Atlas / MCP servers / freshtechbro / Vibe Coder

Vibe CoderBLOCK

mcp/freshtechbro/vibe-coder-2

Vibe-Coder-MCP server extends AI assistants with specialized software development tools.

Verdict
BLOCK
Grade
F
Trust score
46 /100
Exposed tools
26 25r · 1w · 0d
Transport
sse · stdio
License
NOASSERTION
Stars
103
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/vibe-coder-mcp) [](https://www.npmjs.com/package/vibe-coder-mcp) [](https://www.npmjs.com/package/vibe-coder-mcp) [](https://github.com/freshtechbro/Vibe-Coder-MCP/releases) [](https://nodejs.org/) [](LICENSE) [](https://github.com/freshtechbro/Vibe-Coder-MCP/stargazers)

Vibe Coder is an MCP (Model Context Protocol) server designed to supercharge your AI assistant (like Cursor, Cline AI, or Claude Desktop) with powerful tools for software development. It helps with research, planning, generating requirements, creating starter projects, and more!

🆕 What's New in Version 0.3.5

🎉 Latest Release - Enhanced CLI, REPL, and Parameter Extraction

Major Improvements:

  • ✨ Complete Hybrid Matcher Overhaul: All 15 MCP tools now have comprehensive parameter extraction
  • 🚀 CLI/REPL Experience: Interactive confirmations, job status polling with visual progress
  • 🔧 Fixed Critical Bugs: Task-list-generator auto-generates user stories, multi-turn conversations work flawlessly
  • 📊 Better Tool Matching: Mu
Read from source at commit ed6e976edc4cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add code-map-generator --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} --env VIBE_AUTH_SECRET=${VIBE_AUTH_SECRET} --env VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT=${VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT} --env VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE=${VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "code-map-generator": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}",
        "VIBE_AUTH_SECRET": "${VIBE_AUTH_SECRET}",
        "VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT": "${VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT}",
        "VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE": "${VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE}"
      }
    }
  }
}
03

Exposed tools (26)

25 read · 1 write · 0 destructive.

ToolRiskDescription
darkreadHigh contrast theme for dark terminals
defaultreadDefault balanced color scheme
default-projectreadDefault project for testing
errorToolreadA tool that returns an error result
forestreadForest-inspired green and earth color scheme
fullstack-starter-kit-generatorreadGenerates full-stack project starter kits by composing YAML modules based on user requirements, tech stacks, research-informed recommendations, and then provides setup scripts. Dynamically generates missing YAML modules using LLM.
generate-fullstack-starter-kitreadGenerates full-stack project starter kits with custom tech stacks
generate-prdreadCreates comprehensive product requirements documents
generate-rulesreadCreates project-specific development rules based on product description
generate-task-listreadCreates structured development task lists with dependencies
generate-user-storiesreadCreates detailed user stories with acceptance criteria
get-agent-tasksreadGet pending tasks for an agent (stdio polling)
get-job-resultreadRetrieves the current status and, if available, the final result of a background job. Supports enhanced diagnostic information for debugging and troubleshooting.
lightreadSoft colors optimized for light terminals
oceanreadOcean-inspired blue and aqua color scheme
prd-generatorreadProduct requirements tool
process-requestreadProcesses natural language requests and routes them to the appropriate tool
register-agentreadRegister an AI agent with the task management system
research-managerreadResearch management tool
rules-generatorreadCreates project-specific development rules based on product description, user stories, and research.
submit-task-responsewriteSubmit task completion response from agent
successToolreadA tool that always succeeds
task-list-generatorreadCreates structured development task lists, decomposing high-level tasks into detailed sub-tasks with implementation guidance.
throwingToolreadA tool executor that throws
user-stories-generatorreadCreates detailed user stories with acceptance criteria based on a product description and research.
vibe-task-managerreadAI-agent-native task management system with recursive decomposition design (RDD) methodology. Supports project creation, task decomposition, dependency management, and agent coordination for autonomous software development workflows.
04

Trust audit

BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (6 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/tools/context-curator/services/output-formatter.ts:399
const parsed = yaml.load(content) as Record<string, unknown>;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/tools/fullstack-starter-kit-generator/yaml-composer.ts:571
const parsed = yaml.load(fileContent) as Record<string, unknown>;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/tools/vibe-task-manager/utils/file-utils.ts:207
const parsedData = yaml.load(readResult.data!) as T;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/tools/code-map-generator/grammars/tree-sitter-c.wasm
tree-sitter-c.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/tools/code-map-generator/grammars/tree-sitter-css.wasm
tree-sitter-css.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/tools/code-map-generator/grammars/tree-sitter-elisp.wasm
tree-sitter-elisp.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/tools/code-map-generator/grammars/tree-sitter-elm.wasm
tree-sitter-elm.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/tools/code-map-generator/grammars/tree-sitter-embedded_template.wasm
tree-sitter-embedded_template.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/tools/vibe-task-manager/core/di-container.ts:186
logger.debug(`Resolved service synchronously: ${token}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/tools/vibe-task-manager/core/di-container.ts:256
logger.debug(`Resolved service: ${token}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/tools/vibe-task-manager/core/di-container.ts:296
logger.debug(`Disposed service: ${token}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/tools/vibe-task-manager/core/di-container.ts:298
logger.error(`Error disposing service ${token}:`, error);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/utils/__tests__/config-provider.test.ts:90
apiKey: 'ci-test-key-safe-provider',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/utils/__tests__/config-provider.test.ts:238
apiKey: 'ci-test-key-safe-provider'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/utils/config-provider.ts:59
apiKey: 'ci-test-key-safe-provider',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/utils/config-provider.ts:115
apiKey: 'ci-test-key-safe-provider',
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vibe-config.json
.vibe-config.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/config-templates/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/tools/code-map-generator/__tests__/fixtures/python-imports.py:48
math_module = __import__(module_name)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/services/job-manager/index.ts:127
return createHash('md5').update(fingerprintData).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/tools/code-map-generator/__tests__/fixtures/python-imports.py:96
return hashlib.md5(b"test").hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/tools/code-map-generator/cache/fileCache.ts:232
return crypto.createHash('md5').update(key).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/tools/code-map-generator/cache/fileChangeDetector.ts:257
return crypto.createHash('md5').update(content).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/tools/code-map-generator/cache/fileContentManager.ts:223
const hash = crypto.createHash('md5').update(content).digest('hex');
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/tools/vibe-task-manager/__tests__/security/path-injection-security.test.ts:50
'~/.ssh/id_rsa',
Why it matters. touches a credential store

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ed6e976edc4cfull audit observations/trust-audit/mcp-server/freshtechbro__vibe-coder-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ed6e976edc4cBLOCKF46first audit
06

Questions

What is the Vibe Coder MCP server?

Vibe-Coder-MCP server extends AI assistants with specialized software development tools.

What tools does Vibe Coder expose?

26 in total: 25 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Vibe Coder safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (46/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Vibe Coder need?

It reads OPENROUTER_API_KEY, VIBE_AUTH_SECRET, VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT and VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Vibe Coder run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as code-map-generator at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (ed6e976edc4c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement