Atlas / MCP servers / juehang / VS Code Server

VS Code ServerSAFE

mcp/juehang/vs-code-server

MCP server to expose VS Code editing features to an LLM for AI coding

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 7r · 5w · 0d
Transport
streamable-http
License
MIT
Stars
395
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Visual Studio Code extension (available on the Marketplace) that allows Claude and other MCP clients to code directly in VS Code! Inspired by Serena, but using VS Code's built-in capabilities. Perfect for extending existing coding agents like Claude Code with VS Code-specific capabilities (symbol search, document outlines) without duplicating tools they already have. Note that this extension uses the streamable HTTP API, not the SSE API.

This extension can allow for execution of shell commands. This means that there is a potential security risk, so use with caution, and ensure that you trust the MCP client that you are using and that the port is not exposed to anything. Authentication would help, but as the MCP authentication spec is still in flux, this has not been implemented for now.

PRs are welcome!

Demo Video

https://github.com/user-attachments/assets/20b87dfb-fc39-4710-a910-b9481dde1e90

Installation

  1. Install the extension from the Marketplace or clone this repository and run npm install and npm run compile to build it.

Claude Desktop Configuration

Claude Desktop can be configured to use this extension as an MCP server. To do this, your claude_desktop_config.json file should look like this:

{
"mcpServers": {
"vscode-mcp-server": {
"command": "npx",
"args": ["mcp-remote@next", "http://localhost:3000/mcp"]
}

}
}

I also like to use this extension in a Claude project, as it allows me to specify additional instructions for Claude. I find the following prompt to work well:

You are working on an existing codebase, which you can access using your tools. These code tools interact with a VS Code workspace.

WORKFLOW ESSENTIALS:
1. Always start exploration with list_files_code on roo
Read from source at commit 52491feb3c1dOBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add vscode-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "vscode-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (12)

7 read · 5 write · 0 destructive.

ToolRiskDescription
copy_file_codereadCopies a file to a new location. WHEN TO USE: Creating backups, duplicating files for testing, creating template files. LIMITATION: Only works for files, not directories.
create_file_codewrite
execute_shell_command_codewrite
get_diagnostics_codewriteCRITICAL: Run this after EVERY series of code changes to check for errors before completing tasks. Analyzes code for warnings and errors using VS Code
get_document_symbols_coderead
get_symbol_definition_coderead
list_files_coderead
move_file_codewriteMoves a file or directory to a new location using VS Code
read_file_codereadRetrieves file contents with size limits and partial reading support. WHEN TO USE: Reading code, config files, analyzing implementations. Files >100k chars will fail. Encoding: Text encodings (utf-8, latin1, etc.) for text files,
rename_file_codewriteRenames a file or directory using VS Code
replace_lines_coderead
search_symbols_codereadSearches for symbols (functions, classes, variables) across workspace using fuzzy matching. WHEN TO USE: Finding function/class definitions, exploring project structure, locating specific elements. Search: Supports partial terms (e.g.,
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vscode-test.mjs
.vscode-test.mjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/express, express, zod, @modelcontextprotocol/inspector, @types/mocha, @types/proxyquire, @types/sinon
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha 52491feb3c1dfull audit observations/trust-audit/mcp-server/juehang__vs-code-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0252491feb3c1dSAFEB89first audit
06

Questions

What is the VS Code Server MCP server?

MCP server to expose VS Code editing features to an LLM for AI coding

What tools does VS Code Server expose?

12 in total: 7 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is VS Code Server safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does VS Code Server need?

No credential environment variables were found in its source, so it appears to need none.

How does VS Code Server run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as vscode-mcp-server at 0.4.0.

How current is this page?

The grade is for one exact copy of the source (52491feb3c1d), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement