KirbyBLOCK
CLI-first MCP server for composer-based Kirby CMS projects — inspect blueprints/templates/plugins, interact with a real Kirby runtime, and use a bundled Kirby knowledge base.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://getkirby.com) [](https://discordapp.com/users/bnomei) [](https://www.buymeacoffee.com/bnomei)
CLI-first MCP server for Composer-based Kirby CMS projects. It lets an IDE or agent inspect your Kirby project (blueprints, templates, plugins, docs) and interact with a real Kirby runtime. It ships with a local knowledge base of Kirby concepts and tasks. For agent-specific install steps (Claude Code, Codex CLI) and Skill sync, see Client setup.
It can also run as a projectless global reference MCP (kirby-mcp --global) for always-on Kirby docs/KB research. Global reference mode is intentionally separate from project-local MCP servers and cannot inspect, render, update, or run commands in a Kirby project.
The server uses MCP SDK v0.8 dual-era dispatch: existing clients negotiate stateful sessions through initialize, while 2026-07-28 clients use stateless requests. MCP logging requests are not advertised—diagnostics are written to stderr instead. A valid W3C v00 traceparent supplied by a modern request, including the native HTTP header from browser clients, is included for correlation; tracestate and baggage are never logged.
[!WARNING] Prompt injection is a serious security threat, especially when used with documents retrieved from the interne
07ce290aa397OBSERVED · 2026-10-07Exposed tools (75)
62 read · 12 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
blueprint | read | Read a blueprint by id via the installed |
cli_command | read | Parsed help output for a single Kirby CLI command via |
commands | read | Kirby CLI command list for this project (parsed from |
composer | read | Composer audit (composer.json): detects test runner and quality tools (phpstan/larastan/psalm/mago/pint/phpcs/php-cs-fixer); returns “how to run” commands. |
config_get | read | Read a Kirby config option by dot notation (or JSON-encoded array of path segments) via the installed |
extension | read | Fetch Kirby extension reference markdown from getkirby.com (docs/reference/plugins/extensions/{slug}). |
extensions | read | List Kirby plugin extensions (links to kirby://extension/{name}). |
file_content | read | Read a file’s content/metadata by id or uuid. The id must be URL-encoded (e.g. about%2Fcover.jpg). UUIDs can be passed as the raw UUID or as a URL-encoded Kirby UUID like file%3A%2F%2F<uuid>. |
glossary | read | List bundled Kirby glossary terms (links to kirby://glossary/{term}). |
glossary_term | read | Read a bundled Kirby glossary entry from kb/glossary/{term}.md. |
hook | read | Fetch Kirby hook reference markdown from getkirby.com (docs/reference/plugins/hooks/{slug}). Accepts hook names like file.changeName:after or slugs like file-changename-after. |
hooks | read | List Kirby plugin hook names (links to kirby://hook/{name}). |
info | read | Project runtime info (PHP + Kirby version via CLI), composer audit, and local environment detection (Herd/DDEV/Docker). |
kb | read | List bundled KB documents (links to kirby://kb/{path}). Paths are relative to kb/ and omit .md. |
kb_document | read | Read a bundled KB document from kb/{path}.md (path relative to kb/, no .md). |
kirby_blueprint_read | read | Read a single Kirby blueprint by id (e.g. pages/home). Prefers runtime |
kirby_blueprints_index | read | Index Kirby blueprints keyed by id (e.g. pages/home). Default is a small summary (no full data, no raw CLI output) and includes derived displayName (title/name/label) plus source info (file vs extension override). Prefers runtime |
kirby_blueprints_loaded | read | List blueprint ids that Kirby knows about at runtime (extensions + filesystem). Defaults to idsOnly=true to avoid truncation; supports filters and pagination. Requires kirby_runtime_install first. |
kirby_cache_clear | destructive | Clear in-memory caches for the current MCP process (StaticCache, config cache, composer cache, roots cache, tool index). This does not delete any project files. |
kirby_cli_version | write | Run |
kirby_collections_index | read | Index Kirby named collections keyed by id (e.g. articles/latest). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime |
kirby_composer_audit | read | Parse composer.json to detect Kirby version, scripts, test runner, and quality tools (phpstan/larastan/psalm/mago/pint/phpcs/php-cs-fixer). Returns “how to run” commands. Resource: |
kirby_content_migration_assistant | write | Plan/apply a safe content migration using kirby_read_page_content + kirby_update_page_content (explicit confirmation required). |
kirby_controllers_index | read | Index Kirby controllers keyed by id (e.g. album, album.json). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime |
kirby_debug_render_trace | read | Debug by reproducing via kirby_render_page and inspecting mcp_dump traces via kirby_dump_log_tail. |
kirby_dump_log_tail | read | Tail |
kirby_eval | read | Tinker/REPL ( |
kirby_generate_ide_helpers | read | Generate IDE helper files (optional/regeneratable) from project context (blueprints, indexes). Writes to |
kirby_ide_helpers_status | read | Report IDE helper status (missing template/snippet PHPDoc @var hints + helper file freshness using mtimes). Designed to keep LLMs tool-first and avoid stale static helpers. |
kirby_ide_support_boost | read | Improve IDE support via status + minimal type-hint fixes + optional helper generation. |
kirby_info | read | Return project runtime info (PHP + Kirby version via Kirby CLI), composer audit, and local environment detection (Herd/DDEV/Docker). Resource: |
kirby_init | read | Return Kirby MCP guidance + project-specific audit. Required before other tools in handshake sessions; optional for stateless modern calls. |
kirby_models_index | read | Index registered Kirby page models keyed by id (e.g. default, article) with class + file path info. Prefers runtime |
kirby_online | read | Search official Kirby docs via |
kirby_online_plugins | read | Search the official Kirby plugin directory (plugins.getkirby.com) and optionally fetch individual plugin pages to extract key details and return a markdown summary. Online fallback; prefer kirby_plugins_index for installed plugins. |
kirby_performance_audit | read | Guide an agent through a Kirby performance audit (cache + query pitfalls). Use before making performance-related changes. |
kirby_plugins_index | read | Index loaded Kirby plugins keyed by id (runtime truth) via |
kirby_project_tour | read | Map the project (roots + inventory) and suggest next steps. |
kirby_query_dot | read | Evaluate Kirby query language (dot-notation) strings in Kirby runtime via the installed |
kirby_read_file_content | read | Read a file’s content/metadata by id or uuid via the installed |
kirby_read_page_content | read | Read a page’s content (current version; drafts/changes-aware) by id or uuid via the installed |
kirby_read_site_content | read | Read the site’s content (current version) via the installed |
kirby_read_user_content | read | Read a user’s content by id or email via the installed |
kirby_render_page | read | Render a Kirby page by id or uuid via the installed |
kirby_roots | read | Return Kirby’s resolved folder roots (kirby()->roots) via |
kirby_routes_index | read | List registered Kirby routes with pattern/method/name and best-effort source location for the action callback. Requires |
kirby_run_cli_command | write | Run a Kirby CLI command and return raw stdout/stderr + exit code. Commands are guarded by an allowlist (built-in + optional .kirby-mcp/mcp.json); set allowWrite=true for write-capable commands (e.g. make:*). Prefer dedicated MCP resources/tools for common tasks (e.g. |
kirby_runtime_install | write | Install project-local Kirby CLI commands used by Kirby MCP (e.g. |
kirby_runtime_status | read | Check whether project-local Kirby MCP runtime CLI command wrappers are installed (presence check against the package’s expected command files). |
kirby_scaffold_page_type | read | Scaffold a new Kirby page type (blueprint + template, optional controller/page model) using project roots and conventions. |
kirby_search | read | Search the bundled local Kirby knowledge base markdown files (kb/) using fuzzy Levenshtein matching and optionally return full markdown for the top matches (fetch). Prefer this before kirby_online. |
kirby_snippets_index | read | Index Kirby snippets keyed by id (e.g. blocks/gallery). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime |
kirby_templates_index | read | Index Kirby templates keyed by id (e.g. home, notes.json). Defaults to a compact payload (no raw CLI stdout/stderr). Prefers runtime |
kirby_tool_suggest | read | Suggest the best next Kirby MCP tool/resource for a task using a weighted keyword matcher. Suggestions can include tools, resources ( |
kirby_update_file_content | write | Update a file’s content/metadata by id or uuid via the installed |
kirby_update_page_content | write | Update a page’s content by id or uuid via the installed |
kirby_update_site_content | write | Update the site’s content via the installed |
kirby_update_user_content | write | Update a user’s content by id or email via the installed |
kirby_upgrade_kirby | read | Upgrade Kirby safely (official docs + composer + verification). |
page_content | read | Read a page’s content by id or uuid. The id must be URL-encoded (e.g. home or blog%2Fpost). UUIDs can be passed as the raw UUID (preferred) or as a URL-encoded Kirby UUID like page%3A%2F%2F<uuid>. |
panel_field | read | Fetch Kirby Panel field reference markdown from getkirby.com (docs/reference/panel/fields/{type}). |
panel_fields | read | List Kirby Panel field types (links to kirby://field/{type}). |
panel_section | read | Fetch Kirby Panel section reference markdown from getkirby.com (docs/reference/panel/sections/{type}). |
panel_sections | read | List Kirby Panel section types (links to kirby://section/{type}). |
roots | read | Kirby roots (kirby()->roots) discovered via Kirby CLI using the configured default host (KIRBY_MCP_HOST/KIRBY_HOST or .kirby-mcp/mcp.json) when present. |
site_content | read | Read the site’s content (current version) via the runtime CLI command. |
susie | read | Easter egg: Susie (Kirby: Planet Robobot) boss attack loop. Provide phase (1-3) and step (1-based). Returns attack name or null. |
tool-examples | read | Curated usage examples for Kirby MCP tools with stricter inputs or confirm flows. |
tools | read | Weighted keyword index for Kirby MCP tools, resources, and resource templates (used by kirby_tool_suggest). |
update_schema_blueprint | write | Read a bundled blueprint update schema from kb/update-schema/blueprint-{type}.md. |
update_schema_blueprints | write | List bundled blueprint update schemas (links to kirby://blueprint/{type}/update-schema). |
update_schema_field | write | Read a bundled content field update schema from kb/update-schema/{type}.md. |
update_schema_fields | write | List bundled content field update schemas (links to kirby://field/{type}/update-schema). |
user_content | read | Read a user’s content by id or email. The id/email must be URL-encoded (e.g. jane%40example.com). |
uuid_new | read | Generate a new random Kirby UUID string (respects content.uuid format). |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (3 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
return eval($code);
title: 'Eval (CLI)',
title: 'Eval (CLI)',
kirby_cache_clear
streamable-http
"allowedOrigins": ["http://127.0.0.1:3000"],
In Kirby, a “role” defines what a user is allowed to do. Roles are defined by **user blueprints** in `site/blueprints/users/` (e.g. `editor.yml`). The `admin` role always exists and has full permissio
Gates applied: no_behavioural_pass.
07ce290aa397full audit observations/trust-audit/mcp-server/bnomei__kirby.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 07ce290aa397 | BLOCK | D | 66 | first audit |
Questions
What is the Kirby MCP server?
CLI-first MCP server for composer-based Kirby CMS projects — inspect blueprints/templates/plugins, interact with a real Kirby runtime, and use a bundled Kirby knowledge base.
What tools does Kirby expose?
75 in total: 62 read-only, 12 that write, and 1 that can delete or overwrite (kirby_cache_clear). Every one is listed on this page with its risk.
Is Kirby safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Kirby need?
No credential environment variables were found in its source, so it appears to need none.
How does Kirby run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (07ce290aa397), read on 2026-10-07. The repository is watched and re-audited when it changes.