# carbone-mcp

Official MCP for Carbone — Document Generation, Document Conversion, and Universal Templating. Generate PDF, DOCX, XLSX, PPTX, ODT, ODS, CSV, HTML, Markdown and XML documents from templates and JSON data. Convert Office documents (DOCX, XLSX, PPTX), Markd

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.6.0
- **Author:** carboneio
- **License:** Apache-2.0
- **npm:** carbone-mcp
- **Endpoints:** streamable-http https://mcp.carbone.io
- **Source:** https://github.com/carboneio/carbone-mcp
- **Endpoint health:** reachable (last checked 2026-09-30T00:24:24.697Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 103 days — stale; the grade is a claim about the present made from dated evidence

## Security scan

- **Status:** clean
- **Scanned:** 2026-06-24T01:13:35.477Z
- **Version scanned:** 1.2.2
- **CVEs:** none found by OSV at scan time

## Tools

Tool surface: no readable artifact — tool surface unknown.

## Install

**Verdict: review** — Installable, but 2 things to check first: The last scan is 103 days old — the evidence behind this verdict is dated.
**Cautions** (coverage gaps and advisories — never blocking)
- The last scan is 103 days old — the evidence behind this verdict is dated.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"carbone\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"carbone-mcp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs locally and hosted.
- Floor 12, ceiling 30 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/carbone-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/carbone-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/carbone-mcp
- HTML page: https://forgeregistry.com/registry/carbone-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
