Back to Browse

Release Notes Forge MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Summarize local Git release shape without returning commit messages, paths, hashes, or remotes.

About

Summarize local Git release shape without returning commit messages, paths, hashes, or remotes.

Security Report

7.2
Moderate7.2Low Risk

Release Notes Forge is a well-designed, security-conscious MCP server that reads local Git history and aggregates statistics while explicitly suppressing sensitive data (commit messages, hashes, paths, authors). The code demonstrates strong path traversal protection, proper input validation, and careful data sanitization. Minor code quality issues around error handling and logging do not materially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

6 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

process_spawn

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-mrfentmen-release-notes-forge-mcp": {
      "args": [
        "-y",
        "release-notes-forge-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

release-notes-forge-mcp

Release Notes Forge reads local Git history and turns it into a release shape: commit count, broad change categories, and age buckets.

Quick start

npm install
npm test
npm start

Use summarize_release_history with a local repository path inside RELEASE_NOTES_ROOT. The server never pushes, edits, or contacts a remote repository.

Privacy and limits

Commit messages, hashes, paths, branches, remotes, and author identities are suppressed. This is an aggregate release planning aid, not a changelog generator.

Reviews

No reviews yet

Be the first to review this server!