Skip to main content
Glama

librus-mcp

Локальный MCP-сервер с доступом только для чтения для учётной записи Librus Portal. Он использует процедуру входа в Portal для получения кратковременного токена API Librus для выбранной учётной записи Synergia.

Модель безопасности

  • Учётные данные считываются только из LIBRUS_EMAIL и LIBRUS_PASSWORD.

  • Файлы cookie и токены хранятся в памяти и отбрасываются при завершении процесса или вызове librus_logout.

  • Сервер разрешает HTTPS-запросы только к portal.librus.pl и api.librus.pl.

  • Он предоставляет список разрешённых ресурсов API с доступом только для чтения; он не может отправлять сообщения, отмечать уведомления как прочитанные или отправлять произвольные запросы.

  • Сервер намеренно не записывает в stdout/stderr ни запросы, ни ответы, ни учётные данные, ни токены, ни данные API. Stdout зарезервирован для трафика протокола MCP.

Не храните учётные данные в package.json, в конфигурации MCP, сохранённой в Git, или в отслеживаемом файле .env.

Related MCP server: moodle-utn-mcp

Установка и сборка

cd /home/xadix0wy/librus-mcp
npm install
npm run build

Настройка MCP-хоста

Используйте переменные окружения в приватной конфигурации хоста или в хранилище секретов:

{
  "mcpServers": {
    "librus": {
      "command": "node",
      "args": ["/home/xadix0wy/librus-mcp/dist/index.js"],
      "env": {
        "LIBRUS_EMAIL": "your-email@example.com",
        "LIBRUS_PASSWORD": "your-password"
      }
    }
  }
}

LIBRUS_CLIENT_ID необязателен. По умолчанию используется публичный клиентский идентификатор из устаревшего мобильного потока Librus. Он не считается секретом.

Инструменты

  • librus_profiles: перечисляет учётные записи Synergia, привязанные к учётной записи Portal.

  • librus_get: считывает оценки, посещаемость, расписание, домашние задания, уведомления, информацию о школе и другие поддерживаемые ресурсы API. Передавайте account_login из librus_profiles.

  • librus_logout: очищает все данные аутентификации в памяти.

Portal может потребовать прохождения reCAPTCHA или выполнения действия с учётной записью. В этом случае сервер останавливается с понятной ошибкой; выполните требуемое действие напрямую на https://portal.librus.pl или в официальном приложении, а затем повторите попытку.

Совместимость

Это основано на недокументированном механизме Portal/API, замеченном в исходном коде устаревшего Android-приложения Szkolny. Librus может изменить или ограничить его без предупреждения. Он предназначен только для владельца учётной записи и должен использоваться в соответствии с условиями Librus и правилами школы.

Available Tools

3 tools
librus_getB

Read a supported Librus API resource. This tool is read-only and accepts no arbitrary URL or write operation.

ParametersJSON Schema
NameRequiredDescriptionDefault
resourceYesThe Librus resource to retrieve.
week_startNoMonday/date for timetable, in YYYY-MM-DD format. Ignored for other resources.
account_loginYesThe account login returned by librus_profiles.

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure, and it does assert the key safety-relevant trait: the tool is read-only and non-destructive. However, it does not describe return values, pagination, or failure behavior, and since the schema has no output schema, the agent knows neither the shape of the result nor what to expect on unsupported cases.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences with the primary verb+resource front-loaded. The second sentence earns its place by constraining scope (read-only, no arbitrary URL), even though it partially restates the word 'read.' Overall it is tight and free of filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description plus fully documented schema adequately cover what the tool does and how to call it, including the dependency expressed in the account_login parameter. Yet with no output schema and no description hint about return shape, an agent invoking this across 27 heterogeneous resources has an at-a-glance fixed description of the response.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%: the enum of 27 resources, the YYYY-MM-DD pattern with 'ignored for other resources', and the 'account_login returned by librus_profiles' dependency are all already documented in the input schema. The tool description adds no parameter-specific meaning, which fits the baseline of 3 for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb ('Read') and resource ('a supported Librus API resource'), so the core capability is clear. The added boundary — 'accepts no arbitrary URL or write operation' — separates it from any generic API-access tool, and the read-only framing naturally distinguishes it from the auth-oriented siblings (librus_profiles, librus_logout), though it never names them.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description conveys when to use the tool implicitly: when a supported Librus resource needs to be retrieved. It makes explicit exclusions (no arbitrary URLs, no writes), which helps an agent know what NOT to do here, but it does not name an alternative tool or state a precondition such as retrieving account_login via librus_profiles first.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

librus_logoutA

Clear all in-memory Librus cookies and tokens. Nothing is persisted to disk.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description bears full responsibility for disclosing behavior. It clearly states the exact state that changes ('cookies and tokens') and adds persistence context with 'Nothing is persisted to disk.' This goes beyond a bare verb and gives an agent a solid understanding of the tool's boundary, even though it does not explicitly describe post-logout authentication state.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences with no filler, and the main action is front-loaded. The second sentence adds an important clarifier about disk persistence without redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a zero-parameter, no-annotation, no-output-schema tool, the description is largely complete: it says what is deleted, in what scope, and what is not deleted. An agent may need to infer that subsequent tool calls will require reauthentication, but that follow from the stated clearing of cookies and tokens and does not make the description inadequate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters and 100% schema coverage, so there are no parameter semantics to clarify. The description correctly does not mention parameters, and the baseline of 4 for no-parameter tools applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action ('Clear all in-memory Librus cookies and tokens') with a concrete resource. It clearly distinguishes the tool from siblings like librus_get and librus_profiles by targeting session/logout state rather than profiles or data retrieval. There is no ambiguity about what the tool is for.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies the tool is for logging out or ending a session by clearing auth data, so an agent can infer when to use it. However, it does not explicitly say when to use this tool instead of siblings like librus_profiles or librus_get. It could have named these alternatives and given conditions, but the use case is reasonably clear from the token-based action.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

librus_profilesA

List Librus Synergia accounts linked to the configured Librus Portal account. Use the returned login with librus_get.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description conveys that this is a read-only listing operation and that it depends on the 'configured Librus Portal account,' which is useful. However, no annotations are provided, and the description does not elaborate on possible return formats, errors, or whether multiple accounts may be returned.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two short sentences with no filler. The first states the primary purpose; the second gives an essential workflow tidbit. It is front-loaded and each sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a no-parameter tool with no output schema, the description is largely complete: it specifies what the tool lists and how the return value should be used. It does not describe the return structure in detail, but that is a minor omission given the tool's straightforward nature.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters and an empty input schema, so there are no parameter details to clarify. A baseline of 4 for a 0-parameter tool is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a clear action and resource: 'List Librus Synergia accounts linked to the configured Librus Portal account.' It also explicitly names the sibling librus_get as the consumer of the returned data, which distinguishes it from related tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives direct workflow guidance: 'Use the returned login with librus_get.' This tells an agent exactly what to do with the result, though it does not explicitly cover when not to use the tool or mention alternate scenarios.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 3 tool updatesv0.1.0
    • First observedlibrus_get
    • First observedlibrus_logout
    • First observedlibrus_profiles

TDQS

A3.9/5.0
Disambiguation5/5

Each tool has a clear, distinct responsibility: list linked accounts, read a specific API resource, and clear the session. The profiles tool explicitly points to librus_get, removing ambiguity.

Naming Consistency4/5

All tools share the consistent librus_ prefix and snake_case style, making them easy to recognize. There is a minor inconsistency between noun-based librus_profiles and verb-based librus_get/librus_logout.

Tool Count5/5

Three tools is a minimal but well-scoped set for a read-only, session-based Librus API bridge. Each tool serves a real workflow step: discovering accounts, reading data, and ending the session.

Completeness3/5

The session lifecycle is covered, but librus_get is generic and does not enumerate which resources are supported. An agent may struggle to know what API resources can actually be requested.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables guardians to securely query read-only Vklass data such as children, news, calendar entries, assignments, grades, meals, and notifications through MCP, with per-user BankID and OAuth 2.1 authentication.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables read-only access to University of Waterloo Learn and Piazza, allowing users to view courses, assignments, grades, submissions, discussions, and more through an MCP server.
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/TechAdrianPro/librus-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server