Magento 2 LSPSAFE
Language Server (LSP) and MCP server for Magento 2 - provides go-to-definition, references, and rename across PHP, XML, and layout files.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Magento 2 tooling for editors and AI agents. This package includes two servers that share the same index and understanding of Magento's configuration system:
- LSP server - for your editor. Go-to-definition, find-references, diagnostics, and code lenses across XML and PHP.
- MCP server - for AI coding agents. Exposes merged Magento configuration that agents can't get by reading individual files.
Both are installed from the same repo but configured separately - the LSP in your editor, the MCP in your AI agent. They can be used together or independently.
Rationale
Agents write the code, but you still review it - and jumping between XML and PHP with a keystroke beats grepping through config files. AI agents need the opposite: not navigation, but the merged result of Magento's multi-module configuration that no single file contains.
LSP Server
Works alongside Intelephense or Phpactor - this LSP handles the Magento-specific connections that generic PHP tooling can't see.
- Auto-complete as you type. Context-aware completions for FQCNs, event names, config paths, ACL resource IDs, template identifiers, layout handles, block/container names, and DB table/column names across XML config files and PHP.
- Navigate XML config like code. Go-to-definition and find-references work across
di.xml,events.xml,system.xml, and layout XML - linking them to the PHP classes, templates, and config paths they reference.
- Trace the plugin chain. See which plugins intercept a method, jump from a
beforeSaveplugin to the method it wraps, and see plugin counts directly in your editor via code lenses.
- Follow config paths. Jump from
scopeConfig->getValue('payment/account/active')in PHP straight to the `declaration insystem.xml`, and find all PHP files using a config path.
- Catch errors as you type. Broken class references, missing templates, duplicate plugin names, and invalid model classes are flagged with
2a1617443d2dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add magento2-lsp -- npx -y @mage-os/[email protected]
{
"mcpServers": {
"magento2-lsp": {
"command": "npx",
"args": [
"-y",
"@mage-os/[email protected]"
]
}
}
}Exposed tools (11)
11 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
magento_get_class_context | read | Get the full Magento context for a PHP class file: resolves the FQCN from the file path, |
magento_get_class_hierarchy | read | Get the class hierarchy for a PHP class: its parent class, implemented interfaces, |
magento_get_db_schema | read | Get the merged database table schema from all db_schema.xml files across modules. |
magento_get_di_config | read | Get the complete DI configuration for a PHP class/interface after Magento config merging. |
magento_get_event_observers | read | Get all observers for a Magento event, or all events handled by an observer class. |
magento_get_module_overview | read | Get an overview of what a Magento module declares: preferences, plugins, virtual types, |
magento_get_plugins_for_method | read | Get all plugins (before/after/around interceptors) for a specific method on a class, |
magento_get_template_overrides | read | Find theme overrides and layout XML usages for a template identifier. |
magento_rescan_project | read | Rescan the Magento project to rebuild the MCP server cache. Call this after creating |
magento_resolve_class | read | Resolve a PHP class: given a file path, returns its FQCN; given a FQCN, returns its file path. |
magento_search_symbols | read | Search for Magento symbols by name: ALL PHP classes/interfaces (not just DI-configured ones), |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
.vscodeignore
.magento2-lsp-symbols-cache.json
return crypto.createHash('md5').update(data).digest('hex');import { IndexCache } from '../../src/cache/indexCache';import { DiReference, VirtualTypeDecl } from '../../src/indexer/types';import { SymbolsCache, computePsr4Hash, computeTemplateSourceHash } from '../../src/cache/symbolsCache';import { handleCodeAction, handleCodeActionResolve } from '../../src/handlers/codeAction';import { DiIndex } from '../../src/index/diIndex';vscode-languageclient, @types/vscode, typescript
@modelcontextprotocol/sdk, chokidar, sax, vscode-languageserver, vscode-languageserver-textdocument, vscode-uri, @types/node, @types/sax
Server settings are passed via `initializationOptions`. To configure them, the VS Code extension would need to forward settings — this is not yet wired in the extension. In the meantime, you can use e
Gates applied: no_behavioural_pass.
2a1617443d2dfull audit observations/trust-audit/mcp-server/mage-os-lab__magento-2-lsp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2a1617443d2d | SAFE | B | 89 | first audit |
Questions
What is the Magento 2 LSP MCP server?
Language Server (LSP) and MCP server for Magento 2 - provides go-to-definition, references, and rename across PHP, XML, and layout files.
What tools does Magento 2 LSP expose?
11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Magento 2 LSP safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Magento 2 LSP need?
No credential environment variables were found in its source, so it appears to need none.
How does Magento 2 LSP run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mage-os/magento2-lsp at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (2a1617443d2d), read on 2026-10-08. The repository is watched and re-audited when it changes.