Atlas / MCP servers / boldcommerce / Magento 2

Magento 2CAUTION

mcp/boldcommerce/magento-2

A MCP server for Magento 2

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
14 12r · 2w · 0d
Transport
stdio
License
GPL-3.0
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This is a Model Context Protocol (MCP) server that connects to a Magento 2 REST API, allowing Claude and other MCP clients to query product information from a Magento store.

Features

Product Features

  • Query product information by SKU or ID
  • Search for products using various criteria
  • Get product categories
  • Get related products
  • Get product stock information
  • Get product attributes
  • Update product attributes by specifying attribute code and value
  • Advanced product search with filtering and sorting

Customer Features

  • Get all ordered products for a customer by email address

Order and Revenue Features

  • Get order count for specific date ranges
  • Get revenue for specific date ranges
  • Get revenue filtered by country for specific date ranges
  • Get product sales statistics including quantity sold and top-selling products
  • Support for relative date expressions like "today", "yesterday", "last week", "this month", "YTD"
  • Support for country filtering using both country codes and country names

Prerequisites

  • Node.js (v14 or higher)
  • A Magento 2 instance with REST API access
  • API token for the Magento 2 instance

Installation

  1. Clone this repository
  2. Install dependencies:
npm install

Usage

Running the server directly

node mcp-server.js

Testing with the test client

node test-mcp-server.js

Using with Claude Desktop

  1. Check your path node with which node
  2. Go to the Developer settings and click "Edit config". This will open a JSON file.
  3. Add the following snippet within the mcpServers:
"magento2": {
"command": "/path/to/your/node",
"args": ["/path/to/mcp-server.js"],
"env": {
"MAGENTO_BASE_URL": "https://YOUR_DOMAIN/rest/V1",
"MAGENTO_API_TOKEN": "your-api-token"
}
}
  1. Replace /path/to/your/node with the path you checked in step 1
  2. Replace /path/to/mcp-server.js with the path where
Read from source at commit ebb06be00f31OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-magento2 --env MAGENTO_API_TOKEN=${MAGENTO_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-magento2": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MAGENTO_API_TOKEN": "${MAGENTO_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (14)

12 read · 2 write · 0 destructive.

ToolRiskDescription
advanced_product_searchreadSearch for products with advanced filtering options
get_customer_ordered_products_by_emailreadGet all ordered products for a customer by email address
get_order_countwriteGet the number of orders for a given date range
get_product_attributesreadGet all attributes for a product by SKU
get_product_by_idreadGet detailed information about a product by its ID
get_product_by_skureadGet detailed information about a product by its SKU
get_product_categoriesreadGet categories for a specific product by SKU
get_product_salesreadGet statistics about the quantity of products sold in a given date range
get_product_stockreadGet stock information for a product by SKU
get_related_productsreadGet products related to a specific product by SKU
get_revenuereadGet the total revenue for a given date range
get_revenue_by_countryreadGet revenue filtered by country for a given date range
search_productsreadSearch for products using Magento search criteria
update_product_attributewriteUpdate a specific attribute of a product by SKU
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
mcp-server.js:324
rejectUnauthorized: false
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @modelcontextprotocol/sdk, axios, body-parser, date-fns, dotenv, express, zod
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
mcp-instructions/modelcontextprotocol.md:3307
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
mcp-instructions/modelcontextprotocol.md:3891
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ebb06be00f31full audit observations/trust-audit/mcp-server/boldcommerce__magento-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ebb06be00f31CAUTIONB89first audit
06

Questions

What is the Magento 2 MCP server?

A MCP server for Magento 2

What tools does Magento 2 expose?

14 in total: 12 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Magento 2 safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Magento 2 need?

It reads MAGENTO_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Magento 2 run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-magento2 at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (ebb06be00f31), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement