{"_id":"@accreta/mcp-server","_rev":"4-4a6f563b22dc77039d37ac2d509423e9","name":"@accreta/mcp-server","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.1":{"name":"@accreta/mcp-server","version":"0.1.1","license":"MIT","_id":"@accreta/mcp-server@0.1.1","maintainers":[{"name":"francescofiore","email":"francesco.fiore.dev@gmail.com"}],"homepage":"https://github.com/francescofioredev/accreta#readme","bugs":{"url":"https://github.com/francescofioredev/accreta/issues"},"bin":{"accreta-mcp":"src/main.ts"},"dist":{"shasum":"1e5e55b883cc994165e1d8619615304b2ad69348","tarball":"https://registry.npmjs.org/@accreta/mcp-server/-/mcp-server-0.1.1.tgz","fileCount":7,"integrity":"sha512-qwJtQWkJ3GrXFKYYmXo83hYz4KW98ZNhqeVLPUiU8FpB0eqATdMOG9ENRQROcplsQOgvCwk3ZO6hD6ImHN6+qA==","signatures":[{"sig":"MEUCIExr48PMbKAX/HQ/uwIthbkr4i28afIDEVkClUYeb5HGAiEA8xUTy7TrkD9PtBdQqrENf8r0NA5qrJzlzBH/XP0cCdY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21472},"type":"module","engines":{"bun":">=1.3.13"},"exports":{".":"./src/index.ts"},"gitHead":"486e0b974e4de3d3bef2a264a2aa599e06ae60d0","_npmUser":{"name":"francescofiore","email":"francesco.fiore.dev@gmail.com"},"repository":{"url":"git+https://github.com/francescofioredev/accreta.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"11.9.0","description":"The agent-facing surface: MCP tools over a knowledge base.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"^4.1.0","@accreta/core":"0.1.1","@accreta/adapter-fs":"0.1.1","@accreta/adapter-git":"0.1.1","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-server_0.1.1_1786194727521_0.5427664971709163","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@accreta/mcp-server","version":"0.1.2","license":"MIT","_id":"@accreta/mcp-server@0.1.2","maintainers":[{"name":"francescofiore","email":"francesco.fiore.dev@gmail.com"}],"homepage":"https://github.com/francescofioredev/accreta#readme","bugs":{"url":"https://github.com/francescofioredev/accreta/issues"},"bin":{"accreta-mcp":"src/main.ts"},"dist":{"shasum":"3bbb85f096923edb4c74dd9b38570eb15770b837","tarball":"https://registry.npmjs.org/@accreta/mcp-server/-/mcp-server-0.1.2.tgz","fileCount":7,"integrity":"sha512-9ra4MKkqoIUIWezZ0GJrk9EjwZEEK4TsOrTD9gGRYAicDoFK+/S8tl5MNLPa3Zc8SOSc9hgeK7KPiiLq27hsDQ==","signatures":[{"sig":"MEYCIQCqGudaJjgYINXkzrRo5HbWGouOHdgOFOkZEMbCi2DsqgIhAIFT4WJB1EKM1ObWIIy6lUCBh9Z1MJrFUP7xvM3XrOe9","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@accreta%2fmcp-server@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":21472},"type":"module","engines":{"bun":">=1.3.13"},"exports":{".":"./src/index.ts"},"gitHead":"17491858877d5d7ac44e6d65e8b03ac5ee068aef","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c59a8d34-9c32-4031-bc9c-542e6a9cb850"}},"repository":{"url":"git+https://github.com/francescofioredev/accreta.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"12.0.2","description":"The agent-facing surface: MCP tools over a knowledge base.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^4.1.0","@accreta/core":"0.1.2","@accreta/adapter-fs":"0.1.2","@accreta/adapter-git":"0.1.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-server_0.1.2_1786296449795_0.6268399721201101","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@accreta/mcp-server","version":"0.1.3","license":"MIT","_id":"@accreta/mcp-server@0.1.3","maintainers":[{"name":"francescofiore","email":"francesco.fiore.dev@gmail.com"}],"homepage":"https://github.com/francescofioredev/accreta#readme","bugs":{"url":"https://github.com/francescofioredev/accreta/issues"},"bin":{"accreta-mcp":"src/main.ts"},"dist":{"shasum":"40259888c0b6fbb275bc645afd92bf724405369b","tarball":"https://registry.npmjs.org/@accreta/mcp-server/-/mcp-server-0.1.3.tgz","fileCount":7,"integrity":"sha512-2MGCSSMRewUeC7DcEmA1RtlBO7u50BkhWF8evsvmdx1qpmjFN+9lT82E0SfBhRBtDFwKKKe0CFG+zEDLJG0qzg==","signatures":[{"sig":"MEQCIA1D9/7I6+A5gtylYEcWqDuH12/SJUULiIQi3P7W0rXrAiBRrHI4fC6qrE/SNWLkKyyYKgnk7ixOzpNibcUua97cIQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@accreta%2fmcp-server@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":33668},"type":"module","engines":{"bun":">=1.3.13"},"exports":{".":"./src/index.ts"},"gitHead":"ed053ccf64fe990dfd2023cfe71745440438cee5","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c59a8d34-9c32-4031-bc9c-542e6a9cb850"}},"repository":{"url":"git+https://github.com/francescofioredev/accreta.git","type":"git","directory":"packages/mcp-server"},"_npmVersion":"12.0.2","description":"The agent-facing surface: MCP tools over a knowledge base.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.1.0","@accreta/core":"0.1.3","@accreta/adapter-fs":"0.1.3","@accreta/adapter-git":"0.1.3","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-server_0.1.3_1787726157941_0.7205767815365489","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@accreta/mcp-server","version":"0.1.4","type":"module","license":"MIT","description":"The agent-facing surface: MCP tools over a knowledge base.","homepage":"https://github.com/francescofioredev/accreta#readme","repository":{"type":"git","url":"git+https://github.com/francescofioredev/accreta.git","directory":"packages/mcp-server"},"bugs":{"url":"https://github.com/francescofioredev/accreta/issues"},"engines":{"bun":">=1.3.13"},"publishConfig":{"access":"public"},"bin":{"accreta-mcp":"src/main.ts"},"exports":{".":"./src/index.ts"},"dependencies":{"@accreta/adapters":"0.1.4","@accreta/core":"0.1.4","@modelcontextprotocol/sdk":"^1.30.0","zod":"^4.1.0"},"gitHead":"96b98e5dd6a554955e25c1759903f23f39dd4207","_id":"@accreta/mcp-server@0.1.4","_nodeVersion":"22.23.2","_npmVersion":"12.0.2","dist":{"integrity":"sha512-kk0raPAX6aDJuzTLIHrPM3aMlmghonFgyOump9p5Ge1VxfA7Grcawfv2Bj80nSutPinEWKaVQCuE8wMW+ZCZwg==","shasum":"e24d7e74ab7d5ab93a506fdd3400680ae3881e28","tarball":"https://registry.npmjs.org/@accreta/mcp-server/-/mcp-server-0.1.4.tgz","fileCount":7,"unpackedSize":34094,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@accreta%2fmcp-server@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDn+qG8WQQWUQLXu4mKBHzkgPhC+iSkJEzn4j+Ix/hoJAIhAMQTFFlkhCefMeUhTci43lo/39+0liswm1ooq1Nxf8at"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c59a8d34-9c32-4031-bc9c-542e6a9cb850"}},"directories":{},"maintainers":[{"name":"francescofiore","email":"francesco.fiore.dev@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server_0.1.4_1788896722571_0.926636783349424"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-08T13:12:07.365Z","modified":"2026-09-08T19:45:23.116Z","0.1.1":"2026-08-08T13:12:07.681Z","0.1.2":"2026-08-09T17:27:29.937Z","0.1.3":"2026-08-26T06:35:58.069Z","0.1.4":"2026-09-08T19:45:22.717Z"},"bugs":{"url":"https://github.com/francescofioredev/accreta/issues"},"license":"MIT","homepage":"https://github.com/francescofioredev/accreta#readme","repository":{"type":"git","url":"git+https://github.com/francescofioredev/accreta.git","directory":"packages/mcp-server"},"description":"The agent-facing surface: MCP tools over a knowledge base.","maintainers":[{"name":"francescofiore","email":"francesco.fiore.dev@gmail.com"}],"readme":"# @accreta/mcp-server\n\nThe agent-facing surface. Exposes a knowledge base as MCP tools over stdio.\n\n## Configuring a client\n\n`.mcp.json`, in the project the agent is working in:\n\n```json\n{\n  \"mcpServers\": {\n    \"accreta\": {\n      \"command\": \"bun\",\n      \"args\": [\"run\", \"node_modules/@accreta/mcp-server/src/main.ts\"],\n      \"env\": {\n        \"ACCRETA_ROOT\": \"../path/to/knowledge-base\"\n      }\n    }\n  }\n}\n```\n\n`ACCRETA_ROOT` is how an agent working in one directory queries a knowledge base living in\nanother — it needs no filesystem access to the knowledge base itself, only to this server.\n\n## Tools\n\n| Tool | Purpose |\n|---|---|\n| `search_pages` | Full-text search with type and source filters. The primary discovery tool. |\n| `get_page` | Fetch a page by path or wikilink target. |\n| `find_consumers` | Impact analysis across the link graph, both directions. |\n| `find_canonical` | Resolve a term, including aliases, to the page that defines it. |\n| `check_drift` | Which pages their sources have moved out from under. |\n| `list_recent_changes` | What changed in a source since a revision. |\n| `lint_knowledge_base` | Unresolvable links, missing provenance, unknown page types, and a count of the citations it could not check. |\n| `update_verified_revision` | Write. Registered only when `ACCRETA_ALLOW_WRITES=1`. |\n\n## Which fields a page author wrote\n\nThe five tools that relay page text return a `_provenance` block naming the fields that carry it:\n\n```json\n{\n  \"count\": 1,\n  \"results\": [{ \"path\": \"…\", \"title\": \"…\", \"snippet\": \"…\" }],\n  \"_provenance\": {\n    \"page_derived_fields\": [\"results[].title\", \"results[].snippet\"],\n    \"notice\": \"… This label raises an attacker's cost; it does not prevent prompt injection.\"\n  }\n}\n```\n\nValues are byte-identical to what the page contains — the block names fields rather than\ndelimiting them, because a delimiter is itself a string the page author can write, and mangling\nvalues would cost `get_page` its body fidelity.\n\n`search_pages` additionally returns `matched_aliases` on a hit whose match an alias explains.\nAliases are indexed but never displayed, so a page whose title and body are both benign could\nsurface on an alias alone and the hit looked unmotivated. The field is omitted when no alias\nmatched, and it never carries the page's whole alias list.\n\n**This is labelling, not a control.** It prevents nothing: any defence living inside the same\nagent loop the injection controls is defeated by the same move. It raises an attacker's cost and\ntells a reading model which text it should treat as data.\n\n## Four outcomes, not two\n\n`check_drift` distinguishes results that a simpler design would collapse:\n\n- **`stale`** — the source changed since the page was verified.\n- **`unverifiable`** — the page records no revision, so nothing can be said about it.\n- **`unresolvable`** — the source cannot place the revision the page names. History was\n  rewritten, or the revision came from a previous run of an `fs` source.\n- **`delegated`** — accreta cannot reach the source at all; the agent can. Carries the\n  connector, the declared scope, and the pages grouped by the revision they are stuck at.\n  `current_revision` is `null`, because there is no honest string to put there.\n\nOnly the absence of all four means \"current\". Reporting `unresolvable` as \"up to date\" would\nbe a claim the system has no basis for, which is why `list_recent_changes` returns\n`unresolvable: true` rather than an empty change list — and it returns `delegated: true` with\nthe scope instead, because \"nobody asked\" and \"the revision is lost\" are different instructions\nto whoever reads them.\n\n`lint_knowledge_base` draws the same distinction with `citations_unchecked`: a count rather\nthan findings, because a citation into a source nothing here can question was not found to be\nwrong, it was not examined.\n\n## Writes\n\n`update_verified_revision` is the only tool that writes, and it is gated twice.\n\n1. **`ACCRETA_ALLOW_WRITES=1`** must be set or the tool is not registered at all — a\n   read-only deployment does not advertise a capability it will refuse.\n2. **Dry run, then confirm.** The first call returns a description of the edit and a\n   `confirm_token`; the second must echo it back.\n\nThe token is a hash of the page, the new revision and the *current* value, so it cannot be\nproduced without having run the dry run and cannot be reused for a different edit. A plain\n`confirm: true` flag would let a model skip straight to writing.\n\nWhat that handshake does **not** do is decide *whether* the edit should happen. It confirms an\nintent; it does not authorize one. An agent that is following an instruction it read inside a\npage will run the dry run and echo the token back, because doing so is simply the protocol for\ngetting to the write — the two steps are a sequence it can complete unaided. So enabling writes\nextends trust to whoever authored the corpus, not only to whoever is operating the agent. Pages\nare untrusted input to the model; see\n[the README](../../README.md#pages-are-untrusted-input-to-the-model).\n\nThe tool edits the markdown and asks for a reindex rather than updating the index directly.\nThe index is derived; writing to it would put it out of step with the pages it comes from.\n","readmeFilename":"README.md"}