Magento 2 DevSAFE
An MCP server to help with Magento 2 development
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This project is abandoned since it mainly exposed magerun commands through an MCP. Magerun now offers an internal MCP server; just run magerun2 mcp:server:start - see magerun2 9.3.0 release notes.
A Model Context Protocol (MCP) server for Magento 2 development, designed to integrate with AI agents like Claude, Cursor, Continue.dev, and Augment Code.
Installation
Using npx
npx -y @elgentos/magento2-dev-mcp
Quick Start
- Add to your AI agent's MCP configuration:
{
"mcpServers": {
"magento2-dev": {
"command": "npx",
"args": ["-y", "@elgentos/magento2-dev-mcp"]
}
}
}- Restart your AI agent to load the MCP server
- Start using Magento 2 development tools through your AI agent!
See AI Platform Configuration Examples for platform-specific setup instructions.
Docker Environment Support
The server automatically detects Docker-based Magento environments and routes magerun2 commands through the container:
For docker-compose the server tries the service names phpfpm, php-fpm, and php in order.
If Docker execution fails, the server falls back to running magerun2 loc
bc0486445fd0OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add magento2-dev-mcp -- npx -y @elgentos/[email protected]
{
"mcpServers": {
"magento2-dev-mcp": {
"command": "npx",
"args": [
"-y",
"@elgentos/[email protected]"
]
}
}
}Exposed tools (29)
22 read · 7 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cache-clean | read | |
cache-disable | write | |
cache-enable | write | |
cache-flush | read | |
cache-status | read | |
cache-view | read | |
config-set | write | |
config-show | read | |
config-store-get | read | |
config-store-set | write | |
db-query | read | |
dev-module-create | write | |
dev-module-list | read | |
dev-module-observer-list | read | |
dev-plugin-list | read | |
dev-theme-list | read | |
get-di-preferences | read | |
setup-db-status | read | |
setup-di-compile | read | |
setup-static-content-deploy | write | |
setup-upgrade | read | |
sys-check | read | |
sys-cron-list | read | |
sys-cron-run | write | |
sys-info | read | |
sys-store-config-base-url-list | read | |
sys-store-list | read | |
sys-url-list | read | |
sys-website-list | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
@modelcontextprotocol/sdk, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
bc0486445fd0full audit observations/trust-audit/mcp-server/elgentos__magento-2-dev.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | bc0486445fd0 | SAFE | B | 89 | first audit |
Questions
What is the Magento 2 Dev MCP server?
An MCP server to help with Magento 2 development
What tools does Magento 2 Dev expose?
29 in total: 22 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Magento 2 Dev safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Magento 2 Dev need?
No credential environment variables were found in its source, so it appears to need none.
How does Magento 2 Dev run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @elgentos/magento2-dev-mcp at 1.0.2.
How current is this page?
The grade is for one exact copy of the source (bc0486445fd0), read on 2026-10-08. The repository is watched and re-audited when it changes.