Atlas / MCP servers / formulahendry / Spec-Driven Development

Spec-Driven DevelopmentSAFE

mcp/formulahendry/spec-driven-development

Spec-Driven Development MCP Server, not just Vibe Coding

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
438
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

-VS_Code-0098FF)

Model Context Protocol (MCP) server that facilitates spec-driven development workflows by providing structured prompts for generating requirements, design documents, and code following a systematic approach.

🎯 Purpose

This MCP server enables developers to follow a structured spec-driven development approach by providing prompts that guide you through:

  1. Requirements Generation - Create detailed requirements documents using the EARS (Easy Approach to Requirements Syntax) format
  2. Design Generation - Generate design documents based on requirements
  3. Code Generation - Generate implementation code based on design documents

✨ Features

  • Structured Workflow: Follows a clear progression from requirements → design → code
  • EARS Format Support: Uses industry-standard EARS format for requirements documentation
  • MCP Protocol: Integrates seamlessly with MCP-compatible tools and environments

🚀 Quick Start

Prerequisites

  • Node.js 20+

Installation

VS Code

Install the MCP server in VS Code using below buttons:

[-VS_Code-0098FF)]

Read from source at commit 17fc523e3749OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add mcp-server-spec-driven-development -- npx -y [email protected]
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, express, zod, @types/express, @types/node, shx, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 17fc523e3749full audit observations/trust-audit/mcp-server/formulahendry__spec-driven-development.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-3017fc523e3749SAFEB89first audit
05

Questions

What is the Spec-Driven Development MCP server?

Spec-Driven Development MCP Server, not just Vibe Coding

Is Spec-Driven Development safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Spec-Driven Development need?

No credential environment variables were found in its source, so it appears to need none.

How does Spec-Driven Development run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-server-spec-driven-development at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (17fc523e3749), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement