Atlas / MCP servers / bnomei / Kirby

KirbyBLOCK

mcp/bnomei/kirby

CLI-first MCP server for composer-based Kirby CMS projects — inspect blueprints/templates/plugins, interact with a real Kirby runtime, and use a bundled Kirby knowledge base.

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
75 62r · 12w · 1d
Transport
streamable-http
License
MIT
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://getkirby.com) [](https://discordapp.com/users/bnomei) [](https://www.buymeacoffee.com/bnomei)

CLI-first MCP server for Composer-based Kirby CMS projects. It lets an IDE or agent inspect your Kirby project (blueprints, templates, plugins, docs) and interact with a real Kirby runtime. It ships with a local knowledge base of Kirby concepts and tasks. For agent-specific install steps (Claude Code, Codex CLI) and Skill sync, see Client setup.

It can also run as a projectless global reference MCP (kirby-mcp --global) for always-on Kirby docs/KB research. Global reference mode is intentionally separate from project-local MCP servers and cannot inspect, render, update, or run commands in a Kirby project.

The server uses MCP SDK v0.8 dual-era dispatch: existing clients negotiate stateful sessions through initialize, while 2026-07-28 clients use stateless requests. MCP logging requests are not advertised—diagnostics are written to stderr instead. A valid W3C v00 traceparent supplied by a modern request, including the native HTTP header from browser clients, is included for correlation; tracestate and baggage are never logged.

[!WARNING] Prompt injection is a serious security threat, especially when used with documents retrieved from the interne
Read from source at commit 07ce290aa397OBSERVED · 2026-10-07
02

Exposed tools (75)

62 read · 12 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
blueprintreadRead a blueprint by id via the installed
cli_commandreadParsed help output for a single Kirby CLI command via
commandsreadKirby CLI command list for this project (parsed from
composerreadComposer audit (composer.json): detects test runner and quality tools (phpstan/larastan/psalm/mago/pint/phpcs/php-cs-fixer); returns “how to run” commands.
config_getreadRead a Kirby config option by dot notation (or JSON-encoded array of path segments) via the installed
extensionreadFetch Kirby extension reference markdown from getkirby.com (docs/reference/plugins/extensions/{slug}).
extensionsreadList Kirby plugin extensions (links to kirby://extension/{name}).
file_contentreadRead a file’s content/metadata by id or uuid. The id must be URL-encoded (e.g. about%2Fcover.jpg). UUIDs can be passed as the raw UUID or as a URL-encoded Kirby UUID like file%3A%2F%2F<uuid>.
glossaryreadList bundled Kirby glossary terms (links to kirby://glossary/{term}).
glossary_termreadRead a bundled Kirby glossary entry from kb/glossary/{term}.md.
hookreadFetch Kirby hook reference markdown from getkirby.com (docs/reference/plugins/hooks/{slug}). Accepts hook names like file.changeName:after or slugs like file-changename-after.
hooksreadList Kirby plugin hook names (links to kirby://hook/{name}).
inforeadProject runtime info (PHP + Kirby version via CLI), composer audit, and local environment detection (Herd/DDEV/Docker).
kbreadList bundled KB documents (links to kirby://kb/{path}). Paths are relative to kb/ and omit .md.
kb_documentreadRead a bundled KB document from kb/{path}.md (path relative to kb/, no .md).
kirby_blueprint_readreadRead a single Kirby blueprint by id (e.g. pages/home). Prefers runtime
kirby_blueprints_indexreadIndex Kirby blueprints keyed by id (e.g. pages/home). Default is a small summary (no full data, no raw CLI output) and includes derived displayName (title/name/label) plus source info (file vs extension override). Prefers runtime
kirby_blueprints_loadedreadList blueprint ids that Kirby knows about at runtime (extensions + filesystem). Defaults to idsOnly=true to avoid truncation; supports filters and pagination. Requires kirby_runtime_install first.
kirby_cache_cleardestructiveClear in-memory caches for the current MCP process (StaticCache, config cache, composer cache, roots cache, tool index). This does not delete any project files.
kirby_cli_versionwriteRun
kirby_collections_indexreadIndex Kirby named collections keyed by id (e.g. articles/latest). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime
kirby_composer_auditreadParse composer.json to detect Kirby version, scripts, test runner, and quality tools (phpstan/larastan/psalm/mago/pint/phpcs/php-cs-fixer). Returns “how to run” commands. Resource:
kirby_content_migration_assistantwritePlan/apply a safe content migration using kirby_read_page_content + kirby_update_page_content (explicit confirmation required).
kirby_controllers_indexreadIndex Kirby controllers keyed by id (e.g. album, album.json). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime
kirby_debug_render_tracereadDebug by reproducing via kirby_render_page and inspecting mcp_dump traces via kirby_dump_log_tail.
kirby_dump_log_tailreadTail
kirby_evalreadTinker/REPL (
kirby_generate_ide_helpersreadGenerate IDE helper files (optional/regeneratable) from project context (blueprints, indexes). Writes to
kirby_ide_helpers_statusreadReport IDE helper status (missing template/snippet PHPDoc @var hints + helper file freshness using mtimes). Designed to keep LLMs tool-first and avoid stale static helpers.
kirby_ide_support_boostreadImprove IDE support via status + minimal type-hint fixes + optional helper generation.
kirby_inforeadReturn project runtime info (PHP + Kirby version via Kirby CLI), composer audit, and local environment detection (Herd/DDEV/Docker). Resource:
kirby_initreadReturn Kirby MCP guidance + project-specific audit. Required before other tools in handshake sessions; optional for stateless modern calls.
kirby_models_indexreadIndex registered Kirby page models keyed by id (e.g. default, article) with class + file path info. Prefers runtime
kirby_onlinereadSearch official Kirby docs via
kirby_online_pluginsreadSearch the official Kirby plugin directory (plugins.getkirby.com) and optionally fetch individual plugin pages to extract key details and return a markdown summary. Online fallback; prefer kirby_plugins_index for installed plugins.
kirby_performance_auditreadGuide an agent through a Kirby performance audit (cache + query pitfalls). Use before making performance-related changes.
kirby_plugins_indexreadIndex loaded Kirby plugins keyed by id (runtime truth) via
kirby_project_tourreadMap the project (roots + inventory) and suggest next steps.
kirby_query_dotreadEvaluate Kirby query language (dot-notation) strings in Kirby runtime via the installed
kirby_read_file_contentreadRead a file’s content/metadata by id or uuid via the installed
kirby_read_page_contentreadRead a page’s content (current version; drafts/changes-aware) by id or uuid via the installed
kirby_read_site_contentreadRead the site’s content (current version) via the installed
kirby_read_user_contentreadRead a user’s content by id or email via the installed
kirby_render_pagereadRender a Kirby page by id or uuid via the installed
kirby_rootsreadReturn Kirby’s resolved folder roots (kirby()->roots) via
kirby_routes_indexreadList registered Kirby routes with pattern/method/name and best-effort source location for the action callback. Requires
kirby_run_cli_commandwriteRun a Kirby CLI command and return raw stdout/stderr + exit code. Commands are guarded by an allowlist (built-in + optional .kirby-mcp/mcp.json); set allowWrite=true for write-capable commands (e.g. make:*). Prefer dedicated MCP resources/tools for common tasks (e.g.
kirby_runtime_installwriteInstall project-local Kirby CLI commands used by Kirby MCP (e.g.
kirby_runtime_statusreadCheck whether project-local Kirby MCP runtime CLI command wrappers are installed (presence check against the package’s expected command files).
kirby_scaffold_page_typereadScaffold a new Kirby page type (blueprint + template, optional controller/page model) using project roots and conventions.
kirby_searchreadSearch the bundled local Kirby knowledge base markdown files (kb/) using fuzzy Levenshtein matching and optionally return full markdown for the top matches (fetch). Prefer this before kirby_online.
kirby_snippets_indexreadIndex Kirby snippets keyed by id (e.g. blocks/gallery). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime
kirby_templates_indexreadIndex Kirby templates keyed by id (e.g. home, notes.json). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime
kirby_tool_suggestreadSuggest the best next Kirby MCP tool/resource for a task using a weighted keyword matcher. Suggestions can include tools, resources (
kirby_update_file_contentwriteUpdate a file’s content/metadata by id or uuid via the installed
kirby_update_page_contentwriteUpdate a page’s content by id or uuid via the installed
kirby_update_site_contentwriteUpdate the site’s content via the installed
kirby_update_user_contentwriteUpdate a user’s content by id or email via the installed
kirby_upgrade_kirbyreadUpgrade Kirby safely (official docs + composer + verification).
page_contentreadRead a page’s content by id or uuid. The id must be URL-encoded (e.g. home or blog%2Fpost). UUIDs can be passed as the raw UUID (preferred) or as a URL-encoded Kirby UUID like page%3A%2F%2F<uuid>.
panel_fieldreadFetch Kirby Panel field reference markdown from getkirby.com (docs/reference/panel/fields/{type}).
panel_fieldsreadList Kirby Panel field types (links to kirby://field/{type}).
panel_sectionreadFetch Kirby Panel section reference markdown from getkirby.com (docs/reference/panel/sections/{type}).
panel_sectionsreadList Kirby Panel section types (links to kirby://section/{type}).
rootsreadKirby roots (kirby()->roots) discovered via Kirby CLI using the configured default host (KIRBY_MCP_HOST/KIRBY_HOST or .kirby-mcp/mcp.json) when present.
site_contentreadRead the site’s content (current version) via the runtime CLI command.
susiereadEaster egg: Susie (Kirby: Planet Robobot) boss attack loop. Provide phase (1-3) and step (1-based). Returns attack name or null.
tool-examplesreadCurated usage examples for Kirby MCP tools with stricter inputs or confirm flows.
toolsreadWeighted keyword index for Kirby MCP tools, resources, and resource templates (used by kirby_tool_suggest).
update_schema_blueprintwriteRead a bundled blueprint update schema from kb/update-schema/blueprint-{type}.md.
update_schema_blueprintswriteList bundled blueprint update schemas (links to kirby://blueprint/{type}/update-schema).
update_schema_fieldwriteRead a bundled content field update schema from kb/update-schema/{type}.md.
update_schema_fieldswriteList bundled content field update schemas (links to kirby://field/{type}/update-schema).
user_contentreadRead a user’s content by id or email. The id/email must be URL-encoded (e.g. jane%40example.com).
uuid_newreadGenerate a new random Kirby UUID string (respects content.uuid format).
03

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (7)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/Mcp/Commands/EvalPhp.php:138
return eval($code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/Mcp/Tools/RuntimeTools.php:1577
title: 'Eval (CLI)',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/Mcp/Tools/RuntimeTools.php:1580
title: 'Eval (CLI)',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
kirby_cache_clear
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:533
"allowedOrigins": ["http://127.0.0.1:3000"],
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
kb/glossary/role.md:5
In Kirby, a “role” defines what a user is allowed to do. Roles are defined by **user blueprints** in `site/blueprints/users/` (e.g. `editor.yml`). The `admin` role always exists and has full permissio

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 07ce290aa397full audit observations/trust-audit/mcp-server/bnomei__kirby.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0707ce290aa397BLOCKD66first audit
05

Questions

What is the Kirby MCP server?

CLI-first MCP server for composer-based Kirby CMS projects — inspect blueprints/templates/plugins, interact with a real Kirby runtime, and use a bundled Kirby knowledge base.

What tools does Kirby expose?

75 in total: 62 read-only, 12 that write, and 1 that can delete or overwrite (kirby_cache_clear). Every one is listed on this page with its risk.

Is Kirby safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Kirby need?

No credential environment variables were found in its source, so it appears to need none.

How does Kirby run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (07ce290aa397), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement