‹ The Index

Carbone

npm

Generate PDF/DOCX/XLSX/PPTX from templates+JSON. Convert Office/HTML/MD to PDF. Universal templating

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Productivity — see all ranked ›

Install (Claude Code):

claude mcp add arbone -- npx -y carbone-mcp
deep

“Spells out the SSRF and shared-key risk behind two environment defaults”

Security audit

scanned 2026-07-30

Every finding is shown in full. Nothing on this page is behind a licence — there is no advisory to name and no install script to read.

No known advisoriesclearchecked against OSV for 1.5.0
No permission surface detecteddeclares no dependency that reaches files, shell or network
Signed build provenancepublished from public CI with an attestation

npm ↗  ·  source ↗  ·  pkg:carbone-mcp

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›