com.mcparmory/linkly
OCI · GHCR.IO/MCPARMORY/LINKLY:1.0.3 · 2 COMPONENTS · SCANNED SEP 20
Create short links, manage domains, and track click analytics
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security0
- Malware scan not yet available for this package.Unverified
- Known CVEs could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.Unverified
- Install-script risk not yet assessed.Unverified
- Dependency health could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.Unverified
Provenance & Transparency32
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: no license is declared. See how to fix → Fail
- Actively maintained (last published 130 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability70
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3167 tokens (~175/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
- Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the com.mcparmory/linkly MCP server?
com.mcparmory/linkly runs locally as a container image, launched with docker run --rm -i ghcr.io/mcparmory/linkly:1.0.3. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.
oci · ghcr.io/mcparmory/linkly:1.0.3
claude mcp add com-mcparmory-linkly -- docker run --rm -i ghcr.io/mcparmory/linkly:1.0.3
{
"mcpServers": {
"com-mcparmory-linkly": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/mcparmory/linkly:1.0.3"
]
}
}
} {
"servers": {
"com-mcparmory-linkly": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/mcparmory/linkly:1.0.3"
]
}
}
} codex mcp add com-mcparmory-linkly -- docker run --rm -i ghcr.io/mcparmory/linkly:1.0.3
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-mcparmory-linkly": {
"type": "local",
"command": [
"docker",
"run",
"--rm",
"-i",
"ghcr.io/mcparmory/linkly:1.0.3"
],
"enabled": true
}
}
} mcp_servers:
com-mcparmory-linkly:
command: "docker"
args: ["run", "--rm", "-i", "ghcr.io/mcparmory/linkly:1.0.3"] {
"McpServers": {
"com-mcparmory-linkly": {
"Transport": "stdio",
"Command": "docker",
"Arguments": [
"run",
"--rm",
"-i",
"ghcr.io/mcparmory/linkly:1.0.3"
]
}
}
} {
"mcpServers": {
"com-mcparmory-linkly": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/mcparmory/linkly:1.0.3"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 −3
- Stability: pass → 0.80 functional
- 17 Sept 26 0
- Stability: 0.97 → pass security
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 −3
- Stability: pass → 0.80 functional
- 10 Sept 26 0
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed oci/ghcr.io/mcparmory/linkly:1.0.3
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | oci |
| Reason | No attestation published |
Background: How many MCP packages publish verified provenance →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_domain_to_workspace Add Domain to Workspace ~70
Add a new custom domain to your workspace. Ensure DNS CNAME record configuration is completed before adding the domain.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | – | The name of the custom domain to add to your workspace. |
| workspace_id | integer | yes | The unique identifier of the workspace where the domain will be added. |
No output schema declared.
No examples provided.
add_domain_to_workspace_by_id Add Domain to Workspace ~91
Add a custom domain to a workspace. The domain must have a CNAME record configured in DNS before being added.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | The fully qualified domain name to add (e.g., links.example.com). Ensure the corresponding CNAME record is configured in your DNS provider before adding. |
| workspace_id | string | yes | The unique identifier of the workspace where the domain will be added. |
No output schema declared.
No examples provided.
create_or_update_link Create or Update Link ~599
Create a new shortened link or update an existing one. Provide `url` and `workspace_id` to create; provide `id` and fields to update. Supports custom slugs, UTM parameters, tracking pixels, Open Graph metadata, and conditional redirect rules.
| Name | Type | Req | Description |
|---|---|---|---|
| block_bots | boolean | – | Prevent automated bots and crawlers from accessing this link. |
| body_tags | string | – | Custom HTML tags to inject into the page body for tracking or functionality purposes. |
| cloaking | boolean | – | Enable URL cloaking to hide the destination URL from users and analytics. |
| deleted | boolean | – | Mark the link as deleted. Set to true to soft-delete without removing the record. |
| enabled | boolean | – | Enable or disable the link. Disabled links will not redirect. |
| fb_pixel_id | string | – | Facebook Pixel ID for conversion tracking and audience building. |
| forward_params | boolean | – | Forward query parameters from the shortened link to the destination URL. |
| ga4_tag_id | string | – | Google Analytics 4 measurement ID for tracking link performance. |
| gtm_id | string | – | Google Tag Manager container ID for advanced event tracking and tag management. |
| head_tags | string | – | Custom HTML tags to inject into the page head for scripts, metadata, or tracking. |
| hide_referrer | boolean | – | Hide the HTTP referrer header when redirecting to prevent the destination from seeing the source. |
| id | integer | – | Unique identifier of the link to update. Required when updating an existing link; omit when creating new. |
| linkify_words | string | – | Comma-separated list of words to automatically convert into links within the destination page content. |
| name | string | – | Human-readable name or title for the link to aid organization and identification. |
| note | string | – | Internal note or memo for reference; not visible to end users. |
| og_description | string | – | Open Graph description displayed when the link is shared on social media platforms. |
| og_image | string | – | Open Graph image URL displayed when the link is shared on social media platforms. |
| og_title | string | – | Open Graph title displayed when the link is shared on social media platforms. |
| replacements | string | – | String-encoded replacement rules for dynamic URL parameter substitution or content modification. |
| rules | array | – | Array of conditional redirect rules that determine the destination URL based on user attributes, device type, or other criteria. Rules are evaluated in order. |
| slug | string | – | Custom URL slug for the shortened link. If omitted, a random slug is generated automatically. |
| spam | boolean | – | Mark the link as spam or suspicious content. |
| tiktok_pixel_id | string | – | TikTok Pixel ID for conversion tracking and audience building on TikTok. |
| url | string | – | Destination URL to redirect to. Required when creating a new link; must be a valid URI. |
| workspace_id | integer | – | Workspace ID |
No output schema declared.
No examples provided.
create_or_update_link_batch Create or Update Links in Batch ~746
Create a new link or update an existing one in a workspace. Include an 'id' field to update an existing link, or omit it to create a new one. Supports batch operations by accepting an array of links.
| Name | Type | Req | Description |
|---|---|---|---|
| block_bots | boolean | – | When enabled, blocks traffic from known bots and automated crawlers. |
| body_tags | string | – | Custom HTML tags to inject into the body section of the destination page. |
| cloaking | boolean | – | When enabled, hides the actual destination URL and displays a cloaked URL instead. |
| domain_id | integer | – | Numeric identifier of the domain to use for this link. Use this as an alternative to specifying a domain name. |
| enabled | boolean | – | Controls whether the link is active and functional. Set to false to disable without deleting. |
| expiry_clicks | integer | – | Number of clicks after which the link automatically expires and becomes inactive. |
| expiry_datetime | string | – | Date and time when the link automatically expires and becomes inactive. Use ISO 8601 format. |
| expiry_destination | string | – | URL to redirect users to after the link expires. |
| fb_pixel_id | string | – | Facebook Pixel ID for tracking conversions on Facebook. |
| forward_params | boolean | – | When enabled, query parameters from the shortened link are automatically forwarded to the destination URL. |
| ga4_tag_id | string | – | Google Analytics 4 measurement ID for tracking events and conversions. |
| gtm_id | string | – | Google Tag Manager container ID for tracking and analytics. |
| head_tags | string | – | Custom HTML tags to inject into the head section of the destination page. |
| hide_referrer | boolean | – | When enabled, prevents the referrer information from being passed to the destination URL. |
| id | integer | – | Numeric identifier of an existing link to update. Omit this field to create a new link. |
| linkify_words | string | – | Specific words within the link that should be converted into clickable links. |
| name | string | – | Human-readable nickname or label for this link to help identify it in your workspace. |
| note | string | – | Private internal note for reference; not visible to end users. |
| og_description | string | – | Open Graph description text displayed when the link is shared on social media. |
| og_image | string | – | URL of an image to display when the link is shared on social media. |
| og_title | string | – | Open Graph title text displayed when the link is shared on social media. |
| public_analytics | boolean | – | When enabled, analytics data for this link is publicly accessible without authentication. |
| qr_styles | object | – | Object containing styling options for QR codes generated from this link, such as colors and patterns. |
| replacements | string | – | URL parameter replacements to transform or modify query parameters before forwarding to the destination. |
| rules | array | – | Array of redirect rules that determine where users are sent based on conditions like device type, location, or custom parameters. |
| skip_social_crawler_tracking | boolean | – | When enabled, prevents tracking of requests from social media crawlers and bots. |
| slug | string | – | Custom URL slug for this link. Must start with a forward slash (/) and be unique within the workspace. |
| tiktok_pixel_id | string | – | TikTok Pixel ID for tracking conversions on TikTok. |
| url | string | yes | The destination URL where users will be redirected. Must be a valid URI. |
| webhooks | array | – | Array of webhook URLs that receive notifications when link events occur, such as clicks or conversions. |
| workspace_id | string | yes | The workspace identifier where the link will be created or updated. |
No output schema declared.
No examples provided.
delete_domain Delete Domain ~70
Remove a custom domain from your workspace. Once deleted, any links using this domain will no longer be functional.
| Name | Type | Req | Description |
|---|---|---|---|
| domain_id | string | yes | The unique identifier of the domain to be removed from the workspace. |
| workspace_id | string | yes | The unique identifier of the workspace containing the domain to be deleted. |
No output schema declared.
No examples provided.
delete_link Delete Link ~61
Permanently delete a specific link from a workspace by its ID. This action cannot be undone.
| Name | Type | Req | Description |
|---|---|---|---|
| id | integer | yes | The unique identifier of the link to delete. |
| workspace_id | string | yes | The unique identifier of the workspace containing the link to delete. |
No output schema declared.
No examples provided.
delete_links Delete Links ~70
Permanently delete one or more links from a workspace by their IDs. This action cannot be undone.
| Name | Type | Req | Description |
|---|---|---|---|
| ids | array | – | Array of link IDs to delete. If not provided, no links will be deleted. |
| workspace_id | string | yes | The unique identifier of the workspace containing the links to delete. |
No output schema declared.
No examples provided.
delete_webhook_from_link Delete Webhook from Link ~99
Remove a webhook subscription from a link by unsubscribing the specified webhook URL. This operation permanently deletes the webhook subscription relationship.
| Name | Type | Req | Description |
|---|---|---|---|
| hook_id | string | yes | The webhook URL to unsubscribe, provided in URL-encoded format (e.g., https%3A%2F%2Fhooks.example.com%2Fabc123). |
| link_id | integer | yes | The unique identifier of the link from which to remove the webhook subscription. |
No output schema declared.
No examples provided.
export_links Export Links ~97
Export all links in a workspace in JSON or CSV format, with optional filtering by search query.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | The output format for the exported links. Choose between JSON (default) or CSV. |
| search | string | – | Optional search query to filter which links are included in the export. Only links matching the query will be returned. |
| workspace_id | string | yes | The unique identifier of the workspace containing the links to export. |
No output schema declared.
No examples provided.
get_click_counters_by_dimension Get Click Counters by Dimension ~275
Retrieve aggregated click analytics grouped by a specified dimension (such as country, platform, or browser). Returns click counts for each unique value within the selected dimension, with optional filtering by date range, country, and response format.
| Name | Type | Req | Description |
|---|---|---|---|
| counter | string | yes | The dimension to group clicks by. Choose from: country (geographic location), platform (device type), browser (web browser), referer (HTTP referrer), isp (internet service provider), link_id (specifi… |
| country | string | – | Filter results to a specific country using its ISO 3166-1 alpha-2 country code (e.g., 'US', 'GB', 'DE'). If omitted, all countries are included. |
| end | string | – | The end date for filtering analytics data, specified in YYYY-MM-DD format. If omitted, defaults to the current date. |
| format | string | – | The response format for the analytics data. Choose from JSON (default, structured format), CSV (comma-separated values), or TSV (tab-separated values). |
| start | string | – | The start date for filtering analytics data, specified in YYYY-MM-DD format. If omitted, defaults to the earliest available data. |
| workspace_id | string | yes | The workspace identifier that contains the click analytics data. |
No output schema declared.
No examples provided.
get_clicks_analytics Get Clicks Analytics ~420
Retrieve click analytics for a workspace with flexible filtering and aggregation options. Returns time-series data suitable for charting, with support for multiple output formats and pivot transformations.
| Name | Type | Req | Description |
|---|---|---|---|
| browser | string | – | Filter results to clicks from a specific browser (e.g., Chrome, Firefox, Safari). |
| country | string | – | Filter results to clicks from a specific country using its ISO 3166-1 alpha-2 code (e.g., US, GB, DE). |
| end | string | – | The end date for filtering clicks, specified in ISO 8601 format (YYYY-MM-DD or YYYY-MM-DDTHH:MM:SSZ). If omitted, defaults to the current date. |
| format | string | – | Specify the response format: 'json' (default), 'csv', or 'tsv'. |
| frequency | string | – | The time granularity for aggregating data points: 'day' (default) for daily buckets or 'hour' for hourly buckets. |
| isp | string | – | Filter results to clicks from a specific Internet Service Provider. |
| pivot | string | – | Transform the response into a matrix format where dates appear as rows and links as columns. When set to 'link_id', CSV/TSV responses include header rows with link name, full URL, and ID. |
| platform | string | – | Filter results to clicks from a specific platform or operating system (e.g., Windows, Mac, iOS, Android). |
| referer | string | – | Filter results to clicks originating from a specific referrer domain. |
| start | string | – | The start date for filtering clicks, specified in ISO 8601 format (YYYY-MM-DD or YYYY-MM-DDTHH:MM:SSZ). If omitted, defaults to the beginning of available data. |
| timezone | string | – | The timezone to apply for date and time calculations (e.g., America/New_York). Affects how dates are bucketed and displayed. |
| workspace_id | string | yes | The unique identifier of the workspace to retrieve click analytics for. |
No output schema declared.
No examples provided.
get_link Get Link ~41
Retrieve detailed information about a specific link by its unique identifier.
| Name | Type | Req | Description |
|---|---|---|---|
| id | integer | yes | The unique identifier of the link to retrieve (e.g., 24). |
No output schema declared.
No examples provided.
get_link_analytics Get Link Analytics ~75
Retrieve detailed information about a specific link, including click statistics, UTM parameters, and configuration settings.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The unique identifier of the link to retrieve. Use the link ID provided when the link was created. |
| workspace_id | string | – | Workspace ID. Optional when using OAuth2 Bearer token. |
No output schema declared.
No examples provided.
list_domains List Domains ~49
Retrieve all custom domains configured for a workspace. These domains can be used as targets when creating short links.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace_id | string | yes | The unique identifier of the workspace whose domains you want to list. |
No output schema declared.
No examples provided.
list_links List Links ~185
Retrieve a paginated list of all links in a workspace with support for searching, sorting, and filtering. Results include click statistics and link metadata for each entry.
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | – | The page number for pagination, starting from 1. Defaults to the first page if not specified. |
| page_size | integer | – | The maximum number of links to return per page. Defaults to 1000 if not specified. |
| search | string | – | Optional search query to filter links by matching against link properties. Searches across relevant link fields to narrow results. |
| sort_by | string | – | The field name to sort results by. Common sortable fields include creation date, click count, and link name. |
| sort_dir | string | – | The sort direction for results: ascending or descending order. |
| workspace_id | string | yes | The unique identifier of the workspace containing the links to retrieve. |
No output schema declared.
No examples provided.
list_webhooks_for_link List Webhooks for Link ~64
Retrieve all webhook subscriptions configured for a specific link. Returns a list of webhooks that are actively monitoring events for the given link.
| Name | Type | Req | Description |
|---|---|---|---|
| link_id | integer | yes | The unique identifier of the link whose webhooks you want to retrieve. Must be a positive integer. |
No output schema declared.
No examples provided.
list_workspaces List Workspaces ~34
Retrieve all workspaces accessible to the authenticated user. Use this operation to discover available workspace IDs for use in other API calls.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
update_domain_favicon Update Domain Favicon ~121
Update the favicon URL for a custom domain within a workspace. The favicon will be displayed in browser tabs and bookmarks for the domain.
| Name | Type | Req | Description |
|---|---|---|---|
| favicon_url | string | – | A valid URI pointing to the favicon image file. Common formats include .ico, .png, and .svg. If omitted, the favicon will not be updated. |
| id | string | yes | The unique identifier of the domain whose favicon should be updated. Typically a numeric ID. |
| workspace_id | string | yes | The unique identifier of the workspace containing the domain. Typically a numeric ID. |
No output schema declared.
No examples provided.
What is the com.mcparmory/linkly MCP server?
com.mcparmory/linkly is an MCP server listed in the public MCP registry as com.mcparmory/linkly. Create short links, manage domains, and track click analytics. This page covers its container image (ghcr.io/mcparmory/linkly:1.0.3).
Is the com.mcparmory/linkly MCP server safe to use?
com.mcparmory/linkly scores 49 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the com.mcparmory/linkly MCP server expose?
com.mcparmory/linkly exposes 18 tools: add_domain_to_workspace, get_link, create_or_update_link, get_link_analytics, list_webhooks_for_link, and 13 more. Their descriptions and schemas cost roughly 3,167 tokens of context every time the server is loaded.
Is the com.mcparmory/linkly MCP server still maintained?
com.mcparmory/linkly is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.