Back to Home
mholzen icon

workflowy

Verified Safe

by mholzen

Overview

Connect AI assistants to Workflowy data and outlines for search, bulk operations, and reporting, or manage Workflowy via CLI.

Installation

Run Command
workflowy mcp --expose=all --log-file=/tmp/workflowy-mcp.log

Environment Variables

  • WORKFLOWY_API_KEY

Security Notes

The `workflowy_transform` MCP tool and CLI `transform` command include an `--exec` flag that allows execution of arbitrary shell commands on the host machine. If the MCP server is run with `--expose=all` (or `--expose=transform`) and connected to an AI assistant, a malicious or poorly-constrained AI could execute arbitrary local code. While the `--write-root-id` feature provides sandboxing for Workflowy data operations, it does NOT mitigate the risk of local shell command execution via `--exec`. Users must exercise extreme caution when exposing `workflowy_transform` to AI assistants or when using the `--exec` flag directly. API keys are managed responsibly via file permissions and environment variables, not hardcoded.

Similar Servers

Stats

Interest Score45
Security Score6
Cost ClassMedium
Avg Tokens1000
Stars16
Forks1
Last Update2026-01-18

Tags

WorkflowyCLIAIMCPProductivityGo