Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.worklore/worklore

REMOTE · WORKLORE.DEV · SCANNED OCT 5

Search worklore stories and x-ray any skill or story capability tier (T0-T4) before you run it.

Available components

+41 this week 77 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security89
Transport & Reachability100
Schema Quality & AI Usability66
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 1729 tokens (~247/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
  • Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the io.github.worklore/worklore MCP server?

io.github.worklore/worklore is a hosted endpoint at https://worklore.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · worklore.dev

# add to Claude Code
claude mcp add --transport http worklore-worklore 'https://worklore.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "worklore-worklore": {
      "url": "https://worklore.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "worklore-worklore": {
      "type": "http",
      "url": "https://worklore.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.worklore-worklore]
url = "https://worklore.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "worklore-worklore": {
      "type": "remote",
      "url": "https://worklore.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add worklore-worklore --url 'https://worklore.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  worklore-worklore:
    url: "https://worklore.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "worklore-worklore": {
      "Transport": "http",
      "Url": "https://worklore.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add worklore-worklore -t streamable-http -u 'https://worklore.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "worklore-worklore": {
      "type": "http",
      "url": "https://worklore.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 5 Oct 26 +1
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
  • 4 Oct 26 0
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
  • 3 Oct 26 +1
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
  • 2 Oct 26 0
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
  • 1 Oct 26 +1
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
  • 30 Sept 26 0
    • Schema quality: 211 → 247 ▼ functional
    • Stability: unverified → 0.03 ▲ functional
    • This server's schema is too large to store in full, so we cannot compare its tools day to day functional
  • 29 Sept 26 +38
    • Transport: unverified → pass ▲ security
    • Injection markers: unverified → pass ▲ security
    • First check of Judged manipulation: pass security
    • Authorization: Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. security
    • MCP protocol: unverified → fail ▼ functional
    • Tool coverage: unverified → 100 ▲ functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: excellent functional
    • First check of Schema quality: fail functional
    • First check of Destructive annotations: 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Tool coverage: 100 functional
  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 7 Oct 2026 · Probed https://worklore.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=worklore.dev CN=Amazon RSA 2048 M04,O=Amazon,C=US 31 Jul 2026 13 Feb 2027 RSA 2048 SHA256-RSA 5950ddde977b4812fe43c37d4d7bf63
SANs: worklore.dev, www.worklore.dev, worklore.yahhi.me
CN=Amazon RSA 2048 M04,O=Amazon,C=US (CA) CN=Amazon Root CA 1,O=Amazon,C=US 23 Aug 2022 23 Aug 2030 RSA 2048 SHA256-RSA 773124f2a952e3ed18a58bdb85d1bc0ce5f27
CN=Amazon Root CA 1,O=Amazon,C=US (CA) CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US 25 May 2015 31 Dec 2037 RSA 2048 SHA256-RSA 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of worklore.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
worklore.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://worklore.dev/.well-known/oauth-protected-resource"

Bearer resource_metadata="https://worklore.dev/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://worklore.dev/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://worklore.dev/mcp
Authorisation server https://worklore.dev

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://worklore.dev/mcp Verified 200
http (plaintext) http://worklore.dev/mcp HTTPS enforced 301 https://worklore.dev/mcp
MCP tools · 8 exposed · ~1,547 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
check_capability ~181

Disclose what an agent Skill or worklore story CAN DO before you run it: a capability tier T0-T4 bound to a content sha256, with findings that carry file:line evidence, PLUS a separate list of behavioral red flags (prompt-injection / deception / exfiltration-intent / safety-bypass phrasings) for a human to review. This is blast-radius disclosure and triage, never a 'safe' verdict. Pass the raw `text`, or a `url` to fetch and scan (e.g. a worklore story .md). `text` needs no sign-in; a `url` makes the server fetch it for you, so it needs a signed-in session.

NameTypeReqDescription
textstring–The skill/story text to scan.
urlstring–A URL to fetch and scan.
NameTypeReqDescription
behavioralarray––
behavioral_notestring––
disclaimerstring––
endpointsarray––
findingsarray––
scanner_versionstring––
sha256stringyes–
tierstringyes–
tier_labelstring––

No examples provided.

edit_story ~410

Revise a worklore story the signed-in account PUBLISHED — only its author can edit it. Call get_story first, then show the human a before/after diff of your change and get their EXPLICIT approval before calling this; never edit on your own initiative. Send the COMPLETE revised story as `markdown` (frontmatter + '# title' + narrative + '## Reproduce this'), not a fragment. Keep the frontmatter `date` exactly as it is: it records when the work happened, and a revision never moves it. Say what kind of edit this is: 'rephrase' (same claims, better wording), 'addition' (new detail, nothing was wrong), or 'correction' (something in the story was WRONG — a step, a claim, a result). If anything was wrong, it is a correction: never hide a correction as a rephrase. A correction requires a one-line `note` saying what was wrong, and notifies everyone who reported reproducing the story. `source` optionally credits what prompted the revision (an https URL). The new text REPLACES the old (worklore keeps no copy of earlier text), while a record of this revision — when, what kind, the note — is appended to the story's public history.

NameTypeReqDescription
kindstring–rephrase (default) — same claims, reworded; addition — new detail, nothing was wrong; correction — something was wrong (requires `note`, notifies reproducers).
markdownstringyesThe complete revised story markdown, frontmatter included, with the original `date` unchanged.
notestring–One line on what changed (max 500 chars). Required for a correction: what was wrong.
slugstringyesThe slug of the story to revise (one the signed-in account wrote).
sourcestring–Optional https URL crediting what prompted the revision (a comment, an issue, an article).
NameTypeReqDescription
notifiedintegeryes–
revisionobjectyes–
slugstringyes–
urlstringyes–
visibilitystring––

No examples provided.

get_story ~117

Fetch one worklore story by slug — its full markdown (narrative + the 'Reproduce this' contract your agent would run) WITH its capability disclosure attached (tier + findings), so you see what it can do before applying it. Read the capability first; run check_capability on the live artifacts before executing. After you apply the story to the user's task, call report_reproduction with an honest result to record it.

NameTypeReqDescription
slugstringyesThe story slug (from search_stories / a worklore URL).
NameTypeReqDescription
after_you_apply_thisstring––
capabilityobject––
checksobject––
has_checkboolean––
markdownstring––
slugstringyes–
titlestring––
to_check_onlystring––
unavailablestring––
visibilitystring––
visibility_notestring––

No examples provided.

publish_story ~413

Publish a NEW worklore story as the signed-in account. worklore stories are PUBLIC and honest, so before you call this you MUST show the human the complete draft — the title, the first-person narrative, and the 'Reproduce this' contract — and get their EXPLICIT approval. Never publish on your own initiative and never invent details. Provide the full story as `markdown` (frontmatter with title/date/tags/type/reproducible, then '# title', the narrative, then '## Reproduce this' with prerequisites/inputs/steps/verify) — call get_story on an existing story first to match the format — OR provide the structured fields title + narrative (+ reproduce, tags, type, stack) and the server assembles it. SANITIZE: no secrets, employer internals, client names, or private URLs. Returns the live URL and capability tier.

NameTypeReqDescription
markdownstring–The complete story markdown (frontmatter + '# title' + narrative + '## Reproduce this' contract). Preferred.
narrativestring–First-person narrative, ~150-400 words, honest (used if no `markdown`).
reproducestring–The 'Reproduce this' contract body: prerequisites, inputs, ordered steps, verify.
stackstring–Optional: the ecosystem this story is about.
tagsarray–3-6 lowercase kebab tags.
titlestring–Story title (used only if `markdown` is not given).
typestring–success (default), fail, or proposal — a proposal is work the author believes is right but cannot prove yet, published to get evidence or review rather than to claim a result.
visibilitystring–public (default) — anyone can read and reproduce it; private — only the author can, and it appears in no feed, search, badge or link. Ask the human which they want if the draft contains anything they…
NameTypeReqDescription
capabilityobject––
similararray––
slugstring––
urlstring––

No examples provided.

report_check ~178

Record the result of a story's read-only 'Check if this applies to you' section, run in the user's own project (attributed to the signed-in account). Run ONLY that check — change nothing, apply no fix. First decide whether it applies at all: if the project does not match the check's preconditions, do NOT call this — 'not applicable' is never recorded. Otherwise report 'has_problem' or 'no_problem', honestly. One counted result per person per story; a later report replaces the earlier one. Only stories whose get_story result has has_check: true can be checked.

NameTypeReqDescription
notestring–Optional short note: the evidence (max 300 chars).
resultstringyesWhat the check found in the user's project.
slugstringyesThe story slug whose check you ran.
NameTypeReqDescription
checksobject––
countedboolean––
creditedstring––
okboolean––
resultstring––
thanksstring––

No examples provided.

report_reproduction ~134

Call this right after you apply a worklore story's steps to the user's own task, to record the reproduction (attributed to the signed-in account). Use an honest result: 'worked', 'partial' (you produced the output but it isn't verified yet), or 'failed' — all are useful. One counted report per person per story; repeats are acknowledged, not doubled. Never report a story you did not apply.

NameTypeReqDescription
notestring–Optional short note (max 500 chars).
resultstringyesHow it honestly went.
slugstringyesThe story slug you reproduced.
NameTypeReqDescription
countedboolean––
creditedstring––
okboolean––
thanksstring––

No examples provided.

search_stories ~47

Search worklore stories by keyword across title, summary, tags and stack. Returns matches with their capability tier.

NameTypeReqDescription
querystring–Keywords (space-separated; all must match).
NameTypeReqDescription
about_tiersstring––
countinteger––
querystring––
storiesarrayyes–

No examples provided.

suggest_for_project ~67

Given a short description of the current project (stack, what you're building, recent problems), suggest up to 3 worklore stories worth reproducing here, with why each fits and its tier.

NameTypeReqDescription
contextstringyesProject context: stack, goal, recent TODOs/problems.
NameTypeReqDescription
about_tiersstring––
notestring––
suggestedarrayyes–

No examples provided.

Common questions

What is the io.github.worklore/worklore MCP server?

io.github.worklore/worklore is an MCP server listed in the public MCP registry as io.github.worklore/worklore. Search worklore stories and x-ray any skill or story capability tier (T0-T4) before you run it. This page covers its hosted endpoint (https://worklore.dev/mcp).

Is the io.github.worklore/worklore MCP server safe to use?

io.github.worklore/worklore scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.worklore/worklore MCP server expose?

io.github.worklore/worklore exposes 8 tools: check_capability, get_story, search_stories, suggest_for_project, report_reproduction, and 3 more. Their descriptions and schemas cost roughly 1,547 tokens of context every time the server is loaded.

Does the io.github.worklore/worklore MCP server require authentication?

Yes. io.github.worklore/worklore asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the io.github.worklore/worklore MCP server still maintained?

io.github.worklore/worklore is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.