
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@caliu-notes/mcp
Advanced tools
MCP server for Caliu: interact with your notes, tags, reminders and attachments from any MCP-compatible client
Model Context Protocol server for Caliu, a local-first, markdown-powered notes app.
Exposes your Caliu notes, tags, reminders and attachments as a small set of agent-shaped MCP tools that any MCP-compatible client (Claude Desktop, Cursor, Windsurf, …) can call.
No install needed. Run it on demand with npx.
{
"mcpServers": {
"caliu": {
"command": "npx",
"args": ["-y", "@caliu-notes/mcp"],
"env": {
"CALIU_API_KEY": "caliu_your_api_key_here"
}
}
}
}
Drop that into your client's MCP config (e.g. claude_desktop_config.json).
Claude.ai can connect to Caliu directly, with no API key and no npm package: add https://api.caliuapp.com/mcp as a Custom Connector and sign in to Caliu when prompted. It speaks OAuth 2.1 with dynamic client registration.
caliu_)CALIU_API_KEY env var above| Variable | Required | Default | Description |
|---|---|---|---|
CALIU_API_KEY | Yes | none | API key from Caliu → Settings → API keys |
CALIU_API_URL | No | https://api.caliuapp.com | Override the API base URL |
14 tools, designed for agents rather than as a 1:1 mirror of the REST API:
Notes
search_notes: full-text search and filtering (tag, pinned, untagged, backlinks, trash)get_note: single note with content, tags, and backlinkscreate_note, update_note: write markdown; tags auto-derive from #hashtags in the contentdelete_note, restore_note: soft delete and restorearchive_note, unarchive_note: archive without deleting, tags preservedTags
list_tags: discover existing tags before writingReminders
set_reminder (upsert), delete_reminderAttachments
upload_file: attach an image or file to a noteget_attachment: fetch an existing attachmentUser
get_current_user: authenticated profileTags are managed automatically: write #work #urgent in note content and the tags get linked. There are no add_tag_to_note / sync_note_tags helpers, agents just write markdown. Note links work the same way: write [[Note Title]] and the server resolves it to a canonical link.
MIT
FAQs
MCP server for Caliu: interact with your notes, tags, reminders and attachments from any MCP-compatible client
The npm package @caliu-notes/mcp receives a total of 38 weekly downloads. As such, @caliu-notes/mcp popularity was classified as not popular.
We found that @caliu-notes/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.