# Boundary & Risk Card

Project: templatefoxpdf/mcp-server

## Doramagic Trial Decision

Current decision: it can enter pre-publication recommendation checks. First use should still start with least privilege, a temporary directory, and reversible configuration.

## What The User Can Do Now

- Read the Human Manual first to understand the project purpose and main workflows.
- Use Prompt Preview for pre-install exploration; it validates interaction shape, not real execution.
- Run official Quick Start commands only inside an isolated environment, not a primary setup.

## Do Not Do Yet

- Do not treat Prompt Preview as a real project execution result.
- Do not treat metadata-only validation as sandbox installation validation.
- Do not describe unverified capabilities as supported, working, or safe to install.
- Do not provide production data, private files, real secrets, or primary host configuration on first trial.

## Pre-Install Checklist

- Host AI match: mcp_host
- Official installation entry status: official entry point found
- Isolated temporary directory, temporary host, or container validation: required
- Configuration rollback path: required
- API keys, network access, file access, or host configuration changes: treat as high risk until confirmed
- Installation command, actual output, and failure logs: must be recorded

## Current Blockers

- No blockers.

## Project-Specific Pitfalls

- 社区讨论暴露的待验证问题：darkzodchi en X: "Top MCP Servers That Turn Claude Into a Productivity Machine" / X (medium): 这类外部讨论可能代表真实用户在安装、配置、升级或生产使用时遇到阻力；发布前不能只依赖官方 README。 Suggested check: Pack Agent 需要打开来源链接，确认问题是否仍然存在，并把验证结论写入说明书和边界卡。
- 能力判断依赖假设 (medium): 假设不成立时，用户拿不到承诺的能力。 Suggested check: 将假设转成下游验证清单。
- 社区讨论暴露的待验证问题：Adding Github MCP to Claude Code Error : r/ClaudeAI - Reddit (medium): 这类外部讨论可能代表真实用户在安装、配置、升级或生产使用时遇到阻力；发布前不能只依赖官方 README。 Suggested check: Pack Agent 需要打开来源链接，确认问题是否仍然存在，并把验证结论写入说明书和边界卡。
- 社区讨论暴露的待验证问题：you need somewhere between 1-10 Claude skills depending on what ... (medium): 这类外部讨论可能代表真实用户在安装、配置、升级或生产使用时遇到阻力；发布前不能只依赖官方 README。 Suggested check: Pack Agent 需要打开来源链接，确认问题是否仍然存在，并把验证结论写入说明书和边界卡。
- 维护活跃度未知 (medium): 新项目、停更项目和活跃项目会被混在一起，推荐信任度下降。 Suggested check: 补 GitHub 最近 commit、release、issue/PR 响应信号。

## Risk And Permission Notes

- no_demo: medium

## Evidence Gaps

- No structured evidence gaps are currently visible.
