Vibe CoderBLOCK
Vibe-Coder-MCP server extends AI assistants with specialized software development tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/vibe-coder-mcp) [](https://www.npmjs.com/package/vibe-coder-mcp) [](https://www.npmjs.com/package/vibe-coder-mcp) [](https://github.com/freshtechbro/Vibe-Coder-MCP/releases) [](https://nodejs.org/) [](LICENSE) [](https://github.com/freshtechbro/Vibe-Coder-MCP/stargazers)
Vibe Coder is an MCP (Model Context Protocol) server designed to supercharge your AI assistant (like Cursor, Cline AI, or Claude Desktop) with powerful tools for software development. It helps with research, planning, generating requirements, creating starter projects, and more!
🆕 What's New in Version 0.3.5
🎉 Latest Release - Enhanced CLI, REPL, and Parameter Extraction
Major Improvements:
- ✨ Complete Hybrid Matcher Overhaul: All 15 MCP tools now have comprehensive parameter extraction
- 🚀 CLI/REPL Experience: Interactive confirmations, job status polling with visual progress
- 🔧 Fixed Critical Bugs: Task-list-generator auto-generates user stories, multi-turn conversations work flawlessly
- 📊 Better Tool Matching: Mu
ed6e976edc4cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add code-map-generator --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} --env VIBE_AUTH_SECRET=${VIBE_AUTH_SECRET} --env VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT=${VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT} --env VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE=${VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE} -- npx -y [email protected]{
"mcpServers": {
"code-map-generator": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}",
"VIBE_AUTH_SECRET": "${VIBE_AUTH_SECRET}",
"VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT": "${VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT}",
"VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE": "${VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE}"
}
}
}
}Exposed tools (26)
25 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
dark | read | High contrast theme for dark terminals |
default | read | Default balanced color scheme |
default-project | read | Default project for testing |
errorTool | read | A tool that returns an error result |
forest | read | Forest-inspired green and earth color scheme |
fullstack-starter-kit-generator | read | Generates full-stack project starter kits by composing YAML modules based on user requirements, tech stacks, research-informed recommendations, and then provides setup scripts. Dynamically generates missing YAML modules using LLM. |
generate-fullstack-starter-kit | read | Generates full-stack project starter kits with custom tech stacks |
generate-prd | read | Creates comprehensive product requirements documents |
generate-rules | read | Creates project-specific development rules based on product description |
generate-task-list | read | Creates structured development task lists with dependencies |
generate-user-stories | read | Creates detailed user stories with acceptance criteria |
get-agent-tasks | read | Get pending tasks for an agent (stdio polling) |
get-job-result | read | Retrieves the current status and, if available, the final result of a background job. Supports enhanced diagnostic information for debugging and troubleshooting. |
light | read | Soft colors optimized for light terminals |
ocean | read | Ocean-inspired blue and aqua color scheme |
prd-generator | read | Product requirements tool |
process-request | read | Processes natural language requests and routes them to the appropriate tool |
register-agent | read | Register an AI agent with the task management system |
research-manager | read | Research management tool |
rules-generator | read | Creates project-specific development rules based on product description, user stories, and research. |
submit-task-response | write | Submit task completion response from agent |
successTool | read | A tool that always succeeds |
task-list-generator | read | Creates structured development task lists, decomposing high-level tasks into detailed sub-tasks with implementation guidance. |
throwingTool | read | A tool executor that throws |
user-stories-generator | read | Creates detailed user stories with acceptance criteria based on a product description and research. |
vibe-task-manager | read | AI-agent-native task management system with recursive decomposition design (RDD) methodology. Supports project creation, task decomposition, dependency management, and agent coordination for autonomous software development workflows. |
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const parsed = yaml.load(content) as Record<string, unknown>;
const parsed = yaml.load(fileContent) as Record<string, unknown>;
const parsedData = yaml.load(readResult.data!) as T;
tree-sitter-c.wasm
tree-sitter-css.wasm
tree-sitter-elisp.wasm
tree-sitter-elm.wasm
tree-sitter-embedded_template.wasm
logger.debug(`Resolved service synchronously: ${token}`);logger.debug(`Resolved service: ${token}`);logger.debug(`Disposed service: ${token}`);logger.error(`Error disposing service ${token}:`, error);apiKey: 'ci-test-key-safe-provider',
apiKey: 'ci-test-key-safe-provider'
apiKey: 'ci-test-key-safe-provider',
apiKey: 'ci-test-key-safe-provider',
.vibe-config.json
.env.template
math_module = __import__(module_name)
return createHash('md5').update(fingerprintData).digest('hex');return hashlib.md5(b"test").hexdigest()
return crypto.createHash('md5').update(key).digest('hex');return crypto.createHash('md5').update(content).digest('hex');const hash = crypto.createHash('md5').update(content).digest('hex');'~/.ssh/id_rsa',
Gates applied: no_behavioural_pass.
ed6e976edc4cfull audit observations/trust-audit/mcp-server/freshtechbro__vibe-coder-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ed6e976edc4c | BLOCK | F | 46 | first audit |
Questions
What is the Vibe Coder MCP server?
Vibe-Coder-MCP server extends AI assistants with specialized software development tools.
What tools does Vibe Coder expose?
26 in total: 25 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Vibe Coder safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Vibe Coder need?
It reads OPENROUTER_API_KEY, VIBE_AUTH_SECRET, VIBE_CONTEXT_CURATOR_KEYWORD_WEIGHT and VIBE_CONTEXT_CURATOR_MAX_TOKENS_PER_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Vibe Coder run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as code-map-generator at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (ed6e976edc4c), read on 2026-10-07. The repository is watched and re-audited when it changes.