Atlas / MCP servers / normaltusker / Kotlin Android

Kotlin AndroidCAUTION

mcp/normaltusker/kotlin-android

🧠 Kotlin MCP Server for Android app development using OpenAI, Gemini, or OpenRouter. Enables AI-assisted coding via Aider, Gradle build/test integration, Kotlin LSP, and Docker-based portability.

Verdict
CAUTION
Grade
B
Trust score
80 /100
Exposed tools
3 2r · 1w · 0d
Transport
—
License
AGPL-3.0
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive Model Context Protocol (MCP) server that provides AI agents with enterprise-grade access to Kotlin-based Android development projects. This server enables context-aware assistance with advanced security, privacy compliance, AI integration, and comprehensive development tools.

📋 Revision History

Version 2.1 (Current - August 2025)

Enhanced Release: Unified Intelligent Server

🎯 Latest Improvements

  • 🧠 Intelligent Tool Management: All 27 tools now use intelligent proxy system with LSP-like capabilities
  • 🔄 Server Consolidation: Unified into single kotlin_mcp_server.py with enhanced architecture
  • 📁 Clean Architecture: Archived redundant server versions for cleaner project structure
  • ⚡ Enhanced Tool Exposure: Complete tool suite properly exposed through intelligent management system
  • 🛠️ Improved Tool Routing: Smart delegation between native implementations and intelligent proxies

🔧 Architectural Changes

  • Unified Server: Single kotlin_mcp_server.py replaces multiple server versions
  • Intelligent Proxy System: Tools without full implementations use smart proxies with AI enhancement
  • Clean File Structure: Legacy servers archived in archive/legacy-servers/
  • Enhanced Tool Manager: Integration with IntelligentMCPToolManager for advanced capabilities
  • Complete Tool Coverage: All 32 tools properly exposed and functional

📊 Tool Implementation Status

  • Fully Implemented: 6 tools (formatcode, runlint, generatedocs, createcomposecomponent, setupmvvmarchitecture, securityhardening)
  • Legacy Integration: 3 core tools (createkotlinfile, gradlebuild, analyzeproject)
  • Intelligent Proxies: 23 tools with smart fallback implementations
  • Total Available: 32 tools with comprehensive Android development coverage

Version 2.0 (August 2025)

*Major Release: AI-Enhanced Modular Architecture

Read from source at commit f91ffd3dea6cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add kotlin-mcp-server-ts -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "kotlin-mcp-server-ts": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (3)

2 read · 1 write · 0 destructive.

ToolRiskDescription
analyze_projectread
create_kotlin_filewrite
generate_code_with_airead
04

Trust audit

CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMInventory / provenance · inv.binary · CWE-1104
kotlin-sidecar/.gradle/7.6/checksums/checksums.lock
checksums.lock
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
kotlin-sidecar/.gradle/7.6/checksums/md5-checksums.bin
md5-checksums.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
kotlin-sidecar/.gradle/7.6/checksums/sha1-checksums.bin
sha1-checksums.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
kotlin-sidecar/.gradle/7.6/dependencies-accessors/dependencies-accessors.lock
dependencies-accessors.lock
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
kotlin-sidecar/.gradle/7.6/fileChanges/last-build.bin
last-build.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
ci_test_runner.py:96
__import__(package)
LOWInventory / provenance · inv.hidden_file · CWE-1104
.bandit
.bandit
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coveragerc
.coveragerc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tools/security_tools.py:117
encrypted_bytes = base64.b64decode(encrypted_data)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
python-dotenv, pydantic, mcp, typing-extensions, fastmcp, requests, cryptography, bcrypt
Why it matters. 40 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
server/package.json
ajv, ajv-formats, json-schema, @types/node, typescript, jest, @types/jest, @typescript-eslint/eslint-plugin
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:3473
- **admin**: Full access to all tools and configurations

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f91ffd3dea6cfull audit observations/trust-audit/mcp-server/normaltusker__kotlin-android.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f91ffd3dea6cCAUTIONB80first audit
06

Questions

What is the Kotlin Android MCP server?

🧠 Kotlin MCP Server for Android app development using OpenAI, Gemini, or OpenRouter. Enables AI-assisted coding via Aider, Gradle build/test integration, Kotlin LSP, and Docker-based portability.

What tools does Kotlin Android expose?

3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kotlin Android safe to connect to an agent?

With care. The audit graded it B (80/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Kotlin Android need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (f91ffd3dea6c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement