use in the project directory. Add -g to install globally across all projects.
Add the following config to your MCP client:
{
"mcpServers": {
"citadel": {
"command": "npx",
"args": ["-y", "citadel-mcp@latest"]
}
}
}[!NOTE] Using citadel-mcp@latest ensures that your MCP client will always use the latest version of the Citadel MCP server.<details> <summary>Amp</summary>
Using Amp CLI:
amp mcp add citadel -- npx citadel-mcp@latestOr configure manually:
Follow Amp's MCP documentation and apply the standard configuration shown above.
</details>
<details> <summary>Claude Code</summary>
Use the Claude Code CLI to add the Citadel MCP server:
claude mcp add -s user citadel -- npx -y citadel-mcp@latestUse -s project instead of -s user to scope the install to the current project. Restart Claude Code, then verify with claude mcp list. A working server advertises a single tool named docs.
</details>
<details> <summary>Codex</summary>
Using Codex CLI:
codex mcp add citadel -- npx citadel-mcp@latestOr configure manually:
Follow the MCP setup guide with the standard configuration format:
npx-y, citadel-mcp@latest</details>
<details> <summary>Cursor</summary>
Go to Cursor Settings -> MCP -> New MCP Server. Use the JSON config provided above.
</details>
<details> <summary>Gemini</summary>
Using Gemini CLI:
Project-wide installation:
gemini mcp add citadel npx citadel-mcp@latestGlobal installation:
gemini mcp add -s user citadel npx citadel-mcp@latest</details>
<details> <summary>VS Code / Copilot</summary>
Using VS Code CLI:
code --add-mcp '{"name":"citadel","command":"npx","args":["-y","citadel-mcp@latest"]}'Or configure manually:
Follow the official VS Code MCP server setup guide and add the Citadel server through VS Code settings.
</details>
<details> <summary>Warp</summary>
Navigate to Settings | AI | Manage MCP Servers and select + Add to register a new MCP server with the following configuration:
citadelnpx-y, citadel-mcp@latest</details>
The hosted package includes a starter set of stacks so you can try it immediately:
This list is intentionally small. For the best results, fork this repo and add the stacks your agents care about — your internal libraries, the framework version you actually use, or any docs site that publishes machine-readable markdown. See docs/adding-a-docs-tool.md.
Citadel is a Code Mode server: instead of advertising one tool per docs source, it advertises a single docs tool. The agent writes one async () => { ... } per turn that calls codemode.<stack>_docs(...) and codemode.<stack>_index() directly, and the server runs that code in a local Node sandbox. N doc fetches collapse into one round-trip.
Each stack contributes two callable tools to the sandbox SDK:
<stack>_index() — returns the doc index so the agent can pick a valid path<stack>_docs({ path }) — fetches that specific doc as markdownCitadel also exposes a cross-stack ranked search: codemode.docs_search({ query, stacks?, fetch: true }) returns BM25-ranked matches with markdown content attached in a single call.
docs tool, served at runtime as MCP resource citadel://docs/agent-usage. SDK reference, parallel fan-out, error handling, worked examples.<stack>_index + <stack>_docs.To run the MCP server locally for development:
pnpm install
pnpm build {
"mcpServers": {
"citadel-dev": {
"command": "node",
"args": ["/absolute/path/to/citadel-mcp/dist/index.js"]
}
}
}Or with the Claude Code CLI:
claude mcp add -s user citadel-dev -- node /absolute/path/to/citadel-mcp/dist/index.jsFor development with auto-reload, point the MCP client at tsx and the src entry instead:
claude mcp add -s user citadel-dev -- npx tsx /absolute/path/to/citadel-mcp/src/index.tsMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.