Atlas / MCP servers / priyankark / A11y

A11yBLOCK

mcp/priyankark/a11y

An MCP (Model Context Protocol) server for performing accessibility audits on webpages using axe-core. Use the results in an agentic loop with your favorite AI assistants (Amp/Cline/Cursor/GH Copilot) and let them fix a11y issues for you!

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MPL-2.0
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server for performing accessibility audits on webpages using axe-core. Use the results in an agentic loop with your favorite AI assistants (Cline/Cursor/GH Copilot) and let them fix a11y issues for you!

Features

  • Perform detailed accessibility audits on any webpage
  • Get a summary of accessibility issues
  • Filter audits by specific WCAG criteria
  • Include HTML snippets in the results for easier debugging

Installation

# Install globally
npm install -g a11y-mcp

# Or use directly with npx
npx a11y-mcp

Configuration

To use this MCP server with Cline, you need to add it to your MCP settings configuration file.

MCP configuration

Add the following to the mcpServers object:

{
"mcpServers": {
"a11y": {
"command": "npx",
"args": ["a11y-mcp"],
"disabled": false,
"autoApprove": []
}
}
}

Available Tools

audit_webpage

Performs a detailed accessibility audit on a webpage.

Parameters:

  • url (required): URL of the webpage to audit
  • includeHtml (optional): Whether to include HTML snippets in the results (default: false)
  • tags (optional): Array of specific accessibility tags to check (e.g., wcag2a, wcag2aa, wcag21a, best-practice)

Example:

Use the a11y MCP server to audit example.com for accessibility issues

get_summary

Gets a summary of accessibility issues for a webpage.

Parameters:

  • url (required): URL of the webpage to audit

Example:

Give me an accessibility summary of example.com

Example Usage

Once configured, you can ask Claude to use the MCP server to perform accessibility audits:

  1. "Can you check example.com for accessibility issues?"
  2. "Audit my website at https://mywebsite.com for WC
Read from source at commit f66354f3b2b9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add a11y-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "a11y-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
audit_webpagereadPerform an accessibility audit on a webpage
get_summaryreadGet a summary of accessibility issues for a webpage
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/network.js:39
if (['metadata.google.internal', 'metadata.goog'].includes(hostname)) {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/index.js:121
args: [`--proxy-server=http://127.0.0.1:${proxy.port}`,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/index.js:219
args: [`--proxy-server=http://127.0.0.1:${proxy.port}`,
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/network.test.mjs:9
for (const ip of ['10.0.0.1', '172.16.0.1', '192.168.1.1', '169.254.169.254', '::ffff:169.254.169.254', 'fc00::1', 'fe80::1', '0.0.0.0', '100.100.100.200', '224.0.0.1']) assert.equal(isAllowedAddress(
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/network.test.mjs:13
await assert.rejects(resolveTarget('metadata.google.internal.'));
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/network.test.mjs:29
if (req.url === '/redirect') { res.writeHead(302, { location: 'http://169.254.169.254/latest/meta-data' }); res.end(); }
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/network.test.mjs:42
const socket = net.connect(proxy.port, '127.0.0.1', () => socket.write('CONNECT 169.254.169.254:443 HTTP/1.1\r\nHost: 169.254.169.254:443\r\n\r\n'));
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/network.test.mjs:29
if (req.url === '/redirect') { res.writeHead(302, { location: 'http://169.254.169.254/latest/meta-data' }); res.end(); }
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/smoke.mjs:24
const blocked = await client.callTool({ name: 'audit_webpage', arguments: { url: 'http://169.254.169.254/' } });
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@axe-core/puppeteer, @modelcontextprotocol/sdk, axe-core, ipaddr.js, puppeteer
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f66354f3b2b9full audit observations/trust-audit/mcp-server/priyankark__a11y.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f66354f3b2b9BLOCKD69first audit
06

Questions

What is the A11y MCP server?

An MCP (Model Context Protocol) server for performing accessibility audits on webpages using axe-core. Use the results in an agentic loop with your favorite AI assistants (Amp/Cline/Cursor/GH Copilot) and let them fix a11y issues for you!

What tools does A11y expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is A11y safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does A11y need?

No credential environment variables were found in its source, so it appears to need none.

How does A11y run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as a11y-mcp at 1.1.0.

How current is this page?

The grade is for one exact copy of the source (f66354f3b2b9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement