
SilverBullet
io.github.wicahmav1.0.0更新于 Oct 4, 2026
List, read, write, append, delete and search markdown pages in a SilverBullet space.
概览
让助手通过六个笔记工具读取和写入 SilverBullet 空间中的 Markdown 页面。
- 功能
- 这是一个小型桥接服务,把 MCP 工具调用转发到 SilverBullet 内置的 /.fs HTTP API。它提供六个工具:list_pages、read_note、write_note、append_note、delete_note 和 search_notes,其中搜索为不区分大小写的子串匹配,返回路径、行号和文本。路径相对于空间,仅限 .md,并拒绝目录穿越片段。可通过 stdio 或 streamable HTTP 运行。
- 适用场景
- 当助手需要读取、创建、追加、覆盖、删除或搜索现有 SilverBullet 空间中的笔记时使用,例如在聊天客户端中起草或更新页面。若只是自己浏览 SilverBullet,则无需安装。
- 运行要求
- 需要本地运行时:npm 包(npx silverbullet-mcp)需要 Node.js,或直接使用 Python 3,因为 npm 包装器只是启动一个 Python 脚本。需要一个可访问且暴露 /.fs API 的 SilverBullet 实例,通过 SB_URL 设置。HTTP 模式下必须提供 MCP_TOKEN bearer 令牌;SB_AUTH_TOKEN 为可选的上游认证。需要能访问该实例的网络。
安装
在 SourceWeft 中
- 打开 控制台中的 SilverBullet,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
silverbullet-mcp
A tiny MCP server that gives any MCP-capable agent read/write access to a SilverBullet space.
No dependencies — Python 3 stdlib only. It is a translator: it forwards MCP tool
calls to SilverBullet's built-in /.fs HTTP API, which already supports read,
write and delete. Nothing needs to be installed or patched inside SilverBullet.
It is small enough to read in one sitting, and it speaks both MCP transports that clients actually use: stdio (spawned by Claude Desktop, Cursor, and friends) and streamable HTTP (shared or remote access behind a reverse proxy).
Quick start
Run it as a server:
Or let a client spawn it — no clone required, since it ships on npm:
Tools
Paths are space-relative (Projects/Foo.md), restricted to .md, and ..
segments are rejected.
Transports
Both come from the same code and expose the same six tools. MCP_TOKEN only
matters in HTTP mode; the SB_* variables describe the upstream space in both.
Client setup
Claude Desktop
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or
%APPDATA%\Claude\claude_desktop_config.json (Windows):
Cursor
Same body, in .cursor/mcp.json for one project or ~/.cursor/mcp.json
globally.
Any client that speaks remote MCP
Local, with no reverse proxy in front:
Note for remote clients: url must be, or must proxy to, this bridge — not
SilverBullet itself. SilverBullet has no MCP endpoint of its own; that is what
this project adds.
Configuration
All configuration is environment variables, so the same code runs for anyone.
HTTP endpoints
POST /mcp— JSON-RPC 2.0. Bearer token required. A notification returns202.GET /health(alsoGET /mcp/health) —{"status":"ok"}, no auth, no internal details.
Protocol versions negotiated: 2024-11-05, 2025-03-26, 2025-06-18.
Maximum request body 4 MB. Batch arrays are accepted.
Auth
The bearer token is the gate. Fail closed: if MCP_TOKEN is set, every request
without a matching token is rejected. If it is unset the server still starts (for
local debugging) but logs a loud warning.
Do not expose this server to the internet without a token. Anyone who can
reach /mcp can read, overwrite and delete every page in the space.
SilverBullet's own auth
Setting SB_AUTH_TOKEN alone on recent SilverBullet builds (verified on the
2.10.0 Rust build) does not enable authentication — anonymous requests still
succeed. Per upstream docs the token is only an alternative bearer path; the
server actually enforces auth when SB_USER is configured. If in doubt, probe
your own instance with a deliberately wrong bearer token: if it still returns
200, auth is off.
Practical consequence: put the token gate at this bridge (or at your reverse proxy), not at SilverBullet.
Deployment
systemd user unit
Keep the env file mode 600.
Behind a reverse proxy
Works fine behind Cloudflare Tunnel, nginx, Caddy, etc. Two notes from real deployments, both learned the hard way:
- Route by path on an existing hostname if you are on a free TLS plan: some providers issue certificates for the apex and a single subdomain level only, so a two-level hostname may fail the TLS handshake. A path route on an already-covered host avoids that entirely.
- Machine clients cannot complete SSO. If your host sits behind an identity-aware
proxy (Cloudflare Access and similar), bypass the MCP path and let the bearer
token be the gate. This is the usual split: the SilverBullet UI and its
/.fsAPI stay behind SSO, while/mcpis public but token-gated.
Troubleshooting
Security notes
- Paths are restricted to
.mdand..traversal segments are rejected. write_noteoverwrites with no revision history.- Binds to loopback by default; the reverse proxy is the sole ingress.
search_notesreads every page on each call. There is no index.- The bridge stores nothing. It holds no state beyond the environment it was started with, so a restart is always safe.
Distribution
Published as an npm package and as an agent plugin from this same repository.
server.json is the official MCP Registry entry (schema 2025-12-11): the npm
package, run over stdio. It deliberately declares no remote endpoint — that is
each deployment's own URL, so add a remotes entry if you want yours listed.
The registry name is reverse-DNS and must match the publishing GitHub account:
replace OWNER in server.json ("name") and package.json ("mcpName") with
your GitHub login before publishing — the two must be identical.
Agent plugin manifests live at .zcode-plugin/plugin.json (ZCode) and
.claude-plugin/plugin.json + .claude-plugin/marketplace.json (Claude Code and
the skills.sh layout). The plugin ships the MCP server plus
skills/silverbullet-mcp/, and reads the bearer token from the client's user
config as mcp_token, so no secret is stored in the repository.
License
MIT
来源:README.md,提交 3fdfc9c
工具
0版本历史
1- v1.0.0最新Oct 4, 2026

