Kotlin AndroidCAUTION
🧠 Kotlin MCP Server for Android app development using OpenAI, Gemini, or OpenRouter. Enables AI-assisted coding via Aider, Gradle build/test integration, Kotlin LSP, and Docker-based portability.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A comprehensive Model Context Protocol (MCP) server that provides AI agents with enterprise-grade access to Kotlin-based Android development projects. This server enables context-aware assistance with advanced security, privacy compliance, AI integration, and comprehensive development tools.
📋 Revision History
Version 2.1 (Current - August 2025)
Enhanced Release: Unified Intelligent Server
🎯 Latest Improvements
- 🧠 Intelligent Tool Management: All 27 tools now use intelligent proxy system with LSP-like capabilities
- 🔄 Server Consolidation: Unified into single
kotlin_mcp_server.pywith enhanced architecture - 📁 Clean Architecture: Archived redundant server versions for cleaner project structure
- ⚡ Enhanced Tool Exposure: Complete tool suite properly exposed through intelligent management system
- 🛠️ Improved Tool Routing: Smart delegation between native implementations and intelligent proxies
🔧 Architectural Changes
- Unified Server: Single
kotlin_mcp_server.pyreplaces multiple server versions - Intelligent Proxy System: Tools without full implementations use smart proxies with AI enhancement
- Clean File Structure: Legacy servers archived in
archive/legacy-servers/ - Enhanced Tool Manager: Integration with
IntelligentMCPToolManagerfor advanced capabilities - Complete Tool Coverage: All 32 tools properly exposed and functional
📊 Tool Implementation Status
- Fully Implemented: 6 tools (formatcode, runlint, generatedocs, createcomposecomponent, setupmvvmarchitecture, securityhardening)
- Legacy Integration: 3 core tools (createkotlinfile, gradlebuild, analyzeproject)
- Intelligent Proxies: 23 tools with smart fallback implementations
- Total Available: 32 tools with comprehensive Android development coverage
Version 2.0 (August 2025)
*Major Release: AI-Enhanced Modular Architecture
f91ffd3dea6cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add kotlin-mcp-server-ts -- npx -y [email protected]
{
"mcpServers": {
"kotlin-mcp-server-ts": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_project | read | |
create_kotlin_file | write | |
generate_code_with_ai | read |
Trust audit
CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
checksums.lock
md5-checksums.bin
sha1-checksums.bin
dependencies-accessors.lock
last-build.bin
__import__(package)
.bandit
.coveragerc
.flake8
encrypted_bytes = base64.b64decode(encrypted_data)
python-dotenv, pydantic, mcp, typing-extensions, fastmcp, requests, cryptography, bcrypt
ajv, ajv-formats, json-schema, @types/node, typescript, jest, @types/jest, @typescript-eslint/eslint-plugin
- **admin**: Full access to all tools and configurations
Gates applied: no_behavioural_pass.
f91ffd3dea6cfull audit observations/trust-audit/mcp-server/normaltusker__kotlin-android.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f91ffd3dea6c | CAUTION | B | 80 | first audit |
Questions
What is the Kotlin Android MCP server?
🧠 Kotlin MCP Server for Android app development using OpenAI, Gemini, or OpenRouter. Enables AI-assisted coding via Aider, Gradle build/test integration, Kotlin LSP, and Docker-based portability.
What tools does Kotlin Android expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Kotlin Android safe to connect to an agent?
With care. The audit graded it B (80/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Kotlin Android need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (f91ffd3dea6c), read on 2026-10-08. The repository is watched and re-audited when it changes.