Back to Home
General-Mudkip icon

d2l-mcp-server

Verified Safe

by General-Mudkip

Overview

Provides AI assistants with tools to interact with D2L Brightspace LMS for managing academic activities.

Installation

Run Command
d2l-mcp

Environment Variables

  • D2L_HOST
  • D2L_COURSE_ID

Security Notes

The server uses Playwright to manage persistent browser sessions, saving sensitive session data (cookies, local storage) to '~/.d2l-session/'. A compromise of the local machine could lead to session hijacking. The 'download_file' tool allows specifying a 'savePath', which, if controlled by a malicious or poorly designed agent, could potentially lead to arbitrary file writes on the local filesystem. However, direct external arbitrary input is unlikely to control this path as it's passed from the agent. No direct 'eval' or obvious remote code execution vulnerabilities were found.

Similar Servers

Stats

Interest Score0
Security Score6
Cost ClassMedium
Avg Tokens1000
Stars0
Forks0
Last Update2025-11-28

Tags

LMSAI AgentEducationBrightspaceTool-use