Skip to main content
Glama
Sealjay

mcp-signal

by Sealjay

mcp-signal

Python uv MCP License: MIT GitHub issues GitHub stars Sealjay/mcp-signal MCP server

Локальный сервер протокола контекста модели (MCP), который считывает историю Signal Desktop из локальной зашифрованной базы данных через signal-export и отправляет исходящие сообщения через signal-cli.

mcp-signal фокусируется на основном рабочем процессе для личной автоматизации Signal — список чатов, чтение сообщений, поиск по сообщениям, просмотр групп и отправка сообщений в личные или групповые чаты. Все работает локально; используется транспорт stdio без сетевого прослушивателя.

Внимание — смешанный бэкенд. Чтение/поиск осуществляется из локальной базы данных Signal Desktop. Для отправки используется signal-cli, который должен быть установлен и привязан к учетной записи Signal отдельно. Если signal-cli недоступен, чтение/поиск будут работать, но инструменты отправки — нет.

Функции

  • Список личных и групповых чатов из Signal Desktop

  • Чтение последних сообщений из чата

  • Поиск сообщений в одном чате или по всем чатам

  • Список групповых чатов с идентификаторами групп signal-cli для исходящих сообщений

  • Отправка сообщения:

    • прямому получателю по номеру телефона

    • в группу по идентификатору группы

    • в чат по точному названию чата (с проверкой неоднозначности)

  • Работает полностью на вашем компьютере; транспорт stdio без сетевого прослушивателя

Related MCP server: Signal MCP

Настройка

Предварительные требования

  • Python 3.13+

  • uv

  • Signal Desktop с существующей локальной базой данных сообщений

  • signal-cli, установленный и привязанный, если вы хотите отправлять сообщения

Установка

  1. Клонируйте этот репозиторий

    git clone https://github.com/Sealjay/mcp-signal.git
    cd mcp-signal
  2. Установите зависимости

    uv sync
  3. Установите signal-cli (необязательно — нужно только для исходящих сообщений)

    В macOS проще всего использовать Homebrew:

    brew install signal-cli

Настройка исходящих сообщений

Сервер автоматически загружает локальный файл .env.local из корня репозитория, если он существует. Этот файл игнорируется git и является рекомендуемым местом для локальной конфигурации машины.

cat > .env.local <<'EOF'
SIGNAL_ACCOUNT="+441234567890"
EOF

Необязательные переменные окружения:

Переменная

Назначение

SIGNAL_CLI_PATH

Переопределить путь к бинарному файлу signal-cli

SIGNAL_DATA_DIR

Переопределить директорию данных Signal Desktop

SIGNAL_DB_PASSWORD

Пароль для зашифрованных баз данных Desktop, если требуется

SIGNAL_DB_KEY

Ключ для зашифрованных баз данных Desktop, если требуется

Переменные окружения, установленные в оболочке, имеют приоритет над .env.local.

Привязка signal-cli (только при первом запуске)

mcp-signal не управляет привязкой самостоятельно. Сначала привяжите локальное устройство signal-cli:

signal-cli link -n "signal-mcp"

Отсканируйте QR-код в мобильном приложении Signal (Настройки → Связанные устройства → Связать новое устройство).

Не передавайте -a / --account в команду link в текущих версиях signal-cli — привязка нового вторичного устройства не требует номера телефона.

После того как QR-код будет принят, убедитесь, что связанная учетная запись видна:

signal-cli listAccounts

Эта учетная запись должна соответствовать значению SIGNAL_ACCOUNT в .env.local.

signal-cli хранит состояние связанной учетной записи в своей собственной локальной директории данных (обычно ~/.local/share/signal-cli/data в macOS/Linux). Это состояние находится вне этого репозитория и не коммитится в mcp-signal.

Проверьте, что все подключено:

uv run signal-mcp smoke

Конфигурация MCP-клиента

Все клиенты запускают сервер одинаково через stdio. В macOS вам может потребоваться абсолютный путь к uv — см. macOS: uv PATH ниже.

Claude Code

Самый быстрый путь — через CLI:

claude mcp add --transport stdio signal --scope user -- uv run --directory /absolute/path/to/mcp-signal signal-mcp serve

Альтернативно, добавьте в .mcp.json в корне вашего проекта (или ~/.claude.json для сервера на уровне пользователя):

{
  "mcpServers": {
    "signal": {
      "type": "stdio",
      "command": "uv",
      "args": ["run", "--directory", "/absolute/path/to/mcp-signal", "signal-mcp", "serve"]
    }
  }
}

Если вы редактируете файл напрямую, перезапустите сессию Claude Code, чтобы изменения вступили в силу.

Claude Desktop

Добавьте в ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):

{
  "mcpServers": {
    "signal": {
      "command": "uv",
      "args": ["run", "--directory", "/absolute/path/to/mcp-signal", "signal-mcp", "serve"]
    }
  }
}

Перезапустите Claude Desktop. Вы должны увидеть signal в списке доступных интеграций.

Cursor

Добавьте в ~/.cursor/mcp.json:

{
  "mcpServers": {
    "signal": {
      "command": "uv",
      "args": ["run", "--directory", "/absolute/path/to/mcp-signal", "signal-mcp", "serve"]
    }
  }
}

Перезапустите Cursor.

macOS: uv PATH

Графические приложения (Claude Desktop, Cursor) не всегда наследуют PATH из вашего интерактивного терминала, поэтому uv может выдать ошибку spawn uv ENOENT. Исправьте это, используя абсолютный путь к uv в command:

  • Homebrew — /opt/homebrew/bin/uv (Apple Silicon) или /usr/local/bin/uv (Intel)

  • Ручная установка — выполните which uv в терминале, чтобы найти путь

Пример:

{
  "mcpServers": {
    "signal": {
      "command": "/opt/homebrew/bin/uv",
      "args": ["run", "--directory", "/absolute/path/to/mcp-signal", "signal-mcp", "serve"]
    }
  }
}

Архитектура

Компонент

Описание

MCP-сервер

Python/FastMCP, транспорт stdio

Путь чтения

signal-export читает локальную базу данных Signal Desktop

Путь отправки

signal-cli JSON-RPC, запускается по требованию

Состояние

Нет отдельного кэша; чтение напрямую из данных Signal Desktop

Поток данных

  1. MCP-клиент запускает signal-mcp serve через stdio.

  2. Инструменты чтения/поиска вызывают signal-export для локальной базы данных Signal Desktop.

  3. Список групп и исходящие сообщения вызывают signal-cli -a ACCOUNT jsonRpc.

  4. Результаты возвращаются в виде структурированного JSON.

Структура проекта

mcp-signal/
  src/mcp_signal/
    config.py
    main.py
    reader.py
    server.py
    signal_cli.py
  tests/
  CLAUDE.md
  LICENSE
  README.md
  SECURITY.md

Инструменты

Инструмент

Назначение

list_chats

Список личных и групповых чатов из Signal Desktop

read_messages

Чтение сообщений из конкретного чата

search_messages

Поиск сообщений в одном чате или по всем чатам

list_groups

Список групп из signal-cli, включая идентификаторы групп

send_message

Отправка текстового сообщения прямому получателю или в группу

get_status

Показать состояние БД Desktop / signal-cli / учетной записи

Конфиденциальность и безопасность

  • Нет облачного ретранслятора. Нет сетевого прослушивателя. Все данные остаются на вашем компьютере.

  • Чтение/поиск использует только ваши локальные данные Signal Desktop.

  • Операции отправки требуют локально настроенной учетной записи signal-cli.

  • .env.local предназначен для локальных секретов, таких как SIGNAL_ACCOUNT, и не коммитится.

  • Состояние связанного устройства signal-cli хранится в его собственной локальной директории данных приложения, вне этого репозитория, и не коммитится.

См. SECURITY.md для получения информации о том, как сообщать об уязвимостях.

Ограничения

  • Риск инъекции промптов: как и многие MCP-серверы, этот подвержен смертельному трио. Вредоносные входящие сообщения могут попытаться дать агенту команду на эксфильтрацию других сообщений. Относитесь к поверхности инструментов соответствующим образом и проверяйте исходящие действия перед их одобрением.

  • Смешанный бэкенд: история чатов берется из Signal Desktop, а исходящие сообщения — из signal-cli.

  • Нет вложений: отправка только текста.

  • Нет уведомлений в реальном времени: только опрос/чтение.

  • Одна учетная запись на экземпляр MCP.

  • Для отправки в группы нужен signal-cli: одного чтения локальной БД недостаточно для безопасной отправки в группы.

Разработка

uv sync
uv run signal-mcp smoke
uv run pytest
uv run ruff check .

Устранение неполадок

  • signal-cli не найден — убедитесь, что signal-cli находится в PATH, или установите SIGNAL_CLI_PATH в .env.local. В macOS проще всего использовать brew install signal-cli.

  • Чтение/поиск работают, но отправка не удается — signal-cli не привязан или не установлен SIGNAL_ACCOUNT. Выполните signal-cli listAccounts для проверки, затем проверьте .env.local.

  • signal-cli link зависает или выдает ошибку — не передавайте -a / --account в link в текущих версиях. Выполните signal-cli link -n "signal-mcp" и отсканируйте QR-код с телефона.

  • MCP-клиент не может запустить сервер — args должны содержать абсолютный путь к репозиторию, а не относительный. Если сам uv выдает ошибку spawn uv ENOENT, см. macOS: uv PATH.

  • Сообщения не возвращаются — убедитесь, что Signal Desktop установлен и имеет историю сообщений. Путь чтения запрашивает локальную базу данных Signal Desktop напрямую.

Участие в разработке

Приветствуются вклады через pull request. Пожалуйста:

  • Выполните uv run ruff check . перед отправкой.

  • Убедитесь, что uv run pytest проходит успешно.

См. CLAUDE.md для полного рабочего процесса разработки.

Лицензия

Лицензия MIT — см. LICENSE.

Available Tools

8 tools
chat_activityA

List Signal chats ranked by recent activity, showing last message date, last reply date, and count of unanswered inbound messages.

Read-only with no side effects. Use this to identify chats that need a response. Use list_chats instead for a general chat directory with message previews.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMaximum number of chats to return, between 1 and 200.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Explicitly declares 'Read-only with no side effects.' Since no annotations are provided, the description adequately covers behavioral transparency. However, it lacks details on sorting or time window for 'recent activity,' which would be beneficial.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, each serving a purpose: first conveys functionality, second declares safety, third provides usage guidance. No wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With one parameter and an output schema, the description covers purpose, behavior, and usage guidance comprehensively. No gaps remain for this complexity level.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Only one parameter (limit) with 100% schema description coverage. The tool description adds no extra meaning beyond the schema's explanation of the limit range and default. Baseline score 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states the tool lists Signal chats ranked by recent activity with specific fields (last message date, last reply date, count of unanswered inbound messages). Differentiates from sibling list_chats by specifying its unique output.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to use this tool ('identify chats that need a response') and when to use the alternative ('Use list_chats instead for a general chat directory with message previews').

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

decrypt_attachmentA

Decrypt a locally stored Signal attachment and return the path to the decrypted file.

The encrypted_path and local_key values come from attachment metadata in read_messages or search_messages results. Read-only on Signal data; writes a decrypted copy to a temporary directory. Use this after reading messages that contain attachments.

ParametersJSON Schema
NameRequiredDescriptionDefault
encrypted_pathYesAbsolute filesystem path to the encrypted attachment file, as returned in the 'encrypted_path' field of message attachment metadata.
local_keyYesBase64-encoded 64-byte key (32-byte AES-CBC + 32-byte HMAC-SHA256), from the 'local_key' field of attachment metadata.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided, so description bears full burden. Discloses that it is read-only on Signal data and writes a decrypted copy to a temporary directory. Adds important safety and side-effect information beyond basic decryption.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences covering purpose, parameter source, and usage context. No redundancy, well-structured, and front-loaded with the core action.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's moderate complexity (2 parameters, output schema exists), the description covers purpose, parameter sourcing, safety behavior, and usage timing. No obvious gaps for an agent to correctly select and invoke the tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with detailed descriptions. Description adds context on the origin and nature of the parameters (from attachment metadata, base64-encoded key structure), which aids correct invocation beyond schema alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states verb ('Decrypt'), resource ('locally stored Signal attachment'), and outcome ('return the path to the decrypted file'). Distinct from siblings which involve chat activity, status, lists, and messages.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states where the input parameters come from ('encrypted_path and local_key values come from attachment metadata in read_messages or search_messages') and advises using it after reading messages with attachments. No explicit exclusions, but context is clear.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_statusA

Check whether the Signal MCP server can read local messages and send outbound messages.

Returns boolean fields: source_dir_exists, signal_cli_available, signal_account_configured, read_available, send_available. Read-only with no side effects. Call this before read or send operations to verify the server is correctly configured.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription

No output parameters

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations, but description states 'Read-only with no side effects' and lists return fields, fully disclosing behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, front-loaded with purpose, no wasted words. Efficient and clear.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Tool is simple with no parameters. Description covers purpose, return fields, and usage context. Output schema exists for further detail, making this complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

No parameters; schema coverage 100%. Description adds value by explaining return fields, which is sufficient for a zero-parameter tool.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states the tool checks server ability to read and send messages, with specific verb and resource. Distinct from sibling tools like read_messages or send_message.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly recommends calling before read or send operations, providing clear context. No need for alternatives as this is a single-purpose health check.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_chatsA

List direct and group Signal chats from the local desktop database, sorted by most recent message.

Each result includes name, phone number, message count, and a preview of the last message. Read-only with no side effects. Use this to discover exact chat names before calling read_messages or search_messages. Use list_groups instead when you need group_id values for send_message.

ParametersJSON Schema
NameRequiredDescriptionDefault
queryNoCase-insensitive substring to filter by chat name or phone number. Empty string returns all chats.
limitNoMaximum number of chats to return, between 1 and 200.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Declares read-only with no side effects, and mentions data source and sorting. Without annotations, this provides sufficient behavioral context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three efficient sentences: purpose, output details, and usage guidelines. No unnecessary words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given 2 simple parameters with full schema, no annotations, and an output schema present, the description fully covers what the agent needs: purpose, output format, and when to use.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with detailed parameter descriptions. The description adds no extra meaning beyond the schema, so baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states it lists direct and group Signal chats from local desktop database, sorted by most recent message. Differentiates from list_groups by specifying when to use each.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly advises to use this tool to discover chat names before calling read_messages or search_messages, and to use list_groups for group_id values needed for send_message.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_groupsA

List Signal groups with group_id, name, description, members, and admin lists, sorted alphabetically.

Read-only with no side effects. Queries signal-cli when available; falls back to the local desktop database (without group_id). Use this to obtain group_id values needed by send_message. Use list_chats instead for a combined view of both direct and group chats.

ParametersJSON Schema
NameRequiredDescriptionDefault
queryNoCase-insensitive substring to filter group names. Empty string returns all groups.
limitNoMaximum number of groups to return, between 1 and 200.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.7/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries full burden. It declares 'Read-only with no side effects' and explains the fallback from signal-cli to local desktop database (noting that group_id is missing in fallback). This is good but could be improved by mentioning any rate limits or error conditions.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, each serving a distinct purpose: purpose and output fields, safety and fallback, usage guidance and sibling differentiation. No wasted words, and critical information is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers all essential aspects: purpose, output fields, sorting, read-only safety, fallback behavior, when to use, and alternative tools. With an output schema available, return values are handled by schema. No gaps identified.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Input schema has 100% description coverage and describes both parameters well. The description adds value by stating the output is sorted alphabetically, which is not in the schema. Baseline is 3; the sorting detail justifies a 4.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states the verb ('List'), resource ('Signal groups'), and the specific fields returned (group_id, name, description, members, admin lists). Also distinguishes from sibling 'list_chats' by noting that list_chats provides a combined view of direct and group chats.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to use this tool: 'to obtain group_id values needed by send_message'. Also provides an alternative for a different use case: 'Use list_chats instead for a combined view'. Additionally, describes fallback behavior, giving clear context on data availability.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

read_messagesA

Read messages from a single Signal chat, returned newest-first.

Each message includes sender, date, body text, reactions, and attachment metadata. Read-only with no side effects. Requires an exact chat name from list_chats. Use search_messages instead to find messages by keyword across chats.

ParametersJSON Schema
NameRequiredDescriptionDefault
chat_nameYesExact chat name as returned by list_chats (case-sensitive).
limitNoMaximum number of messages to return, between 1 and 200.
offsetNoNumber of messages to skip from the most recent, for pagination (0-10000).
afterNoISO 8601 datetime; only return messages sent after this time, e.g. '2025-01-15T00:00:00'.
beforeNoISO 8601 datetime; only return messages sent before this time, e.g. '2025-02-01T00:00:00'.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

States 'Read-only with no side effects', and describes what each message includes. No annotations provided, so description carries full burden; it adequately discloses read-only nature and output detail.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Four concise sentences with no wasted words. Front-loads purpose and immediately gives key details.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given 5 parameters with full schema coverage and output schema present, the description covers purpose, output format, prerequisite, and alternative tool sufficiently without needing to repeat schema details.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline is 3. The description adds minimal extra meaning beyond the schema (e.g., chat_name must be exact from list_chats), but does not significantly enhance parameter understanding.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states 'Read messages from a single Signal chat' with verb and resource, and distinguishes from sibling 'search_messages' which finds messages by keyword across chats.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides prerequisite ('Requires an exact chat name from list_chats') and an alternative ('Use search_messages instead'), but does not explicitly exclude other inappropriate use cases.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

search_messagesA

Search Signal message bodies for a keyword, within one chat or across all chats, returned newest-first.

Read-only with no side effects. Use this to find messages by content. Use read_messages instead to browse a specific chat chronologically.

ParametersJSON Schema
NameRequiredDescriptionDefault
queryYesCase-insensitive substring to search for within message bodies.
chat_nameNoExact chat name to restrict the search to a single chat. Omit to search across all chats.
limitNoMaximum number of matching messages to return, between 1 and 200.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.7/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Declares 'Read-only with no side effects', which covers safety. No annotations exist, so description carries full burden. Could mention search scope (message bodies only) but is adequate.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences only, no wasted words. Front-loaded with purpose and scope.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given output schema exists, description is comprehensive: covers usage scope, safety, sorting, and links to alternative. Only minor omission is pagination details, but acceptable.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3. Description adds value by explaining scope ('within one chat or across all chats') and sort order ('newest-first'), enhancing what schema provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states the tool searches message bodies by keyword, within one chat or all, and returns newest-first. Distinguishes from sibling read_messages by specifying its use for content search versus chronological browsing.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly tells when to use ('to find messages by content') and when not to ('use read_messages instead to browse a specific chat chronologically'), with a direct sibling alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

send_messageA

Send a text message via Signal to a direct recipient or group.

This is a write operation that delivers a real message through signal-cli. Exactly one of phone_number, group_id, or chat_name must be supplied; providing zero or more than one raises an error. Rate-limited to 1 message per recipient per second and 10 messages per 60-second window globally. Requires signal-cli and SIGNAL_ACCOUNT to be configured — call get_status first to verify send_available is true. Returns target_type, target identifier, and timestamp on success.

ParametersJSON Schema
NameRequiredDescriptionDefault
messageYesThe text message content to send.
phone_numberNoRecipient phone number in E.164 format (e.g. '+441234567890'). Mutually exclusive with group_id and chat_name.
group_idNoTarget group ID as returned by list_groups. Mutually exclusive with phone_number and chat_name.
chat_nameNoExact chat name from list_chats; auto-resolves to the matching phone_number or group_id. Mutually exclusive with the other two recipient fields.

Output Schema

ParametersJSON Schema
NameRequiredDescription

No output parameters

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description fully disclosures behavioral traits: it is a write operation, rate-limited (1/s per recipient, 10/60s globally), requires signal-cli and SIGNAL_ACCOUNT, and hints at the return structure. This covers all necessary behavioral context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise, with the main purpose front-loaded, followed by essential rules and constraints in a logical order. Every sentence adds value, and there is no redundant or extraneous content.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (4 params, 1 required, mutual exclusivity, rate limits, prerequisites, and output schema), the description covers all necessary aspects: how to specify recipient, error conditions, rate limits, preconditions, and return format. It is fully sufficient for correct agent usage.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, and each parameter has a clear description in the schema (including mutual exclusivity). The tool description restates the exclusivity rule but adds no new semantic details about the parameters themselves beyond what the schema already provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description begins with 'Send a text message via Signal to a direct recipient or group,' which clearly identifies the action and resource. It further distinguishes itself from sibling tools (e.g., read_messages, get_status) by stating it is a write operation that delivers a real message.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit when-to-use guidance: exactly one recipient field must be supplied, and it warns against providing zero or multiple. It also specifies prerequisites (call get_status first) and rate limits, giving clear boundaries for safe invocation.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 16 tool updatesv0.1.3
    • Addedchat_activity
    • Addeddecrypt_attachment
    • Changedlist_chats2 fields changed
      • addedInput schema / properties / limit / description
        Added value: +"Maximum number of chats to return, between 1 and 200."
      • addedInput schema / properties / query / description
        Added value: +"Case-insensitive substring to filter by chat name or phone number. Empty string returns all chats."
    • Changedlist_groups2 fields changed
      • addedInput schema / properties / limit / description
        Added value: +"Maximum number of groups to return, between 1 and 200."
      • addedInput schema / properties / query / description
        Added value: +"Case-insensitive substring to filter group names. Empty string returns all groups."
    • Changedread_messages5 fields changed
      • addedInput schema / properties / after / description
        Added value: +"ISO 8601 datetime; only return messages sent after this time, e.g. '2025-01-15T00:00:00'."
      • addedInput schema / properties / before / description
        Added value: +"ISO 8601 datetime; only return messages sent before this time, e.g. '2025-02-01T00:00:00'."
      • addedInput schema / properties / chat_name / description
        Added value: +"Exact chat name as returned by list_chats (case-sensitive)."
      • addedInput schema / properties / limit / description
        Added value: +"Maximum number of messages to return, between 1 and 200."
      • addedInput schema / properties / offset / description
        Added value: +"Number of messages to skip from the most recent, for pagination (0-10000)."
    • Changedsearch_messages3 fields changed
      • addedInput schema / properties / chat_name / description
        Added value: +"Exact chat name to restrict the search to a single chat. Omit to search across all chats."
      • addedInput schema / properties / limit / description
        Added value: +"Maximum number of matching messages to return, between 1 and 200."
      • addedInput schema / properties / query / description
        Added value: +"Case-insensitive substring to search for within message bodies."
    • Changedsend_message4 fields changed
      • addedInput schema / properties / chat_name / description
        Added value: +"Exact chat name from list_chats; auto-resolves to the matching phone_number or group_id. Mutually exclusive with the other two recipient fields."
      • addedInput schema / properties / group_id / description
        Added value: +"Target group ID as returned by list_groups. Mutually exclusive with phone_number and chat_name."
      • addedInput schema / properties / message / description
        Added value: +"The text message content to send."
      • addedInput schema / properties / phone_number / description
        Added value: +"Recipient phone number in E.164 format (e.g. '+441234567890'). Mutually exclusive with group_id and chat_name."
    • Removedsignal_chat_activity
    • Removedsignal_get_chat_messages
    • Removedsignal_get_status
    • Removedsignal_list_chats
    • Removedsignal_list_groups
    • Removedsignal_read_messages
    • Removedsignal_search_chat
    • Removedsignal_search_messages
    • Removedsignal_send_message
  2. 15 tool updatesv0.1.2
    • First observedget_status
    • First observedlist_chats
    • First observedlist_groups
    • First observedread_messages
    • First observedsearch_messages
    • First observedsend_message
    • First observedsignal_chat_activity
    • First observedsignal_get_chat_messages
    • First observedsignal_get_status
    • First observedsignal_list_chats
    • First observedsignal_list_groups
    • First observedsignal_read_messages
    • First observedsignal_search_chat
    • First observedsignal_search_messages
    • First observedsignal_send_message

TDQS

A4.6/5.0

Scored across 8 tools

Disambiguation5/5

Each tool has a distinct purpose: chat_activity for unanswered messages, list_chats for directory, list_groups for group IDs, read_messages for browsing, search_messages for keyword search, send_message for sending, decrypt_attachment for attachments, get_status for configuration. No overlaps or ambiguity.

Naming Consistency4/5

Most tools follow verb_noun pattern (e.g., decrypt_attachment, list_chats), but chat_activity uses noun_noun. Overall consistent and clear, minor deviation.

Tool Count5/5

8 tools is well-scoped for a Signal messaging server: listing, reading, searching, sending, decrypting, and status checking. Not too few or too many.

Completeness5/5

Covers key operations: list chats/groups, read/search messages, send messages, decrypt attachments, check status. Missing features like message deletion or editing are likely out of scope for a read-only/send server.

Maintenance

ActivityStale
ResponsivenessSlow

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    C
    maintenance
    MCP server for Signal via signal-cli that enables sending and receiving messages, managing contacts and groups, and reacting over stdio.
    2 npm
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    MCP server for a local-first messaging workspace that integrates Google Messages, WhatsApp, and Signal. It enables reading, sending, searching messages, and managing conversations through MCP tools.
    55
    -