# minutes-mcp

MCP server for minutes — conversation memory for AI assistants. Works with Claude Desktop, Mistral Vibe, Cursor, Windsurf, and any MCP client.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.27.2
- **Author:** Mat Silverstein
- **License:** MIT
- **npm:** minutes-mcp
- **Source:** https://github.com/silverstein/minutes
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 29 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-07T15:50:59.189Z
- **Version scanned:** 0.26.1
- **CVEs:** none found by OSV at scan time
**Findings**
- injection-shaped content (note) in the `stop_copilot` tool: Imperative addressed to the AI model

## Tools

21 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `start_recording` — Start recording audio with call-aware preflight. When a known call app is active, Minutes can infer call intent and block silent mic-only call captures unless e
- `stop_recording` — Stop the current recording and process it (transcribe, diarize, summarize).
- `get_status` — Check if a recording is currently in progress.
- `list_processing_jobs` — List background processing jobs for recent recordings, including queued, transcript-ready, needs-review, failed, and completed work.
- `research_topic` — Research a topic across policy-authorized meetings within the supported corpus bounds. Restricted meetings are excluded. An override requires an operator launch
- `process_audio` — On macOS and Linux, process a bounded WAV file from the Minutes inbox or Downloads through the transcription pipeline. Compressed/private containers and Windows
- `add_note` — Add a note to the current active recording. Notes are timestamped and included in that recording's meeting summary. Existing meeting files cannot be mutated fro
- `start_dictation` — Start dictation mode. Speak naturally — text accumulates across pauses and the combined result is written when dictation ends. Runs until stop_dictation is call
- `stop_dictation` — Stop the current dictation session.
- `list_voices` — List active voice enrollments for speaker identification. Shows who has been enrolled, sample count, and model version.
- `confirm_speaker` — Compatibility registration for speaker confirmation. Agent-controlled mutation is intentionally unavailable; confirm in the Minutes app or a human CLI session s
- `add_agent_annotation` — Append attributed agent commentary as an agent.annotation event. This never edits meeting markdown/frontmatter and is rejected unless the agent_id is allowed in
- `start_copilot` — Start the independent Minutes real-time copilot for a goal. This launches `minutes copilot start`; MCP does not run model inference, own capture, or need to sta
- `stop_copilot` — Request that the active Minutes copilot stop. This invokes `minutes copilot stop` and never stops recording or live transcription. Calling it while no copilot i
- `copilot_status` — Read the current operational copilot state from the strict `minutes copilot status --json` contract. This is observation only and returns a clear Off/not-active
- `read_copilot_nudges` — Read nudges observed from the active real CLI copilot stream. Use cursor (or a numeric since value) for lossless delta reads; since also accepts durations such 
- `start_live_transcript` — Start real-time transcription. If a recording is already running, it already includes a live transcript — use read_live_transcript to read it. Runs until stop i
- `read_live_transcript` — Read the live transcript — works during both recordings and live transcript sessions. Use 'since' to get new finalized lines after a cursor (line number) or tim
- `ingest_meeting` — Extract facts from a meeting and update the knowledge base (person profiles, log, index). Requires [knowledge] to be configured in config.toml. Uses structured 
- `resummarize_meeting` — Re-run the AI pass (summary, action items, decisions) on an edited meeting or memo. Preview by default: returns the regenerated content WITHOUT writing — note t
- `knowledge_status` — Reconcile persistent meeting derivatives and show the privacy-safe knowledge-base status. This cleanup/status tool cannot create or register an external index.

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"minutes\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"minutes-mcp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/minutes-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/minutes-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/minutes-mcp
- HTML page: https://forgeregistry.com/registry/minutes-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
