Atlas / MCP servers / elgentos / Magento 2 Dev

Magento 2 DevSAFE

mcp/elgentos/magento-2-dev

An MCP server to help with Magento 2 development

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
29 22r · 7w · 0d
Transport
stdio
License
MIT
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This project is abandoned since it mainly exposed magerun commands through an MCP. Magerun now offers an internal MCP server; just run magerun2 mcp:server:start - see magerun2 9.3.0 release notes.

A Model Context Protocol (MCP) server for Magento 2 development, designed to integrate with AI agents like Claude, Cursor, Continue.dev, and Augment Code.

Installation

Using npx

npx -y @elgentos/magento2-dev-mcp

Quick Start

  1. Add to your AI agent's MCP configuration:
{
"mcpServers": {
"magento2-dev": {
"command": "npx",
"args": ["-y", "@elgentos/magento2-dev-mcp"]
}
}
}
  1. Restart your AI agent to load the MCP server
  1. Start using Magento 2 development tools through your AI agent!

See AI Platform Configuration Examples for platform-specific setup instructions.

Docker Environment Support

The server automatically detects Docker-based Magento environments and routes magerun2 commands through the container:

For docker-compose the server tries the service names phpfpm, php-fpm, and php in order.

If Docker execution fails, the server falls back to running magerun2 loc

Read from source at commit bc0486445fd0OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add magento2-dev-mcp -- npx -y @elgentos/[email protected]
claude-desktop
{
  "mcpServers": {
    "magento2-dev-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@elgentos/[email protected]"
      ]
    }
  }
}
03

Exposed tools (29)

22 read · 7 write · 0 destructive.

ToolRiskDescription
cache-cleanread
cache-disablewrite
cache-enablewrite
cache-flushread
cache-statusread
cache-viewread
config-setwrite
config-showread
config-store-getread
config-store-setwrite
db-queryread
dev-module-createwrite
dev-module-listread
dev-module-observer-listread
dev-plugin-listread
dev-theme-listread
get-di-preferencesread
setup-db-statusread
setup-di-compileread
setup-static-content-deploywrite
setup-upgraderead
sys-checkread
sys-cron-listread
sys-cron-runwrite
sys-inforead
sys-store-config-base-url-listread
sys-store-listread
sys-url-listread
sys-website-listread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha bc0486445fd0full audit observations/trust-audit/mcp-server/elgentos__magento-2-dev.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08bc0486445fd0SAFEB89first audit
06

Questions

What is the Magento 2 Dev MCP server?

An MCP server to help with Magento 2 development

What tools does Magento 2 Dev expose?

29 in total: 22 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Magento 2 Dev safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Magento 2 Dev need?

No credential environment variables were found in its source, so it appears to need none.

How does Magento 2 Dev run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @elgentos/magento2-dev-mcp at 1.0.2.

How current is this page?

The grade is for one exact copy of the source (bc0486445fd0), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement