Atlas / MCP servers / bigcodegen / Neovim

NeovimSAFE

mcp/bigcodegen/neovim

Control Neovim using Model Context Protocol (MCP) and the official neovim/node-client JavaScript library

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
19 11r · 8w · 0d
Transport
stdio
License
MIT
Stars
322
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Connect Claude Desktop (or any Model Context Protocol client) to Neovim using MCP and the official neovim/node-client JavaScript library. This server leverages Vim's native text editing commands and workflows, which Claude already understands, to create a lightweight code or general purpose AI text assistance layer.

Features

  • Connects to your nvim instance if you expose a socket file, for example --listen /tmp/nvim, when starting nvim
  • Views your current buffers and manages buffer switching
  • Gets cursor location, mode, file name, marks, registers, and visual selections
  • Runs vim commands and optionally shell commands through vim
  • Can make edits using insert, replace, or replaceAll modes
  • Search and replace functionality with regex support
  • Project-wide grep search with quickfix integration
  • Comprehensive window management
  • Health monitoring and connection diagnostics

API

Resources

  • nvim://session: Current neovim text editor session
  • nvim://buffers: List of all open buffers in the current Neovim session with metadata including modified status, syntax, and window IDs

Tools

Core Tools

  • vim_buffer
  • Get buffer contents with line numbers (supports filename parameter)
  • Input filename (string, optional) - Get specific buffer by filename
  • Returns numbered lines with buffer content
  • vim_command
  • Send a command to VIM for navigation, spot editing, and line deletion
  • Input command (string)
  • Runs vim commands with nvim.replaceTermcodes. Multiple commands work with newlines
  • Shell commands supported with ! prefix when ALLOW_SHELL_COMMANDS=true
  • On error, 'nvim:errmsg' contents are returned
  • vim_status
  • Get comprehensive Neovim status
  • Returns cursor position, mode, filename, visual select
Read from source at commit 3946de390d13OBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-neovim-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-neovim-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (19)

11 read · 8 write · 0 destructive.

ToolRiskDescription
vim_bufferreadGet buffer contents with line numbers
vim_buffer_savewriteSave current buffer or save to specific filename
vim_buffer_switchreadSwitch between buffers by name or number
vim_commandwriteExecute Vim commands with optional shell command support
vim_editwriteEdit buffer content using insert, replace, or replaceAll modes
vim_file_openreadOpen files into new buffers
vim_foldwriteManage code folding: create, open, close, and toggle folds
vim_grepreadProject-wide search using vimgrep with quickfix list
vim_healthreadCheck Neovim connection health
vim_jumpreadNavigate Neovim jump list: go back, forward, or list jumps
vim_macrowriteRecord, stop, and play Neovim macros
vim_markwriteSet named marks at specific positions in the buffer
vim_registerreadManage Neovim register contents
vim_searchreadSearch within current buffer with regex support and options
vim_search_replacereadFind and replace with global, case-insensitive, and confirm options
vim_statusreadGet comprehensive Neovim status including cursor position, mode, marks, and registers
vim_tabwriteManage Neovim tabs: create, close, and navigate between tabs
vim_visualwriteCreate visual mode selections in the buffer
vim_windowreadManage Neovim windows: split, close, and navigate between windows
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, neovim, ts-node, zod, @types/node, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha 3946de390d13full audit observations/trust-audit/mcp-server/bigcodegen__neovim.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-033946de390d13SAFEB89first audit
06

Questions

What is the Neovim MCP server?

Control Neovim using Model Context Protocol (MCP) and the official neovim/node-client JavaScript library

What tools does Neovim expose?

19 in total: 11 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Neovim safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Neovim need?

No credential environment variables were found in its source, so it appears to need none.

How does Neovim run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-neovim-server at 0.5.5.

How current is this page?

The grade is for one exact copy of the source (3946de390d13), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement