Dev.to MCP ServerCAUTION
A remote Model Context Protocol (MCP) server for interacting with the dev.to public API without requiring authentication.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A remote Model Context Protocol (MCP) server for interacting with the dev.to public API without requiring authentication.
Features
This MCP server provides access to the following dev.to public API endpoints:
- get_articles - Get articles from dev.to with optional filters (username, tag, state, pagination)
- get_article - Get a specific article by ID or path
- get_user - Get user information by ID or username
- get_tags - Get popular tags from dev.to
- get_comments - Get comments for a specific article
- search_articles - Search articles using query parameters
Installation
Using npm
If you want to install and build from source using npm:
npm install npm run build
Usage
The server runs as a remote HTTP server on port 3000 (or the PORT environment variable) and can be used with any MCP-compatible client.
npm start
The server will be available at http://localhost:3000 for MCP connections.
Development
# Build the project npm run build # Watch mode for development npm run dev # Linting npm run lint npm run lint:fix # Formatting npm run format npm run format:check
Docker
Using Pre-built Image
Pull and run the pre-built Docker image:
# Pull the image docker pull docker.io/nickytonline/dev-to-mcp:latest # Run it docker run -d \ --name dev-to-mcp \ -e NODE_ENV=production \ -e PORT=3000 \ -p 3000:3000 \ --restart unless-stopped \ docker.io/nickytonline/dev-to-mcp:latest
Once it's up, check health status via:
curl -fsS http://127.0.0.1:3000/mcp
The server will be available at http://localhost:3000/mcp for MCP connections.
Building from Source
Build and run the MCP server using Docker:
# Build the Docker image docker build -t dev-to-mcp . # Run the container docker run -p 3000:3000 dev-to-mcp
Docker Compose
Using the pre-built image with Docker Compose:
services: dev-to-mcp:
59723630e999OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add dev-to-mcp -- npx -y [email protected]
{
"mcpServers": {
"dev-to-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_article | read | |
get_articles | read | |
get_comments | read | |
get_tags | read | |
get_user | read | |
search_articles | read |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
RUN apt-get update && apt-get install -y python3 make g++ git && rm -rf /var/lib/apt/lists/*
streamable-http
.copilot-instructions.md
curl -fsS http://127.0.0.1:3000/mcp
"curl -fsS http://127.0.0.1:${PORT:-3000}/mcp >/dev/null || exit 1",@modelcontextprotocol/sdk, @types/express, express, pino, pino-pretty, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Gates applied: no_behavioural_pass, no_license.
59723630e999full audit observations/trust-audit/mcp-server/nickytonline__dev-to.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 59723630e999 | CAUTION | B | 87 | first audit |
Questions
What is the Dev.to MCP server?
A remote Model Context Protocol (MCP) server for interacting with the dev.to public API without requiring authentication.
What tools does Dev.to expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Dev.to safe to connect to an agent?
With care. The audit graded it B (87/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Dev.to need?
No credential environment variables were found in its source, so it appears to need none.
How does Dev.to run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as dev-to-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (59723630e999), read on 2026-10-08. The repository is watched and re-audited when it changes.