MCP server

The same commands, without the terminal

paniolo mcp serves Paniolo's retrieval, scan, wiki, staleness, evolve, skills, and browser surfaces to any MCP client over stdio. Each tool is the sibling of a CLI command, scoped to one configured harness root, and labelled with whether it reads, writes, or destroys.

Quick start

Register it once

The server is the CLI, so there is nothing extra to install. Point your client at it:

npx @paniolo/cli mcp

Clients that read a project-level .mcp.json — Claude Code among them — want an entry like this at the harness root:

{ "mcpServers": { "paniolo": { "command": "paniolo", "args": ["mcp"] } } }

A stamped harness writes that file for you as part of the retrieval hook set, alongside the prompt-search and index-refresh hooks:

paniolo evolve hooks install --retrieval --vendor claude

Add --dry-run to see the plan first, or --all to cover every detected vendor. The registration is ownership-scoped: only entries Paniolo wrote are touched, so a hand-added server of your own survives.

How it works

One root, declared up front

SurfaceBehavior
TransportJSON-RPC over stdio, protocol 2025-06-18. The server reports itself as paniolo at the CLI's own version.
ScopeThe harness root holding paniolo.config.json — the working directory, or --root. Every tool reads the same configured repos, wikis, and scan targets the CLI would.
Scope overridesRefused. A call that tries to pass its own root, config, or qmd endpoint fails with invalid_arguments rather than widening the server's reach for one request.
Capabilitiestools and resources. Resource subscriptions and list-changed notifications are not offered.
AvailabilityEvery tool is always listed. A surface the deployment has not configured — no wiki, no ledger, no browser — fails at call time with a named code such as stale_unavailable, so a client can tell "not set up" from "went wrong".
responseFormatOn all 39 tools. concise (the default) drops bulk free-text — result snippets, observation bodies, narration, manifest text — and detailed returns the full payload.
Safety

Reads and writes are separate tools

The split is structural rather than a flag: stale reads the ledger and stale_write mutates it; evolve reports and evolve_write changes. A client that only wants to look can allow the read tools and nothing else.

Each tool carries the standard MCP annotations, so a client can gate on them without parsing prose. Of the 39, 18 are read-only and 21 write; of those writes, 9 are marked destructive.

Destructive wiki operations plan by default — a deliberate inversion of the CLI, where wiki rename and wiki move write immediately. Over MCP they report the transform and change nothing until you pass apply: true. The same holds for workspace, for stale_write's plan-shaped ops, and for evolve_write.

Two exceptions worth knowing: wiki_new writes on call, refusing to overwrite rather than planning, and skills_write performs its lockfile operation immediately. The agent-driven staleness work — run, propose, worker — is not served as a tool at all; it goes through job_submit, or stays in the CLI.

The browser tools act as the signed-in human on whatever origin a tab is on, including production sites. They are annotated as writes for that reason even when they look like reads, and browser_webmcp_call can run site code with real consequences — the contact form on this site sends mail.

Catalog

Every tool the server offers

Grouped by family. "Plans" means the op reports without writing until apply is set.

Retrieval

Hybrid search over the configured qmd collections, plus index maintenance. The CLI guide is paniolo qmd. 3 tools

ToolKindWhat it does
qmdreadThe sibling of paniolo qmd search|vsearch|query|get|multi-get|ls|status|print-config|doctor, selected with op.
qmd_admindestructiveIndex maintenance — cleanup releases orphaned rows and stale worker installs, vacuum compacts the shared database, gpu reports or persists the acceleration choice.
queryreadDeprecated alias for qmd with op: "query", kept for one release.

Wiki

The knowledge base: validation, reference graph, discovery, and page operations. 12 tools

ToolKindWhat it does
wiki_validatereadValidate configured wiki targets; optionally semantic, changed-only, or a file list.
wiki_refsreadEvery reference to a slug across the configured repos, classified by role and status, plus the repos the scan could not reach.
wiki_where_does_this_goreadFind the pages related to a fact or snippet — where a new claim belongs.
wiki_find_duplicatesreadFind pages close to candidate text, above a similarity threshold.
wiki_suggest_linksreadSuggest links for one target-relative page.
wiki_newwriteStamp a page the corpus' rules accept: kind prefix, frontmatter, log.md entry, index links. Writes on call; refuses to overwrite.
wiki_set_statuswriteSet a page's lifecycle status:, updating updated: and the operation log. Plans.
wiki_fixdestructiveApply the safe autofixes for one target.
wiki_renamedestructiveRename a page and rewrite every reference to it. Plans.
wiki_movedestructiveMove a page into another configured wiki, rewriting references. Plans.
wiki_archivedestructiveSnapshot a page's bytes into raw/wiki-archive/ with provenance, repoint references, and remove the page — no stub left behind. Plans.
wiki_deletedestructiveDelete a page: index entries go mechanically, while prose references hold it back until resolved. Plans.

Browser

The shared agent browser — the tab the human is looking at. 10 tools

ToolKindWhat it does
browser_tabsreadList open tabs — what the human has in front of them, before acting.
browser_consolereadDrain console output, logs, and failed requests since the last call. The first call subscribes and returns no history.
browser_screenshotreadCapture a tab as a base64 PNG.
browser_webmcp_listreadList the tools the current page declares about itself via WebMCP. Same-origin only.
browser_navigatewritePoint a tab at a URL — it moves a page someone may be using.
browser_clickwriteClick an element as the signed-in user.
browser_fillwriteSet a form field, dispatching the input and change events frameworks listen for.
browser_typewriteType as real keyboard input, for fields that only react to genuine typing.
browser_evalwriteEvaluate JavaScript in a tab and return its value. chrome:// pages are refused.
browser_webmcp_callwriteRun a tool the page declares. Executes site code as the signed-in user.

Staleness

The knowledge-base freshness ledger. 2 tools

ToolKindWhat it does
stalereadlist, summary, next, show, report, status, packet. only narrows list and summary to a file or subtree.
stale_writedestructivescan, flag, retry, resolve, prune, rebase, seed. Plan-shaped ops report until apply.

Scan, skills, and evolve

The harness itself — findings, managed skills, and configuration. 5 tools

ToolKindWhat it does
scanreadThe read-only scan over the configured scope. Returns a findings summary plus a resource link to the full report.
skillsreadEach lockfile entry's source, and whether its files are present on disk.
skills_writedestructiveadd, update, bundle, eject, link. Executes on call.
evolvereadstatus, the config graph, effective config and schema, harness status and detection, and hook coverage.
evolve_writedestructiveDiagnose, validate, rollback, config migration, hook install and removal, harness plan/apply/upgrade/connect, and the git and scan integrations. Plans.

Jobs

Long-running work on a worker thread, so a call does not hold the connection. 4 tools

ToolKindWhat it does
job_submitwriteStart an op — the stale family covers run, propose, merge-sync, worker, index, and verify.
job_statusreadRunning, completed, failed, or cancelled, with timestamps and result/log resource URIs.
job_resultreadA terminal job's stored result — the same JSON the CLI emits. A cancelled run still returns its partial report.
job_cancelwriteCooperative cancellation. The op stops between ledger transitions, never mid-write.

Host

Status and local conveniences on the machine the server runs on. 3 tools

ToolKindWhat it does
harnessreadCached session identity (no network call), which declared secret names are stored — never values — and the configured workspace's repos.
workspacewriteRegenerate the .code-workspace manifest from the repo graph. Plans, reporting folders added and removed.
clip_savewriteResolve the host clipboard to file paths: an image is saved as a PNG, copied files echo their existing paths.
Resources

Bulk payloads stay out of the reply

Tools that would otherwise return something enormous return a summary plus a paniolo:// link, so a client fetches the full body only when it wants it. Every configured wiki page is also listed directly as a resource.

URITypeContents
paniolo://qmd/doc/{docid}markdownThe full body of one indexed document.
paniolo://scan/{target}/reportjsonThe last scan result for a target, or default.
paniolo://stale/items/{id}jsonOne allegation and its sealed observations. {id} may be a unique prefix.
paniolo://jobs/{id}/resultjsonA terminal job's stored outcome.
paniolo://jobs/{id}/logtextA job's event log — submitted, cancellation requested, finished.
paniolo://wiki/{name}/findingsjsonOne wiki's full validation report.
paniolo://wiki/{name}/page/{slug}markdownOne wiki page's source, listed for every page in every configured wiki.
Learn more

Each tool has a guide behind it

The server is a surface, not a separate product — every tool does what its command does. For the surfaces themselves, read paniolo qmd, LLM Wiki, paniolo stale, the scan guide, Skills, and the config reference for the paniolo.config.json that decides the server's scope. For what agents do with a page that describes itself, see Agent-First.