Atlas / MCP servers / mage-os-lab / Magento 2 LSP

Magento 2 LSPSAFE

mcp/mage-os-lab/magento-2-lsp

Language Server (LSP) and MCP server for Magento 2 - provides go-to-definition, references, and rename across PHP, XML, and layout files.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
11 11r · 0w · 0d
Transport
stdio
License
MIT
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Magento 2 tooling for editors and AI agents. This package includes two servers that share the same index and understanding of Magento's configuration system:

  • LSP server - for your editor. Go-to-definition, find-references, diagnostics, and code lenses across XML and PHP.
  • MCP server - for AI coding agents. Exposes merged Magento configuration that agents can't get by reading individual files.

Both are installed from the same repo but configured separately - the LSP in your editor, the MCP in your AI agent. They can be used together or independently.

Rationale

Agents write the code, but you still review it - and jumping between XML and PHP with a keystroke beats grepping through config files. AI agents need the opposite: not navigation, but the merged result of Magento's multi-module configuration that no single file contains.

LSP Server

Works alongside Intelephense or Phpactor - this LSP handles the Magento-specific connections that generic PHP tooling can't see.

  • Auto-complete as you type. Context-aware completions for FQCNs, event names, config paths, ACL resource IDs, template identifiers, layout handles, block/container names, and DB table/column names across XML config files and PHP.
  • Navigate XML config like code. Go-to-definition and find-references work across di.xml, events.xml, system.xml, and layout XML - linking them to the PHP classes, templates, and config paths they reference.
  • Trace the plugin chain. See which plugins intercept a method, jump from a beforeSave plugin to the method it wraps, and see plugin counts directly in your editor via code lenses.
  • Follow config paths. Jump from scopeConfig->getValue('payment/account/active') in PHP straight to the ` declaration in system.xml`, and find all PHP files using a config path.
  • Catch errors as you type. Broken class references, missing templates, duplicate plugin names, and invalid model classes are flagged with
Read from source at commit 2a1617443d2dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add magento2-lsp -- npx -y @mage-os/[email protected]
claude-desktop
{
  "mcpServers": {
    "magento2-lsp": {
      "command": "npx",
      "args": [
        "-y",
        "@mage-os/[email protected]"
      ]
    }
  }
}
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
magento_get_class_contextreadGet the full Magento context for a PHP class file: resolves the FQCN from the file path,
magento_get_class_hierarchyreadGet the class hierarchy for a PHP class: its parent class, implemented interfaces,
magento_get_db_schemareadGet the merged database table schema from all db_schema.xml files across modules.
magento_get_di_configreadGet the complete DI configuration for a PHP class/interface after Magento config merging.
magento_get_event_observersreadGet all observers for a Magento event, or all events handled by an observer class.
magento_get_module_overviewreadGet an overview of what a Magento module declares: preferences, plugins, virtual types,
magento_get_plugins_for_methodreadGet all plugins (before/after/around interceptors) for a specific method on a class,
magento_get_template_overridesreadFind theme overrides and layout XML usages for a template identifier.
magento_rescan_projectreadRescan the Magento project to rebuild the MCP server cache. Call this after creating
magento_resolve_classreadResolve a PHP class: given a file path, returns its FQCN; given a FQCN, returns its file path.
magento_search_symbolsreadSearch for Magento symbols by name: ALL PHP classes/interfaces (not just DI-configured ones),
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

LOWInventory / provenance · inv.hidden_file · CWE-1104
editors/vscode/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
test/fixtures/magento-root/.magento2-lsp-symbols-cache.json
.magento2-lsp-symbols-cache.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/cache/symbolsCache.ts:56
return crypto.createHash('md5').update(data).digest('hex');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/cache/indexCache.test.ts:5
import { IndexCache } from '../../src/cache/indexCache';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/cache/indexCache.test.ts:6
import { DiReference, VirtualTypeDecl } from '../../src/indexer/types';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/cache/symbolsCache.test.ts:5
import { SymbolsCache, computePsr4Hash, computeTemplateSourceHash } from '../../src/cache/symbolsCache';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/handlers/codeAction.test.ts:10
import { handleCodeAction, handleCodeActionResolve } from '../../src/handlers/codeAction';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/handlers/codeAction.test.ts:11
import { DiIndex } from '../../src/index/diIndex';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
editors/vscode/package.json
vscode-languageclient, @types/vscode, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, chokidar, sax, vscode-languageserver, vscode-languageserver-textdocument, vscode-uri, @types/node, @types/sax
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/editor-vscode.md:31
Server settings are passed via `initializationOptions`. To configure them, the VS Code extension would need to forward settings — this is not yet wired in the extension. In the meantime, you can use e
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2a1617443d2dfull audit observations/trust-audit/mcp-server/mage-os-lab__magento-2-lsp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082a1617443d2dSAFEB89first audit
06

Questions

What is the Magento 2 LSP MCP server?

Language Server (LSP) and MCP server for Magento 2 - provides go-to-definition, references, and rename across PHP, XML, and layout files.

What tools does Magento 2 LSP expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Magento 2 LSP safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Magento 2 LSP need?

No credential environment variables were found in its source, so it appears to need none.

How does Magento 2 LSP run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mage-os/magento2-lsp at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (2a1617443d2d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement