Back to Browse

Yocoolab MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Pin visual feedback on any live web page and send it to Claude Code, Cursor or your AI agent.

About

Pin visual feedback on any live web page and send it to Claude Code, Cursor or your AI agent.

Security Report

4.2
Use Caution4.2High Risk

The Yocoolab MCP server is a well-structured tool for design feedback management with reasonable security practices. Authentication via environment variables is properly implemented, and sensitive tokens are not hardcoded. However, there are notable concerns: the GitHub token is obtained via subprocess execution without sufficient validation, companion message data persists in memory without explicit clearing guarantees, and several tools lack input validation. Permissions align with the server's purpose (API calls, file I/O, network access), but the subprocess execution pattern for GitHub CLI token retrieval introduces moderate risk. Supply chain analysis found 8 known vulnerabilities in dependencies (1 critical, 4 high severity). Package verification found 1 issue.

4 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

process_spawn

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Your Yocoolab JWT, from the Chrome extension settings or app.yocoolab.com. When unset, thread feedback tools are disabled but bridge, companion and activity tools still work.Required

Environment variable: YOCOOLAB_TOKEN

Yocoolab API base URL. Defaults to https://app.yocoolab.com.Optional

Environment variable: YOCOOLAB_API_URL

GitHub PAT with repo scope, needed only for the PR-creation tools. Auto-detected from the gh CLI when authenticated.Required

Environment variable: GITHUB_TOKEN

Absolute path to your project workspace, used to resolve file references in selections. Defaults to the current working directory.Optional

Environment variable: YOCOOLAB_BRIDGE_WORKSPACE

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-jonahbkerr-yocoolab": {
      "env": {
        "GITHUB_TOKEN": "your-github-token-here",
        "YOCOOLAB_TOKEN": "your-yocoolab-token-here",
        "YOCOOLAB_API_URL": "your-yocoolab-api-url-here",
        "YOCOOLAB_BRIDGE_WORKSPACE": "your-yocoolab-bridge-workspace-here"
      },
      "args": [
        "-y",
        "@yocoolab/mcp-server"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@yocoolab/mcp-server

npm version npm downloads CI License Node Types OpenSSF Best Practices

MCP (Model Context Protocol) server that exposes Yocoolab feedback threads, design selections, and activity events as tools for Claude Code and other MCP-compatible clients.

With this installed, your AI coding assistant can:

  • List and triage open design feedback threads on your repo
  • Pull rich context for a thread (selection, screenshot, conversation, files touched)
  • Reply to designers and mark threads as addressed
  • Open PRs that close out feedback threads
  • Inspect element context and selection history from the Yocoolab Chrome extension
  • Read activity summaries, AI conversations, and Pendo product analytics

Install

One command:

npx -y @yocoolab/mcp-server@2 setup

The setup wizard auto-detects your installed AI agents (Claude Code, Cursor, Cline, Roo Code, Windsurf) and writes the correct MCP config for each. Restart your agent and the yocoolab server appears with all tools available.

init is kept as an alias for setup for backwards compatibility with v1.0.x install instructions.

If you'd rather configure manually, the equivalent ~/.mcp.json looks like:

{
  "mcpServers": {
    "yocoolab": {
      "command": "npx",
      "args": ["-y", "@yocoolab/mcp-server@2"],
      "env": {
        "YOCOOLAB_API_URL": "https://app.yocoolab.com",
        "YOCOOLAB_TOKEN": "<your-yocoolab-jwt>",
        "GITHUB_TOKEN": "<your-github-pat>",
        "YOCOOLAB_BRIDGE_PORT": "9800",
        "YOCOOLAB_BRIDGE_WORKSPACE": "/absolute/path/to/your/workspace"
      }
    }
  }
}

The @2 version pin keeps you on the v2 major line — you'll receive bug fixes and new features automatically, but a future v3 with breaking changes won't break your setup. (Pin to @1 if you need Node 18 support — v1.x will receive security patches for 90 days after v2.0.)

Requirements

  • Node.js 20 or newer. We test on Node 20 and 22 in CI. We support whichever Node.js versions are currently in Active LTS or Maintenance LTS status, and drop versions within 30 days of their EOL. Node 18 was dropped in v2.0.0 (EOL April 2025).
  • A Yocoolab account and JWT token — get yours from the Yocoolab Chrome extension settings, or via your account at app.yocoolab.com.
  • A GitHub personal access token with repo scope, if you want to use the PR-creation tools (create_pr_for_thread). The token is auto-detected if you have the GitHub CLI installed and authenticated (gh auth login). No GITHUB_TOKEN env var needed in that case. Otherwise, create one at github.com/settings/tokens/new?scopes=repo.

Configuration

Env varRequiredDefaultDescription
YOCOOLAB_TOKENnoYour Yocoolab JWT (from the Chrome extension). When unset, thread feedback tools are disabled but bridge / companion / activity tools still work.
YOCOOLAB_API_URLnohttps://app.yocoolab.comYocoolab API base URL
GITHUB_TOKENonly for PR toolsGitHub PAT with repo scope. Auto-detected — if gh CLI is installed and authenticated (gh auth token), no env var is needed. Placeholder values like <your GitHub PAT> are detected and safely ignored.
YOCOOLAB_BRIDGE_PORTno9800Local port for the HTTP bridge to the Chrome extension
YOCOOLAB_BRIDGE_WORKSPACEnoprocess.cwd()Absolute path to your project workspace, used to resolve file references in selections
YOCOOLAB_AGENT_NAMEnoClaude CodeDisplay name shown in the Chrome extension's agent picker
YOCOOLAB_AGENT_TYPEnoclaude-codeAgent type identifier (claude-code, roo, cline, cursor, windsurf, or custom)

CLI

yocoolab-mcp           Run the MCP server (used by your agent via .mcp.json)
yocoolab-mcp setup     Interactive setup — auto-detects agents and writes their configs
yocoolab-mcp init      Alias for `setup` (backwards compatible with v1.0.x)
yocoolab-mcp --help    Show this help

The mcp-server command is a synonym for yocoolab-mcp. Either works.

Tools

The server exposes tools across several categories:

  • Threadslist_open_threads, get_thread_context, add_thread_message, mark_thread_addressed, create_pr_for_thread
  • Selection / Bridgeget_latest_selection, get_selection_history, get_element_context, find_source_for_selection, ai_analyze_page
  • Activityget_recent_events, get_activity_summary, get_files_touched, get_companion_messages, reply_to_companion
  • AIget_ai_conversations
  • Deploymentget_deployment_preview
  • Pendo (optional)pendo_list_guides, pendo_page_analytics, pendo_feature_usage, pendo_track_event

For full tool descriptions and parameters, your MCP client will list them after the server starts.

Troubleshooting

yocoolab-mcp: command not found — make sure you're on v1.0.1 or newer. Run npx -y @yocoolab/mcp-server@latest setup to get the current release.

[yocoolab] Warning: YOCOOLAB_TOKEN not set — thread feedback tools are disabled without a token, but bridge / companion / activity tools still work. To enable everything, run yocoolab-mcp setup to (re)generate the config with your JWT.

Tools don't appear in your agent after install — restart your agent completely (quit & reopen). MCP servers load at startup.

Port 9800 is already in use — another instance of the MCP server is running, or another app has the port. Set YOCOOLAB_BRIDGE_PORT to a different value (e.g. 9801) in your .mcp.json.

Verbose diagnostic logs — set DEBUG=yocoolab:* in your env block. All diagnostic output goes to stderr (so it doesn't interfere with the MCP stdio protocol on stdout).

PR creation says "GitHub token not configured" — the create_pr_for_thread tool needs a GitHub token. Two ways to fix:

  1. Auto-detect (easiest): install the GitHub CLI and run gh auth login. The server picks up the token automatically.
  2. Manual: create a personal access token with repo scope and add GITHUB_TOKEN: "ghp_..." to your MCP config's env block. If your config has a placeholder value like <your GitHub PAT>, the server detects it and shows a helpful message instead of crashing with a 401.

Support

Development

git clone https://github.com/Yocoolab/mcp-server.git
cd mcp-server
npm install
npm run build       # compile TypeScript to dist/
npm test            # run the vitest suite
npm run dev         # tsc --watch

See CONTRIBUTING.md for the full contributor workflow.

Security & supply chain

  • Released with npm provenance — every published version is cryptographically signed by GitHub Actions OIDC, traceable back to the exact commit and workflow run.
  • Each release ships with a CycloneDX SBOM attached to the GitHub Release.
  • We run npm audit signatures and CodeQL static analysis in CI on every PR.
  • See SECURITY.md for vulnerability reporting.

License

Apache 2.0 — © 2026 Yocoolab

Reviews

No reviews yet

Be the first to review this server!