io.github.Lucav21/heu-mcp
PYPI · HEU-MCP · SCANNED SEP 20
HEU Legal e-signature MCP: manage HEU documents and PDFs, prompt signers, download PDFs.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
- 0 of 35 dependencies flagged as unhealthy. View diagnostics → Pass
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 25 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability74
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3347 tokens (~119/item across 28 items; 28 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
- Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.Lucav21/heu-mcp server?
io.github.Lucav21/heu-mcp runs locally as a PyPI package, launched with uvx heu-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · heu-mcp
claude mcp add lucav21-heu-mcp -- uvx heu-mcp
{
"mcpServers": {
"lucav21-heu-mcp": {
"command": "uvx",
"args": [
"heu-mcp"
]
}
}
} {
"servers": {
"lucav21-heu-mcp": {
"command": "uvx",
"args": [
"heu-mcp"
]
}
}
} codex mcp add lucav21-heu-mcp -- uvx heu-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"lucav21-heu-mcp": {
"type": "local",
"command": [
"uvx",
"heu-mcp"
],
"enabled": true
}
}
} openclaw mcp add lucav21-heu-mcp --command uvx --arg heu-mcp
mcp_servers:
lucav21-heu-mcp:
command: "uvx"
args: ["heu-mcp"] {
"McpServers": {
"lucav21-heu-mcp": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"heu-mcp"
]
}
}
} assistant mcp add lucav21-heu-mcp -t stdio -c uvx -a heu-mcp
{
"mcpServers": {
"lucav21-heu-mcp": {
"command": "uvx",
"args": [
"heu-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
- Security disclosure: unverified → fail ▼ functional
- 19 Sept 26 0
- Security disclosure: fail → unverified ▼ functional
- 18 Sept 26 +1
- Package version: 0.3.0 → 0.5.2 functional
- 17 Sept 26 0
- Security disclosure: unverified → fail ▼ functional
- 16 Sept 26 +1
- Security disclosure: fail → unverified ▼ functional
- 15 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 14 Sept 26 −14
- Malware scan: pass → unverified ▼ security
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed pypi/heu-mcp@0.5.2
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | setuptools.build_meta |
Background: Why install scripts are a supply-chain risk →
Dependencies 35 packages
| Packages resolved | 35 |
|---|---|
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
cancel_pdf_document ~107
Annulla una richiesta di firma inviata: nasconde il PDF da tutti gli elenchi e invalida l'accesso alla firma, così i firmatari in attesa non possono più firmare. Viene rifiutato con 409 se il documento ha già attività di firma. IMPORTANTE: chiedere SEMPRE conferma esplicita all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del documento PDF da annullare |
No output schema declared.
No examples provided.
create_heu_document ~162
Crea e condivide un nuovo documento HEU partendo da un template esistente. Invia email ai destinatari. IMPORTANTE: chiedere conferma all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_name | string | – | Nome del nuovo documento |
| document_type | string | – | Default: document |
| email_subject | string | yes | Oggetto email di condivisione |
| email_text | string | yes | Corpo email di condivisione |
| email_to | array | yes | Lista email destinatari (oppure stringa singola) |
| placeholders | object | – | Mappa key->value dei placeholder da sostituire nel template (chiave = nome placeholder) |
| source_document_id | string | yes | ID del template sorgente |
No output schema declared.
No examples provided.
create_pdf_document ~175
Crea e condivide un nuovo PDF firmabile partendo da un template PDF esistente. Richiede signers e (opzionalmente) i valori dei placeholder. Con signature_type='fea' serve avere credito FEA sufficiente. IMPORTANTE: chiedere conferma all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_name | string | – | Nome del nuovo documento |
| email_body | string | yes | Corpo email di condivisione |
| email_subject | string | yes | Oggetto email di condivisione |
| placeholders | array | – | Valori dei placeholder (opzionale) |
| signature_type | string | – | Tipo firma. Default: fes |
| signers | array | yes | Lista firmatari (richiesto) |
| source_document_id | string | yes | ID del template PDF sorgente |
No output schema declared.
No examples provided.
create_pdf_document_from_upload ~286
Crea e invia direttamente un PDF firmabile caricando un file locale (max 5 MB), senza passare da un template. Richiede firmatari completi di email, oggetto/corpo email e layout placeholder (opzionalmente precompilati). Il documento viene creato in stato 'to_sign' e i firmatari ricevono subito l'email. Con signature_type='fea' servono crediti FEA sufficienti. SUGGERIMENTO: per posizionare i campi automaticamente, usa PRIMA locate_pdf_text per trovare le coordinate di ancore come 'Firma', i nomi delle parti, ecc. IMPORTANTE: chiedere conferma all'utente (mostrando la mappatura campi proposta) prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_name | string | yes | Nome del documento |
| email_body | string | yes | Corpo email di invito alla firma |
| email_subject | string | yes | Oggetto email di invito alla firma |
| file_path | string | yes | Path locale del file PDF da caricare (max 5 MB) |
| placeholders | array | yes | Campi posizionati sul PDF, opzionalmente precompilati |
| signature_type | string | – | Tipo firma. Default: fes |
| signers | array | yes | Firmatari (con email) |
No output schema declared.
No examples provided.
create_pdf_template ~174
Crea un template PDF riutilizzabile caricando un file PDF locale (max 5 MB) con firmatari e placeholder. Ritorna l'ID del nuovo template, utilizzabile come source_document_id in create_pdf_document. Le posizioni dei placeholder sono in percentuale (0-100) con origine in basso a sinistra. PDF ruotati vengono rifiutati. IMPORTANTE: chiedere conferma all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_name | string | yes | Nome del template |
| file_path | string | yes | Path locale del file PDF da caricare (max 5 MB) |
| placeholders | array | yes | Campi firma/testo/checkbox posizionati sul PDF |
| signers | array | yes | Firmatari del template (senza email) |
No output schema declared.
No examples provided.
delete_pdf_template ~78
Elimina (nasconde) un template PDF da tutti gli elenchi. I template non vengono mai firmati quindi l'eliminazione è sempre consentita. IMPORTANTE: chiedere SEMPRE conferma esplicita all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del template PDF da eliminare |
No output schema declared.
No examples provided.
download_heu_document_pdf ~138
Scarica il PDF di un documento HEU e lo salva localmente. Ritorna il path del file. Layout opzionale (codici a 3 cifre della UI HEU).
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del documento HEU |
| has_footer | boolean | – | Includi footer (opzionale) |
| has_index | boolean | – | Includi indice (opzionale) |
| layout | string | – | Codice layout (opzionale) |
| output_path | string | – | Path output personalizzato (opzionale, default: HEU_DOWNLOAD_DIR/heu_<id>.pdf) |
No output schema declared.
No examples provided.
download_pdf_audit_trail ~69
Scarica l'audit trail (registro delle attività di firma) di un PDF e lo salva localmente. Ritorna il path del file.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
| output_path | string | – | Path output personalizzato (opzionale) |
No output schema declared.
No examples provided.
download_pdf_bundle ~81
Scarica il bundle ZIP completo di un PDF (documento + audit trail + artefatti FES) e lo salva localmente. Ritorna il path del file. Utile per archiviazione legale.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
| output_path | string | – | Path output personalizzato (opzionale) |
No output schema declared.
No examples provided.
download_pdf_document ~81
Scarica il PDF di un documento caricato (versione firmata se disponibile) e lo salva localmente. Ritorna il path del file.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
| output_path | string | – | Path output personalizzato (opzionale, default: HEU_DOWNLOAD_DIR/heu_pdf_<id>.pdf) |
No output schema declared.
No examples provided.
extract_heu_document_parties ~188
Estrae i dati anagrafici delle parti da un documento HEU. Combina i metadati registrati (firmatari, ruoli, stato firma) con dati estratti dal testo del contratto: codice fiscale, P.IVA, codice univoco SDI, email/PEC, luogo e data di nascita, indirizzi, CAP. Pattern ottimizzati per contratti italiani.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del documento HEU |
| include_text | boolean | – | Se true include nel risultato anche il testo grezzo (utile per ulteriore analisi). Default: false. |
| pages | string | – | Range pagine: '1-3', '5', '1,3,5-7'. Default: tutte (max 100). Le 'parti' sono spesso in pagina 1-2. |
No output schema declared.
No examples provided.
extract_pdf_document_parties ~155
Estrae i dati anagrafici delle parti da un PDF caricato. Combina i metadati dei firmatari registrati con dati estratti dal testo: codice fiscale, P.IVA, codice univoco SDI, email/PEC, luogo e data di nascita, indirizzi, CAP. Pattern ottimizzati per contratti italiani.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF caricato |
| include_text | boolean | – | Se true include nel risultato anche il testo grezzo. Default: false. |
| pages | string | – | Range pagine: '1-3', '5', '1,3,5-7'. Default: tutte (max 100). |
No output schema declared.
No examples provided.
get_heu_document ~41
Dettaglio di un documento o template HEU per ID.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del documento (UUID per document/template HEU) |
No output schema declared.
No examples provided.
get_heu_health ~34
Health check API HEU. Ritorna { message: 'ok', status: 200 } se operativa.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_pdf_document ~33
Dettaglio di un PDF documento/template HEU per ID.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
No output schema declared.
No examples provided.
list_heu_document_placeholders ~43
Lista i placeholder di un documento/template HEU (chiavi sostituibili nel testo).
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del documento HEU |
No output schema declared.
No examples provided.
list_heu_documents ~241
Lista documenti/template nativi HEU con filtri opzionali. IMPORTANTE: quando filtri per intervallo di date passa SEMPRE entrambi i parametri 'created_from' e 'created_to' insieme, altrimenti l'API potrebbe non restituire tutti i documenti del periodo. Se vuoi tutti i documenti senza limiti di data, ometti entrambi.
| Name | Type | Req | Description |
|---|---|---|---|
| created_from | string | – | Data inizio del filtro (ISO 8601, es. 2025-01-01T00:00:00Z). USA SEMPRE INSIEME a 'created_to': passare solo una delle due date può far escludere documenti dal risultato. |
| created_to | string | – | Data fine del filtro (ISO 8601, es. 2025-01-31T23:59:59Z). USA SEMPRE INSIEME a 'created_from'. |
| have_editors_signed | boolean | – | Filtra per: tutti gli editor hanno firmato |
| sort | string | – | Ordinamento per data |
| type | string | – | Filtra per tipo |
No output schema declared.
No examples provided.
list_pdf_document_placeholders ~34
Lista tutti i placeholder/campi di firma di un PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
No output schema declared.
No examples provided.
list_pdf_document_signer_placeholders ~53
Lista i placeholder/campi di firma di un signer specifico su un PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
| signer_id | string | yes | ID del firmatario |
No output schema declared.
No examples provided.
list_pdf_document_signers ~31
Lista i firmatari di un PDF.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
No output schema declared.
No examples provided.
list_pdf_documents ~41
Lista PDF documenti/template caricati su HEU.
| Name | Type | Req | Description |
|---|---|---|---|
| sort | string | – | Ordinamento |
| type | string | yes | Tipo (richiesto) |
No output schema declared.
No examples provided.
locate_pdf_text ~403
Trova la posizione esatta di testi dentro un PDF, per posizionare i placeholder di firma automaticamente. Cerca i termini indicati (default: 'firma', 'sottoscri', 'signature', 'per accettazione', 'timbro', 'luogo e data') e ritorna per ogni occorrenza: pagina, coordinate in percentuale (position_x/position_y, origine in basso a sinistra — lo stesso sistema dei placeholder HEU) e il testo della riga. Ritorna anche le dimensioni pagina. Flusso tipico: locate_pdf_text -> proponi la mappatura campi all'utente -> create_pdf_document_from_upload o create_pdf_template. Suggerimento: il campo firma va di solito posizionato leggermente sopra o a destra dell'etichetta trovata (es. y +2-4 punti percentuali rispetto alla riga 'Firma'). Funziona su un file locale (file_path) o su un PDF già caricato su HEU (document_id). PDF scansionati senza testo restituiscono zero righe.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | – | ID di un PDF già caricato su HEU (alternativo a file_path) |
| file_path | string | – | Path locale del PDF da analizzare (alternativo a document_id) |
| include_all_lines | boolean | – | Se true ritorna TUTTE le righe con coordinate (non solo i match): utile per layout complessi. Default: false. |
| pages | string | – | Range pagine da analizzare: '1-3', '5', '1,3,5-7'. Default: tutte. |
| search_terms | array | – | Testi da cercare (case-insensitive, match parziale). Default: parole chiave di firma. Usa i nomi delle parti per trovare dove posizionare i campi di ciascun firmatario. |
No output schema declared.
No examples provided.
preview_pdf_template ~112
Scarica un'anteprima annotata di un template PDF: ogni placeholder è disegnato come un riquadro etichettato con tipo e firmatario. Utile per verificare il posizionamento dei campi prima di usare il template. Salva il PDF localmente e ritorna il path. Solo il proprietario del template può usarlo.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del template PDF |
| output_path | string | – | Path output personalizzato (opzionale) |
No output schema declared.
No examples provided.
prompt_heu_document_signature ~73
Invia un sollecito di firma per un documento HEU. Limite: 1 prompt ogni 24h per documento (altrimenti 429). IMPORTANTE: chiedere conferma all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del documento HEU |
No output schema declared.
No examples provided.
prompt_pdf_document_signature ~49
Invia un sollecito di firma per un PDF. IMPORTANTE: chiedere conferma all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF |
No output schema declared.
No examples provided.
read_heu_document ~189
Legge il contenuto testuale di un documento HEU senza salvarlo su disco. Scarica il PDF dall'API HEU, ne estrae il testo e lo restituisce direttamente nella risposta — utile per riassumere, cercare clausole, confrontare contratti. Default: tutte le pagine fino a un limite di 100. Per documenti più lunghi usa il parametro 'pages'.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del documento HEU |
| has_footer | boolean | – | Includi footer (opzionale) |
| has_index | boolean | – | Includi indice (opzionale) |
| layout | string | – | Codice layout (opzionale) |
| pages | string | – | Range pagine: '1-3', '5', '1,3,5-7'. Default: tutte (max 100). |
No output schema declared.
No examples provided.
read_pdf_document ~118
Legge il contenuto testuale di un PDF caricato senza salvarlo su disco. Scarica il PDF (incluso quello firmato, se disponibile), ne estrae il testo e lo restituisce direttamente nella risposta. Default: tutte le pagine fino a un limite di 100.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del PDF caricato |
| pages | string | – | Range pagine: '1-3', '5', '1,3,5-7'. Default: tutte (max 100). |
No output schema declared.
No examples provided.
update_pdf_template ~158
Sostituisce integralmente firmatari e placeholder di un template PDF esistente (l'ID template resta lo stesso). Solo il proprietario; il documento deve essere di tipo 'template'. Placeholder omessi o [] cancella tutti i campi. IMPORTANTE: chiedere conferma all'utente prima di eseguire.
| Name | Type | Req | Description |
|---|---|---|---|
| document_id | string | yes | ID del template PDF |
| document_name | string | – | Nuovo nome del template (opzionale, aggiornato solo se fornito) |
| placeholders | array | – | Set completo sostitutivo dei placeholder (ometti o [] per cancellarli tutti) |
| signers | array | yes | Set completo sostitutivo dei firmatari (richiesto) |
No output schema declared.
No examples provided.
What is the io.github.Lucav21/heu-mcp server?
io.github.Lucav21/heu-mcp is listed in the public MCP registry as io.github.Lucav21/heu-mcp. HEU Legal e-signature MCP: manage HEU documents and PDFs, prompt signers, download PDFs. This page covers its PyPI package (heu-mcp).
Is the io.github.Lucav21/heu-mcp server safe to use?
io.github.Lucav21/heu-mcp scores 83 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.Lucav21/heu-mcp server expose?
io.github.Lucav21/heu-mcp exposes 28 tools: get_heu_health, list_heu_documents, get_heu_document, list_heu_document_placeholders, create_heu_document, and 23 more. Their descriptions and schemas cost roughly 3,347 tokens of context every time the server is loaded.
Is the io.github.Lucav21/heu-mcp server still maintained?
io.github.Lucav21/heu-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.Lucav21/heu-mcp server under?
io.github.Lucav21/heu-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.