Back to Browse

M Dev Tools MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server wrapping the m-dev-tools catalog: route_intent, describe, verify.

About

MCP server wrapping the m-dev-tools catalog: route_intent, describe, verify.

Security Report

4.8
Use Caution4.8High Risk

This is a well-structured MCP server with solid security practices. The codebase implements proper error handling, uses safe network access patterns (read-only HTTPS to GitHub), and includes comprehensive input validation. The server appropriately fetches catalog metadata from a remote source without caching to disk, maintains proper separation of concerns between pure logic and network I/O, and validates all untrusted input before processing. Minor code quality observations do not materially impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

file_system

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-m-dev-tools-m-dev-tools-mcp": {
      "args": [
        "m-dev-tools-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

m-dev-tools-mcp

MCP server for the m-dev-tools org catalog. Exposes three first-class agent tools:

  • route_intent(query) — plain-English intent → typed IDs (e.g. "parse JSON in M"module:m-stdlib#STDJSON)
  • describe(typed_id) — typed ID → pointer-blob (manifest URL, AGENTS.md URL, verification commands, …)
  • verify(repo) — list a repo's declared verification commands (does not execute them)

The server reads the catalog at https://github.com/m-dev-tools/.github over the network at call time; it is a thin wrapper, not a cache. See AGENTS.md for the contract and the AI users guide for the full walk-through.

mcp-name: io.github.m-dev-tools/m-dev-tools-mcp

Install

pip install m-dev-tools-mcp
# or:
uvx m-dev-tools-mcp
# or from a GitHub Release wheel:
pip install https://github.com/m-dev-tools/m-dev-tools-mcp/releases/download/v0.2.4/m_dev_tools_mcp-0.2.4-py3-none-any.whl

Point any MCP client at the m-dev-tools-mcp binary the install provides:

{
  "mcpServers": {
    "m-dev-tools": { "command": "m-dev-tools-mcp" }
  }
}

Or for clients that consult the public MCP registry:

io.github.m-dev-tools/m-dev-tools-mcp

Develop

make install        # creates .venv and installs editable + dev deps
make test           # pytest
make check          # lint + mypy + test + check-manifest + check-agents
make build          # → wheel-out/m_dev_tools_mcp-<ver>-py3-none-any.whl

More

  • Architecture: m-dev-tools/.github's docs/ai-discoverability/AI-discoverability-architecture.md
  • Plan + phases: docs/ai-discoverability/phases/
  • Release process: tag vX.Y.Z on main.github/workflows/release.yml builds the wheel, attaches it to a GitHub Release, publishes to PyPI via Trusted Publisher OIDC, and updates the MCP registry record via GitHub OIDC.

License

AGPL-3.0. Same license as every other m-dev-tools repo.

Reviews

No reviews yet

Be the first to review this server!