io.github.theluckystrike/appointment
MCPB · CALENDAR.MCPB · SCANNED SEP 20
Read your .ics calendar for appointments, free-busy windows and conflicts.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security23
- Malware scan not yet available for this package.Unverified
- Known CVEs were checked across the 96 of 96 dependencies we could resolve, so this covers what we could see, not the whole tree.Partial
- No install/post-install scripts declared.Pass
- 31 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 13 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability88
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1106 tokens (~85/item across 13 items; 12 tools + 1 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management43
- Stability observed for 13 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "ics_forget" implies "remove" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
mcpb · calendar.mcpb
Download bundleEvery change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +4
- Stability: unverified → 0.27 ▲ functional
- 7 Sept 26 48
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed mcpb/https://github.com/theluckystrike/mcp-servers/releases/download/v0.21.0/calendar.mcpb@0.21.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | mcpb |
Background: How many MCP packages publish verified provenance →
Dependencies 96 packages
| Packages resolved | 96 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
calendars_list List imported calendars ~35
Every calendar imported into this server: its name, where it came from, how many event definitions it holds and when it was imported.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
conflicts Find double bookings ~98
Every pair of events overlapping in time, with minutes they collide. Across all calendars unless one named, so a clashing work/family event is caught. Whole-day events reported separately. Free: 31 days; Pro: any window.
| Name | Type | Req | Description |
|---|---|---|---|
| calendar | string | – | One calendar name; default every imported calendar |
| from | string | yes | First day, YYYY-MM-DD |
| to | string | yes | Last day, YYYY-MM-DD, included |
No output schema declared.
No examples provided.
event_export Export events to a .ics file ~136
Call this tool to write chosen events to a new .ics file you can send or import elsewhere. Pass either ids (from events_list) or a from/to window. Times are written in UTC so the file lands correctly in any client.
| Name | Type | Req | Description |
|---|---|---|---|
| calendar | string | – | With from/to: limit to one calendar |
| from | string | – | First day, YYYY-MM-DD (alternative to ids) |
| ids | array | – | Event ids from events_list, events_search or next_event |
| out_path | string | yes | Where to write the .ics file |
| to | string | – | Last day, YYYY-MM-DD, included |
No output schema declared.
No examples provided.
event_to_time_entry Turn a meeting into a time entry ~155
Take one event and return the exact arguments for the time-tracker's entry_add, so a meeting that already happened becomes billable time without retyping it. Writes nothing: pass the JSON straight to entry_add.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | – | Currency of the rate: EUR, USD, GBP, PLN, or the word the user said ('euros'). Without it the time-tracker falls back to USD. |
| event_id | string | yes | Event id from events_list, events_search or next_event |
| project | string | yes | Project or client the meeting is billed to |
| rate | – | – | Hourly rate for this entry; a number (120) or the words the user said ('120 euros an hour') |
No output schema declared.
No examples provided.
events_list List events in a window ~115
Every event between two dates, recurring expanded to occurrences, sorted by start. Times shown in your zone (profile's, else this machine's) unless zone passed. Each id works for event_export or event_to_time_entry.
| Name | Type | Req | Description |
|---|---|---|---|
| calendar | string | – | One calendar name; default every imported calendar |
| from | string | yes | First day, YYYY-MM-DD |
| to | string | yes | Last day, YYYY-MM-DD, included |
| zone | string | – | Show local times in this zone or city instead of your own |
No output schema declared.
No examples provided.
events_search Search events ~94
Find events whose title, description, location or attendees contain a phrase. Searches every imported calendar. Without from/to it looks a year back and a year forward on Pro, and the free window either side of today.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | First day, YYYY-MM-DD |
| query | string | yes | Words to look for, case-insensitive |
| to | string | – | Last day, YYYY-MM-DD, included |
No output schema declared.
No examples provided.
free_busy Busy blocks and free windows ~159
Where the time actually went: merged busy blocks from the calendars named, and the gaps in your working hours where nothing is booked. Free/transparent events do not count as busy; whole-day events block the day.
| Name | Type | Req | Description |
|---|---|---|---|
| calendars | array | – | Calendar names; default all of them |
| from | string | yes | First day, YYYY-MM-DD |
| to | string | yes | Last day, YYYY-MM-DD, included |
| work_end | string | – | End of your working day, HH:MM, default 17:00 |
| work_start | string | – | Start of your working day, HH:MM, default 09:00 |
| zone | string | – | Zone the working hours and the output are in; default your own |
No output schema declared.
No examples provided.
ics_forget Forget a calendar ~42
Remove one imported calendar and the local copy of its .ics file. Nothing else is touched.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | The calendar name from calendars_list |
No output schema declared.
No examples provided.
ics_import Import a calendar (.ics) ~143
Call this tool to read a calendar export and keep it under a name. Give path (.ics file), text (contents), or url (public .ics/webcal feed; Pro). Google, Apple, Outlook exports read. Re-importing a name replaces it.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | What to call this calendar, e.g. "work" or "family" |
| path | string | – | Path to a .ics file on this machine |
| text | string | – | The .ics file contents, pasted |
| url | string | – | Public https:// or webcal:// .ics feed. Fetched once, only because you asked; Pro feature |
No output schema declared.
No examples provided.
license_activate Activate license ~42
Activate a Pro license key (format MCPL1.xxx.yyy). Verified offline and saved locally.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | License key from the checkout confirmation page |
No output schema declared.
No examples provided.
license_status License status ~23
Show whether this server runs in free or Pro mode and where to upgrade.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
next_event Next event ~46
The next event that has not started yet, with how long until it begins. Looks ahead up to a year.
| Name | Type | Req | Description |
|---|---|---|---|
| calendar | string | – | One calendar name; default every imported calendar |
No output schema declared.
No examples provided.
What is the io.github.theluckystrike/appointment MCP server?
io.github.theluckystrike/appointment is an MCP server listed in the public MCP registry as io.github.theluckystrike/appointment. Read your .ics calendar for appointments, free-busy windows and conflicts. This page covers its MCPB bundle (https://github.com/theluckystrike/mcp-servers/releases/download/v0.21.0/calendar.mcpb).
Is the io.github.theluckystrike/appointment MCP server safe to use?
io.github.theluckystrike/appointment scores 54 out of 100 on VerifyMCP. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.theluckystrike/appointment MCP server expose?
io.github.theluckystrike/appointment exposes 12 tools: license_status, license_activate, ics_import, calendars_list, events_list, and 7 more. Their descriptions and schemas cost roughly 1,088 tokens of context every time the server is loaded.
What licence is the io.github.theluckystrike/appointment MCP server under?
io.github.theluckystrike/appointment declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.