Skip to content

docs: add IsMalicious MCP setup guide - #798

Open
hexablob wants to merge 1 commit into
LibreChat-AI:mainfrom
hexablob:docs/ismalicious-mcp-guide
Open

hexablob wants to merge 1 commit into
LibreChat-AI:mainfrom
hexablob:docs/ismalicious-mcp-guide

Conversation

@hexablob

@hexablob hexablob commented Oct 3, 2026

Copy link
Copy Markdown

Summary

Adds an IsMalicious MCP setup guide to the existing MCP server guide section. The guide configures the published @ismalicious/mcp-server@0.6.0 stdio package with masked per-user API key and secret fields, then shows indicator triage and explicit check_url and scan_before_use calls.

It distinguishes optional model tool calls from automatic interception or enforcement, explains block/warn/allow and unknown link reputation, and covers credentials, connection errors, quotas, and missing tool calls. It also adds the guide to the index and sidebar. English content only, following the translation workflow.

Provider contribution for the IsMalicious API-backed MCP server. No LibreChat application code, new dependencies, real credentials, or images are added.

Validation

  • pnpm lint
  • pnpm typecheck
  • pnpm lint:prettier
  • pnpm check:config-version
  • pnpm test
  • pnpm build
  • Served the production build locally and checked HTTP 200, the guide heading, rendered configuration/tool examples, and its index card on /docs/mcp_servers.
  • Extracted the guide's YAML with js-yaml and validated its mcpServers object with LibreChat's native MCPServersSchema at f10b1d91f1eee3a2c82d5247bf620351486b7c1b.
  • Ran the exact YAML command against a local HTTP fixture server: stdio initialization reports version 0.6.0; the three documented tools and their argument names exist; the IOC, URL, and content calls preserve inputs and returned verdicts. Eight checks, three synthetic HTTP requests, zero production API calls. Only synthetic credentials were used; they were absent from stdout and stderr.

Local checks use pnpm 9.15.9 and Node.js 24.21.0. The smoke test substitutes the two declared user placeholders before launching the process; LibreChat's runtime credential binding was reviewed in its native source.

No LibreChat UI installation, model-driven tool selection, authenticated production request, or detector accuracy test is claimed. The guide installs the published npm 0.6.0 package; it does not claim to build that version from the separate public source mirror currently at 0.5.0.

@vercel

vercel Bot commented Oct 3, 2026

Copy link
Copy Markdown

@hexablob is attempting to deploy a commit to the LibreChat's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant