Atlas / MCP servers / agenticcontrolio / TwinCAT Validator

TwinCAT ValidatorCAUTION

mcp/agenticcontrolio/twincat-validator

An MCP server that validates, auto-fixes, and scaffolds TwinCAT 3 XML files. Connect it to any LLM client to give your AI assistant reliable, deterministic TwinCAT code quality tooling — structural checks, 21 IEC 61131-3 OOP checks, auto-fix pipelines, and canonical skeleton generation.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
16 11r · 5w · 0d
Transport
stdio
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io) [](https://github.com/psf/black)

An MCP server that validates, auto-fixes, and scaffolds TwinCAT 3 XML files (.TcPOU, .TcIO, .TcDUT, .TcGVL). Connect it to any LLM client to give your AI assistant reliable, deterministic TwinCAT code quality tooling — structural checks, 21 IEC 61131-3 OOP checks, auto-fix pipelines, and canonical skeleton generation.

Supported File Types

Installation

pip install twincat-validator-mcp

From Source

git clone https://github.com/agenticcontrolio/twincat-validator-mcp.git
cd twincat-validator-mcp
pip install -e .

Claude Desktop Extension

The easiest way to use this server with Claude Desktop is via the one-click .dxt extension:

  1. pip install twincat-validator-mcp
  2. Download the .dxt file from the latest release
  3. Open Claude Desktop → Settings → Extensions → Install Extension

See dxt/README.md for full instructions and troubleshooting.

Connecting to an LLM Client

For other clients (Cursor, VS Code, Windsurf, Cline), the server uses stdio transport. Add the following to your client's MCP config file:

Cursor — .cursor/mcp.json

{
"mcpServers": {
"tw
Read from source at commit edb6504c245aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add twincat-validator-mcp -- uvx twincat-validator-mcp
claude-desktop
{
  "mcpServers": {
    "twincat-validator-mcp": {
      "command": "uvx",
      "args": [
        "twincat-validator-mcp"
      ]
    }
  }
}
03

Exposed tools (16)

11 read · 5 write · 0 destructive.

ToolRiskDescription
autofix_batchreadAutomatically fix multiple TwinCAT files matching glob patterns.
autofix_filereadAutomatically fix common TwinCAT XML issues.
check_specificwriteRun specific validation checks on a TwinCAT file.
extract_methods_to_xmlreadPromote inline METHOD blocks from main ST to <Method> XML elements.
generate_skeletonreadGenerate canonical deterministic TwinCAT XML skeleton for a file type.
get_context_packreadGet curated knowledge base entries and OOP policy scoped by workflow stage.
get_effective_oop_policyreadGet effective OOP validation policy for a file or directory target.
get_validation_summaryreadGet high-level file quality summary with health score.
lint_oop_policyreadLint nearest .twincat-validator.json policy keys/types and return normalized policy.
process_twincat_batchwriteRun enforced deterministic batch TwinCAT workflow.
process_twincat_singlewriteRun enforced deterministic single-file TwinCAT workflow.
suggest_fixesreadGenerate prioritized fix recommendations from validation results.
validate_batchreadValidate multiple TwinCAT files matching glob patterns.
validate_filereadValidate a single TwinCAT file.
validate_for_importwriteQuick validation check for TwinCAT import readiness.
verify_determinism_batchwriteRun strict batch orchestration twice and report per-file idempotence stability.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (3)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
twincat_validator/fixers/__init__.py:13
importlib.import_module(f"{__name__}.{module_name}")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
twincat_validator/validators/__init__.py:13
importlib.import_module(f"{__name__}.{module_name}")
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
twincat_validator/_server_helpers.py:383
digest = hashlib.md5(seed.encode("utf-8")).hexdigest()

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha edb6504c245afull audit observations/trust-audit/mcp-server/agenticcontrolio__twincat-validator.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08edb6504c245aCAUTIONB89first audit
06

Questions

What is the TwinCAT Validator MCP server?

An MCP server that validates, auto-fixes, and scaffolds TwinCAT 3 XML files. Connect it to any LLM client to give your AI assistant reliable, deterministic TwinCAT code quality tooling — structural checks, 21 IEC 61131-3 OOP checks, auto-fix pipelines, and canonical skeleton generation.

What tools does TwinCAT Validator expose?

16 in total: 11 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is TwinCAT Validator safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does TwinCAT Validator need?

No credential environment variables were found in its source, so it appears to need none.

How does TwinCAT Validator run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as twincat-validator-mcp.

How current is this page?

The grade is for one exact copy of the source (edb6504c245a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement