# io.github.worklore/worklore (remote · worklore.dev)

Search worklore stories and x-ray any skill or story capability tier (T0-T4) before you run it.

- Trust score: 77/100 (medium)
- Change this week: +41
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-05

## Components

- remote · `worklore.dev`: 77/100 (this document), [markdown](https://verifymcp.io/servers/worklore-worklore/worklore.md), [page](https://verifymcp.io/servers/worklore-worklore/worklore)

## Channel facts

- Endpoint: `https://worklore.dev/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.5.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-05.

- **Endpoint Security**: 89/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 66/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1729 tokens (~247/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 20/100
  - Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the io.github.worklore/worklore MCP server?

io.github.worklore/worklore is a hosted endpoint at https://worklore.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http worklore-worklore 'https://worklore.dev/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "worklore-worklore": {
      "url": "https://worklore.dev/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "worklore-worklore": {
      "type": "http",
      "url": "https://worklore.dev/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.worklore-worklore]
url = "https://worklore.dev/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "worklore-worklore": {
      "type": "remote",
      "url": "https://worklore.dev/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add worklore-worklore --url 'https://worklore.dev/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  worklore-worklore:
    url: "https://worklore.dev/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "worklore-worklore": {
      "Transport": "http",
      "Url": "https://worklore.dev/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add worklore-worklore -t streamable-http -u 'https://worklore.dev/mcp'
```

### Other

```json
{
  "mcpServers": {
    "worklore-worklore": {
      "type": "http",
      "url": "https://worklore.dev/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-05 (score 77, +1)

- [functional] This server's schema is too large to store in full, so we cannot compare its tools day to day

### 2026-10-04 (score 76, 0)

- [functional] This server's schema is too large to store in full, so we cannot compare its tools day to day

### 2026-10-03 (score 76, +1)

- [functional] This server's schema is too large to store in full, so we cannot compare its tools day to day

### 2026-10-02 (score 75, 0)

- [functional] This server's schema is too large to store in full, so we cannot compare its tools day to day

### 2026-10-01 (score 75, +1)

- [functional] This server's schema is too large to store in full, so we cannot compare its tools day to day

### 2026-09-30 (score 74, 0)

- [functional regression] Schema quality: 211 → 247
- [functional improvement] Stability: unverified → 0.03
- [functional] This server's schema is too large to store in full, so we cannot compare its tools day to day

### 2026-09-29 (score 74, +38)

- [security improvement] Transport: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] Authorization: Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Schema quality: fail
- [functional] First check of Destructive annotations: 100
- [functional] First check of Tool coverage: 100
- [functional] First check of Tool coverage: 100

### 2026-09-28 (score 36, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

## MCP tools (8)

### `check_capability` (~181 tokens)

Disclose what an agent Skill or worklore story CAN DO before you run it: a capability tier T0-T4 bound to a content sha256, with findings that carry file:line evidence, PLUS a separate list of behavioral red flags (prompt-injection / deception / exfiltration-intent / safety-bypass phrasings) for a human to review. This is blast-radius disclosure and triage, never a 'safe' verdict. Pass the raw `text`, or a `url` to fetch and scan (e.g. a worklore story .md). `text` needs no sign-in; a `url` makes the server fetch it for you, so it needs a signed-in session.

Input parameters:

- `text` (string): The skill/story text to scan.
- `url` (string): A URL to fetch and scan.

Output parameters:

- `behavioral` (array)
- `behavioral_note` (string)
- `disclaimer` (string)
- `endpoints` (array)
- `findings` (array)
- `scanner_version` (string)
- `sha256` (string)
- `tier` (string)
- `tier_label` (string)

### `get_story` (~117 tokens)

Fetch one worklore story by slug — its full markdown (narrative + the 'Reproduce this' contract your agent would run) WITH its capability disclosure attached (tier + findings), so you see what it can do before applying it. Read the capability first; run check_capability on the live artifacts before executing. After you apply the story to the user's task, call report_reproduction with an honest result to record it.

Input parameters:

- `slug` (string, required): The story slug (from search_stories / a worklore URL).

Output parameters:

- `after_you_apply_this` (string)
- `capability` (object)
- `checks` (object)
- `has_check` (boolean)
- `markdown` (string)
- `slug` (string)
- `title` (string)
- `to_check_only` (string)
- `unavailable` (string)
- `visibility` (string)
- `visibility_note` (string)

### `search_stories` (~47 tokens)

Search worklore stories by keyword across title, summary, tags and stack. Returns matches with their capability tier.

Input parameters:

- `query` (string): Keywords (space-separated; all must match).

Output parameters:

- `about_tiers` (string)
- `count` (integer)
- `query` (string)
- `stories` (array)

### `suggest_for_project` (~67 tokens)

Given a short description of the current project (stack, what you're building, recent problems), suggest up to 3 worklore stories worth reproducing here, with why each fits and its tier.

Input parameters:

- `context` (string, required): Project context: stack, goal, recent TODOs/problems.

Output parameters:

- `about_tiers` (string)
- `note` (string)
- `suggested` (array)

### `report_reproduction` (~134 tokens)

Call this right after you apply a worklore story's steps to the user's own task, to record the reproduction (attributed to the signed-in account). Use an honest result: 'worked', 'partial' (you produced the output but it isn't verified yet), or 'failed' — all are useful. One counted report per person per story; repeats are acknowledged, not doubled. Never report a story you did not apply.

Input parameters:

- `note` (string): Optional short note (max 500 chars).
- `result` (string, required): How it honestly went.
- `slug` (string, required): The story slug you reproduced.

Output parameters:

- `counted` (boolean)
- `credited` (string)
- `ok` (boolean)
- `thanks` (string)

### `report_check` (~178 tokens)

Record the result of a story's read-only 'Check if this applies to you' section, run in the user's own project (attributed to the signed-in account). Run ONLY that check — change nothing, apply no fix. First decide whether it applies at all: if the project does not match the check's preconditions, do NOT call this — 'not applicable' is never recorded. Otherwise report 'has_problem' or 'no_problem', honestly. One counted result per person per story; a later report replaces the earlier one. Only stories whose get_story result has has_check: true can be checked.

Input parameters:

- `note` (string): Optional short note: the evidence (max 300 chars).
- `result` (string, required): What the check found in the user's project.
- `slug` (string, required): The story slug whose check you ran.

Output parameters:

- `checks` (object)
- `counted` (boolean)
- `credited` (string)
- `ok` (boolean)
- `result` (string)
- `thanks` (string)

### `publish_story` (~413 tokens)

Publish a NEW worklore story as the signed-in account. worklore stories are PUBLIC and honest, so before you call this you MUST show the human the complete draft — the title, the first-person narrative, and the 'Reproduce this' contract — and get their EXPLICIT approval. Never publish on your own initiative and never invent details. Provide the full story as `markdown` (frontmatter with title/date/tags/type/reproducible, then '# title', the narrative, then '## Reproduce this' with prerequisites/inputs/steps/verify) — call get_story on an existing story first to match the format — OR provide the structured fields title + narrative (+ reproduce, tags, type, stack) and the server assembles it. SANITIZE: no secrets, employer internals, client names, or private URLs. Returns the live URL and capability tier.

Input parameters:

- `markdown` (string): The complete story markdown (frontmatter + '# title' + narrative + '## Reproduce this' contract). Preferred.
- `narrative` (string): First-person narrative, ~150-400 words, honest (used if no `markdown`).
- `reproduce` (string): The 'Reproduce this' contract body: prerequisites, inputs, ordered steps, verify.
- `stack` (string): Optional: the ecosystem this story is about.
- `tags` (array): 3-6 lowercase kebab tags.
- `title` (string): Story title (used only if `markdown` is not given).
- `type` (string): success (default), fail, or proposal — a proposal is work the author believes is right but cannot prove yet, published to get evidence or review rather than to claim a result.
- `visibility` (string): public (default) — anyone can read and reproduce it; private — only the author can, and it appears in no feed, search, badge or link. Ask the human which they want if the draft contains anything they…

Output parameters:

- `capability` (object)
- `similar` (array)
- `slug` (string)
- `url` (string)

### `edit_story` (~410 tokens)

Revise a worklore story the signed-in account PUBLISHED — only its author can edit it. Call get_story first, then show the human a before/after diff of your change and get their EXPLICIT approval before calling this; never edit on your own initiative. Send the COMPLETE revised story as `markdown` (frontmatter + '# title' + narrative + '## Reproduce this'), not a fragment. Keep the frontmatter `date` exactly as it is: it records when the work happened, and a revision never moves it. Say what kind of edit this is: 'rephrase' (same claims, better wording), 'addition' (new detail, nothing was wrong), or 'correction' (something in the story was WRONG — a step, a claim, a result). If anything was wrong, it is a correction: never hide a correction as a rephrase. A correction requires a one-line `note` saying what was wrong, and notifies everyone who reported reproducing the story. `source` optionally credits what prompted the revision (an https URL). The new text REPLACES the old (worklore keeps no copy of earlier text), while a record of this revision — when, what kind, the note — is appended to the story's public history.

Input parameters:

- `kind` (string): rephrase (default) — same claims, reworded; addition — new detail, nothing was wrong; correction — something was wrong (requires `note`, notifies reproducers).
- `markdown` (string, required): The complete revised story markdown, frontmatter included, with the original `date` unchanged.
- `note` (string): One line on what changed (max 500 chars). Required for a correction: what was wrong.
- `slug` (string, required): The slug of the story to revise (one the signed-in account wrote).
- `source` (string): Optional https URL crediting what prompted the revision (a comment, an issue, an article).

Output parameters:

- `notified` (integer)
- `revision` (object)
- `slug` (string)
- `url` (string)
- `visibility` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/worklore-worklore/worklore#diagnostics

## Score history

- 2026-10-05: 77
- 2026-10-04: 76
- 2026-10-03: 76
- 2026-10-02: 75
- 2026-10-01: 75
- 2026-09-30: 74
- 2026-09-29: 74
- 2026-09-28: 36
- 2026-09-27: 36
- 2026-09-26: 36
- 2026-09-25: 36
- 2026-09-24: 36
- 2026-09-23: 36
- 2026-09-22: 36
- 2026-09-21: 36
- 2026-09-20: 36
- 2026-09-19: 36
- 2026-09-18: 36
- 2026-09-17: 36
- 2026-09-16: 36
- 2026-09-15: 36

## Common questions

### What is the io.github.worklore/worklore MCP server?

io.github.worklore/worklore is an MCP server listed in the public MCP registry as io.github.worklore/worklore. Search worklore stories and x-ray any skill or story capability tier (T0-T4) before you run it. This page covers its hosted endpoint (https://worklore.dev/mcp).

### Is the io.github.worklore/worklore MCP server safe to use?

io.github.worklore/worklore scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.worklore/worklore MCP server expose?

io.github.worklore/worklore exposes 8 tools: check_capability, get_story, search_stories, suggest_for_project, report_reproduction, and 3 more. Their descriptions and schemas cost roughly 1,547 tokens of context every time the server is loaded.

### Does the io.github.worklore/worklore MCP server require authentication?

Yes. io.github.worklore/worklore asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the io.github.worklore/worklore MCP server still maintained?

io.github.worklore/worklore is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://worklore.dev/mcp
- Repository: https://github.com/worklore/worklore-mcp
- Changelog RSS feed: https://verifymcp.io/servers/worklore-worklore/worklore.xml
- Changelog JSON feed: https://verifymcp.io/servers/worklore-worklore/worklore.json
- HTML version of this page: https://verifymcp.io/servers/worklore-worklore/worklore
