Lexware MCP Server

@lazyants/lexware-mcp-server npm v5.2.0 Source verified

Published by lazyants — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.

MCP server for the Lexware Office API — manage invoices, contacts, articles, vouchers, and more

Trust grade
A
97/100
Last scanned get badge →
Trust
A · 97/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
Moderate
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 100 − adoption risk = 97/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:

The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.

2. Client adoption risk — 100 − 3 = 97. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−3 capability blast radius (moderate) — client exposure if the model is manipulated

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 1

medium Untrusted input can drive an external actionMTC-FLOW-005

Untrusted-input tools ([lexware_download_credit_note_file, lexware_download_delivery_note_file, lexware_download_down_payment_invoice_file, lexware_download_dunning_file, lexware_download_file, lexware_download_invoice_file, lexware_download_order_confirmation_file, lexware_download_quotation_file]) co-exist with external-action tools ([lexware_create_event_subscription, lexware_list_event_subscriptions, lexware_get_event_subscription, lexware_delete_event_subscription, lexware_verify_webhook_signature, lexware_upload_file]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.

Evidence: untrusted [lexware_download_credit_note_file, lexware_download_delivery_note_file, lexware_download_down_payment_invoice_file, lexware_download_dunning_file, le

Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.

Location: flow lexware_download_credit_note_file → lexware_create_event_subscription

Tools 66

Each tool and what it can reach — statically extracted from the published source.

  • lexware_create_event_subscriptionnetwork egress
  • lexware_delete_event_subscriptionnetwork egress
  • lexware_download_credit_note_fileingests untrusted input
  • lexware_download_delivery_note_fileingests untrusted input
  • lexware_download_down_payment_invoice_fileingests untrusted input
  • lexware_download_dunning_fileingests untrusted input
  • lexware_download_fileingests untrusted input
  • lexware_download_invoice_fileingests untrusted input
  • lexware_download_order_confirmation_fileingests untrusted input
  • lexware_download_quotation_fileingests untrusted input
Show 56 more tools ↓
  • lexware_get_event_subscriptionnetwork egress
  • lexware_list_event_subscriptionsnetwork egress
  • lexware_upload_filenetwork egress
  • lexware_verify_webhook_signaturenetwork egress
  • lexware_create_articleno sensitive capability
  • lexware_create_contactno sensitive capability
  • lexware_create_credit_noteno sensitive capability
  • lexware_create_delivery_noteno sensitive capability
  • lexware_create_invoiceno sensitive capability
  • lexware_create_order_confirmationno sensitive capability
  • lexware_create_quotationno sensitive capability
  • lexware_create_voucherno sensitive capability
  • lexware_deeplink_contactno sensitive capability
  • lexware_deeplink_credit_noteno sensitive capability
  • lexware_deeplink_delivery_noteno sensitive capability
  • lexware_deeplink_down_payment_invoiceno sensitive capability
  • lexware_deeplink_dunningno sensitive capability
  • lexware_deeplink_fileno sensitive capability
  • lexware_deeplink_invoiceno sensitive capability
  • lexware_deeplink_order_confirmationno sensitive capability
  • lexware_deeplink_quotationno sensitive capability
  • lexware_deeplink_recurring_templateno sensitive capability
  • lexware_deeplink_voucherno sensitive capability
  • lexware_delete_articleno sensitive capability
  • lexware_get_articleno sensitive capability
  • lexware_get_contactno sensitive capability
  • lexware_get_credit_noteno sensitive capability
  • lexware_get_delivery_noteno sensitive capability
  • lexware_get_down_payment_invoiceno sensitive capability
  • lexware_get_dunningno sensitive capability
  • lexware_get_file_statusno sensitive capability
  • lexware_get_invoiceno sensitive capability
  • lexware_get_order_confirmationno sensitive capability
  • lexware_get_paymentsno sensitive capability
  • lexware_get_profileno sensitive capability
  • lexware_get_quotationno sensitive capability
  • lexware_get_recurring_templateno sensitive capability
  • lexware_get_voucherno sensitive capability
  • lexware_list_articlesno sensitive capability
  • lexware_list_contactsno sensitive capability
  • lexware_list_countriesno sensitive capability
  • lexware_list_payment_conditionsno sensitive capability
  • lexware_list_posting_categoriesno sensitive capability
  • lexware_list_print_layoutsno sensitive capability
  • lexware_list_recurring_templatesno sensitive capability
  • lexware_list_voucherlistno sensitive capability
  • lexware_list_vouchersno sensitive capability
  • lexware_pursue_credit_noteno sensitive capability
  • lexware_pursue_delivery_noteno sensitive capability
  • lexware_pursue_dunningno sensitive capability
  • lexware_pursue_invoiceno sensitive capability
  • lexware_pursue_order_confirmationno sensitive capability
  • lexware_update_articleno sensitive capability
  • lexware_update_contactno sensitive capability
  • lexware_update_voucherno sensitive capability
  • lexware_upload_voucher_fileno sensitive capability

Toxic flows 1

Cross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).

What this scan could not see

Versions 4

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v5.2.0 latest A 97/100 1 1.13.0 2026-09-08
v5.0.0 A 97/100 1 1.12.1 2026-08-20
v4.2.0 A 97/100 1 1.12.1 2026-07-27
v4.1.0 A 97/100 2 1.10.0 2026-07-27

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 97/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/lazyants-lexware-mcp-server/badge.svg)](https://mcptrustchecker.com/registry/lazyants-lexware-mcp-server)
HTML
<a href="https://mcptrustchecker.com/registry/lazyants-lexware-mcp-server"><img src="https://mcptrustchecker.com/registry/lazyants-lexware-mcp-server/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/lazyants-lexware-mcp-server/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan @lazyants/lexware-mcp-server --online

Use the free API → How scoring works

More in Finance & Commerce