
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
tooldash-mcp
Advanced tools
Offline PDF and text tools for AI agents over the Model Context Protocol. Merge PDFs, extract pages, inspect documents and clean text — entirely on your machine, no upload and no API key.
Offline PDF and text tools for AI agents. An MCP server that lets Claude Desktop, Cursor, VS Code and any other MCP client merge PDFs, pull out pages, inspect documents and clean up text — entirely on your own machine.
No upload. No API key. No account. No network call of any kind: the PDF work is done locally by pdf-lib, so a confidential contract never leaves your laptop.
| Tool | What it does | Writes files? |
|---|---|---|
pdf_info | Page count, per-page dimensions and metadata of a PDF | No |
merge_pdfs | Combine two or more PDFs into one, in the given order | Yes |
extract_pdf_pages | Copy a page selection ("1-3,7,10-12") into a new PDF | Yes |
clean_text | Collapse whitespace, strip invisible characters, normalize punctuation, optionally remove URLs | No |
The two tools that write files refuse to replace an existing file unless you pass overwrite: true, so an agent retrying a call cannot quietly destroy a document.
Node.js 20 or newer.
No install step — your MCP client runs it on demand with npx. Add the server to your client's config and restart it.
Edit claude_desktop_config.json:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json~/.config/Claude/claude_desktop_config.json{
"mcpServers": {
"tooldash": {
"command": "npx",
"args": ["-y", "tooldash-mcp"]
}
}
}
Restart Claude Desktop. The tools appear under the tools icon in the chat box.
Create .cursor/mcp.json in your project (or ~/.cursor/mcp.json for every project):
{
"mcpServers": {
"tooldash": {
"command": "npx",
"args": ["-y", "tooldash-mcp"]
}
}
}
Then enable the server under Settings → MCP.
Create .vscode/mcp.json:
{
"servers": {
"tooldash": {
"type": "stdio",
"command": "npx",
"args": ["-y", "tooldash-mcp"]
}
}
}
git clone https://github.com/LassiB999/tooldash-mcp.git
cd tooldash-mcp
npm install
npm test
Then point your client at node /absolute/path/to/tooldash-mcp/server.js instead of npx.
Paths may be absolute, relative to the client's working directory, or start with ~. Surrounding quotes are stripped, so a path pasted as "/home/you/file.pdf" still works.
The server reads and writes wherever your user account can. To confine it to one directory, set TOOLDASH_MCP_ROOT — any path outside it is refused with a clear error:
{
"mcpServers": {
"tooldash": {
"command": "npx",
"args": ["-y", "tooldash-mcp"],
"env": { "TOOLDASH_MCP_ROOT": "/home/you/Documents/pdfs" }
}
}
}
Ask your assistant in plain language — "merge these two PDFs and put the result on my desktop" — and it will fill in the calls below. The raw JSON is here for testing.
pdf_info{ "path": "/home/you/Documents/report.pdf" }
report.pdf: 12 page(s), 248.3 KB. Title: "Q3 Report".
merge_pdfs{
"inputPaths": ["/home/you/Documents/cover.pdf", "/home/you/Documents/report.pdf"],
"outputPath": "/home/you/Documents/final.pdf",
"overwrite": false
}
extract_pdf_pagesPages are 1-based. Order is preserved, so "3,1-2" gives you page 3 first. A descending range like "5-1" reverses those pages.
{
"inputPath": "/home/you/Documents/report.pdf",
"pages": "1-3,7,10-12",
"outputPath": "/home/you/Documents/excerpt.pdf"
}
clean_text{
"text": "Hello world \r\n\r\n\r\n\r\nSecond line ",
"collapseBlankLines": true,
"normalizeQuotes": false,
"removeUrls": false
}
removeUrls strips every http/https URL. The server is offline, so it cannot tell a working link from a dead one — it does not pretend to.
Bad input comes back as a readable error result the model can act on, never as a crash: a missing file, a password-protected PDF, a page number past the end of the document, or an output path that already exists each produce a message saying what to do next. The server keeps running.
Diagnostics go to stderr only. stdout carries protocol frames and nothing else — the tests would fail if anything leaked into it.
npm test # 15 end-to-end tests: a real MCP client over stdio, on real PDFs
npm run inspect # open the MCP Inspector against this server
ToolDash is a set of free, browser-based utilities — PDF, text, image, colour, developer and calculator tools — that run entirely in your tab with nothing uploaded. This server brings the same idea to your editor.
MIT
FAQs
Offline PDF and text tools for AI agents over the Model Context Protocol. Merge PDFs, extract pages, inspect documents and clean text — entirely on your machine, no upload and no API key.
We found that tooldash-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.