Atlas / MCP servers / nickytonline / Dev.to MCP Server

Dev.to MCP ServerCAUTION

mcp/nickytonline/dev-to

A remote Model Context Protocol (MCP) server for interacting with the dev.to public API without requiring authentication.

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
6 6r · 0w · 0d
Transport
streamable-http
License
—
Stars
45
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A remote Model Context Protocol (MCP) server for interacting with the dev.to public API without requiring authentication.

Features

This MCP server provides access to the following dev.to public API endpoints:

  • get_articles - Get articles from dev.to with optional filters (username, tag, state, pagination)
  • get_article - Get a specific article by ID or path
  • get_user - Get user information by ID or username
  • get_tags - Get popular tags from dev.to
  • get_comments - Get comments for a specific article
  • search_articles - Search articles using query parameters

Installation

Using npm

If you want to install and build from source using npm:

npm install
npm run build

Usage

The server runs as a remote HTTP server on port 3000 (or the PORT environment variable) and can be used with any MCP-compatible client.

npm start

The server will be available at http://localhost:3000 for MCP connections.

Development

# Build the project
npm run build

# Watch mode for development
npm run dev

# Linting
npm run lint
npm run lint:fix

# Formatting
npm run format
npm run format:check

Docker

Using Pre-built Image

Pull and run the pre-built Docker image:

# Pull the image
docker pull docker.io/nickytonline/dev-to-mcp:latest

# Run it
docker run -d \
--name dev-to-mcp \
-e NODE_ENV=production \
-e PORT=3000 \
-p 3000:3000 \
--restart unless-stopped \
docker.io/nickytonline/dev-to-mcp:latest

Once it's up, check health status via:

curl -fsS http://127.0.0.1:3000/mcp

The server will be available at http://localhost:3000/mcp for MCP connections.

Building from Source

Build and run the MCP server using Docker:

# Build the Docker image
docker build -t dev-to-mcp .

# Run the container
docker run -p 3000:3000 dev-to-mcp

Docker Compose

Using the pre-built image with Docker Compose:

services:
dev-to-mcp:
Read from source at commit 59723630e999OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add dev-to-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "dev-to-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
get_articleread
get_articlesread
get_commentsread
get_tagsread
get_userread
search_articlesread
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:4
RUN apt-get update && apt-get install -y python3 make g++ git && rm -rf /var/lib/apt/lists/*
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.copilot-instructions.md
.copilot-instructions.md
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:78
curl -fsS http://127.0.0.1:3000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:115
"curl -fsS http://127.0.0.1:${PORT:-3000}/mcp >/dev/null || exit 1",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/express, express, pino, pino-pretty, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 59723630e999full audit observations/trust-audit/mcp-server/nickytonline__dev-to.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0859723630e999CAUTIONB87first audit
06

Questions

What is the Dev.to MCP server?

A remote Model Context Protocol (MCP) server for interacting with the dev.to public API without requiring authentication.

What tools does Dev.to expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Dev.to safe to connect to an agent?

With care. The audit graded it B (87/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Dev.to need?

No credential environment variables were found in its source, so it appears to need none.

How does Dev.to run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as dev-to-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (59723630e999), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement