io.github.immuneeb/marigold is an MCP server that comment on AI-generated webpages; feedback flows back to your coding agent. Free, MIT, local-first. Its tool list has not been published yet, requires no API key, and scores 56/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"io-github-immuneeb-marigold": {
"args": [
"-y",
"pnpm"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Local drafts — a review loop for agent-authored HTML. Your coding agent writes a rich HTML/SVG draft to a file; marigold-draft open serves it in a comment shell in your browser; you highlight, comment, and edit in place; Send feedback to agent returns your review to the agent's blocked CLI call as JSON, and its next save live-reloads the tab with your comments re-anchored.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'pnpm' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
## Summary `pnpm` accepts package names from the env lockfile `configDependencies` section and uses those names directly when creating config dependency symlinks under `node_modules/.pnpm-config`. A malicious repository can commit a crafted `pnpm-lock.yaml` whose env-lockfile document contains a traversal-shaped config dependency name such as `../../PWNED_CFGDEP`. During `pnpm install`, pnpm installs the config dependency and creates a symlink at a path derived from that name. In local testin
pnpm: `patch-remove` could delete project-selected files outside the patches directory
## Summary The `patch-remove` deletion-scope issue tracked as GHSA-72r4-9c5j-mj57 / CAND-PNPM-030 has been addressed in pnpm. A crafted patch entry could resolve outside the configured patches directory and cause `pnpm patch-remove` to delete an arbitrary reachable file. This patch validates the configured directory and every resolved target before unlinking anything, then deletes the final directory entry without following it. ## Security boundary - Traversal and absolute paths that resolve
pnpm: Hoisted install imports lockfile alias outside node_modules
## Summary The hoisted dependency alias issue tracked as GHSA-fr4h-3cph-29xv / CAND-PNPM-059 has been addressed in both pnpm and pacquet. A crafted lockfile alias could be joined directly under a hoisted `node_modules` directory. Traversal aliases could escape that directory, while reserved aliases such as `.bin` or `.pnpm` could overwrite pnpm-owned layout. This patch validates package-name semantics and path containment before graph insertion or filesystem work. ## Security boundary - The
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
## Summary The staged-tarball filename traversal reported as GHSA-v23m-ccfg-pq9h / CAND-PNPM-038 is fixed on `main` by [pnpm/pnpm#12303](https://github.com/pnpm/pnpm/pull/12303), merged as `65443f4bdf1f0db9c8c7dc58fee25252607e9234`. Before the fix, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite another reachable file. The merged fix validates both fields, deri
pnpm: Reserved bin name deletes PNPM_HOME during global remove
<details> <summary>Maintainer Action Plan</summary> ## Maintainer Action Plan This report is ready to review with the shared patch branch. Start with the PR and the expected fixed behavior, then use the detailed exploit narrative below only if you want to replay the original path. - Advisory: `CAND-PNPM-085` / `GHSA-4gxm-v5v7-fqc4` - Advisory URL: https://github.com/pnpm/pnpm/security/advisories/GHSA-4gxm-v5v7-fqc4 - Shared patch PR: https://github.com/pnpm/pnpm-ghsa-j2hc-m6cf-6jm8/pull/1 - S
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in browser
Monitor browser logs directly from Cursor and other MCP compatible IDEs.
Chrome DevTools for coding agents
🔥 Official Firecrawl MCP Server - Adds powerful web scraping and search to Cursor, Claude and any other LLM clients.
MCP server paired with a browser extension that enables AI agents to control the user's browser.
MCP Security Weekly
Get CVE alerts and security updates for io.github.immuneeb/marigold and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
Local drafts — a review loop for agent-authored HTML. Your coding agent writes a
rich HTML/SVG draft to a file; marigold-draft open serves it in a comment
shell in your browser; you highlight, comment, and edit in place; Send
feedback to agent returns your review to the agent's blocked CLI call as
JSON, and its next save live-reloads the tab with your comments re-anchored.
No database, no accounts, no network. One warm background daemon; comments persist in a sidecar file next to the draft.
npm i -g marigold-draft
marigold-draft agent-setup # wires up Claude Code (skill) + Claude Desktop (MCP)
Or hand this prompt to your coding agent:
Install Marigold for me using
npm i -g marigold-draft, then read https://marigold.page/draft/setup.md and set yourself up to use it.
Full docs: packages/local/README.md — the
agent loop, in-place edits, .svg drafts, sharing, and graduating a draft to
hosted Marigold when you want a
link you can send to someone.
| Package | What it is |
|---|---|
packages/local | marigold-draft (npm) — the CLI, daemon, review shell, and MCP server |
packages/core | The shared anchoring engine: deterministic element instrumentation, composite comment anchors (marigoldId → css → textQuote), and the Marigold Way methodology packs. Bundled into the CLI at build time. |
The anchoring engine is the same one hosted Marigold runs, so comments re-anchor identically across draft revisions locally and doc versions in the cloud, and a draft promoted to the cloud instruments byte-for-byte the same.
pnpm install
pnpm test # vitest across both packages
pnpm build # bundles packages/local/dist/cli.cjs
Hosted Marigold ("Google Docs for AI-generated webpages" — share by email, comment on the rendered page, agents read feedback over MCP) is a separate, closed-source service. This repo is the open-source local tool, MIT-licensed, and is where its issues and pull requests live.
Development happens in a private monorepo that also contains the hosted service; the OSS subset is auto-synced here on every change, so this mirror is always current. PRs are welcome — they're reviewed here and ported onto the internal tree with your authorship preserved.
MIT.