Atlas / MCP servers / shunseven / Mocxykit

MocxykitCAUTION

mcp/shunseven/mocxykit

This is an Frontend development service middleware that can be used with webpack and vite. Its main function is to visualize the configuration, manage http(s)-proxy, and mock data.

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
1 1r · 0w · 0d
Transport
sse · streamable-http
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

  • 中文
  • English

前端开发服务的中间件,主要用于代理请求和 MOCK 数据,可用于所有 webpack,vite和其它所有前端开发服务启动服务的开发项目, 此中间件应仅用于开发。

主要功能:

  • 代理请求和 MOCK数据
  • 可视化的管理 MOCK 数据及代理功能
  • 代理支持全局代理和某一个 URL 的自定义代理
  • 可随时切换某一个URL进行代理转发或 MOCK 数据
  • 可通过不同的入参,返回不同的MOCK 数据
  • 可以快速把最近的请求返回的数据,存为 MOCK 数据
  • 支持 faker 随机MOCK数据生成
  • 支持多环境变量管理,随时切换环境变量
  • 支持 Ngrok 公网访问
  • 支持自动同步ApiFox文档及生成的mock数据
  • 支持 MCP 协议,让 AI 编程时,自动获取 MOCK 数据或最近浏览器请求的数据及文档
  • 内置API请求工具,可直接发送和测试API请求

入门

首先,安装模块:

npm install mocxykit --save-dev

示例

用法

Webpack >= 5.0

修改 webpack.config.js

const { WebpackProxyMockPlugin } = require('mocxykit')
module.exports = {
//...
devServer: {
...
},
plugins: [
// 在 wepback 中会在插件里获取 devServer 并注入代理,devServer 不需要再配制
new WebpackProxyMockPlugin({
apiRule: '/api/*',
lang: 'zh'
})
]
};

Webpack <= 4+

// vue.config.js 或者其它 webpack config 文件 
const { proxyMockMiddleware } = require('mocxykit')

module.exports = {
//...
devServer: {
before(app) {
app.use(proxyMockMiddleware({
apiRule: '/api/*',
lang: 'en'
}))
}
}
};

vite

// vite.config.js
import { defineConfig } from 'vite'
import { viteProxyMockPlugin } from 'mocxykit'

export default defineConfig({
plugins: [
viteProxyMockPlugin({
apiRule: '/api/*',
lang: 'zh',
buttonPosition: 'bottom', // 可选:'top'(顶部)、'middle'(中间)、'bottom'(底部) 或坐标格式如 '100,100'
})
]
})

vue.config.js

const proxyMockPlugin = new WebpackProxyMockPlugin({
apiRule: '/api/*',
lang: 'zh'
})
module.exports = {
//...
devServer: {
setupMiddlewares: (middlewares, devServer) => {
// 在vue中,因 vue-cli在webpack 编译完成后,才注入 devServer,插件中获取不到 devServer配制,需要手动注入代理中间件
proxyMockPlugin.setupDevServer(devServer.app);
return middlewares;
}
},
plugins: [
proxyMockPlugin
]
};

express

Read from source at commit 264e04df7596OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mocxykit -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mocxykit": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
getDataread获取数据, 获取mcp数据
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
main/mockProxy/proxy/certificate/certificate.p12
certificate.p12
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/components/proxy/proxy.jsx:178
<Input size='middle' style={{width: '300px'}} placeholder="http://127.0.0.1:8800" />
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
sse,streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
main/mockProxy/common/apiManageTool.ts:2
import { ApiFoxApiTreeItem, ApiFoxDataSchema, ApiFoxApiDetailResponse, ApiFoxApiDetailsResponse, getApiDetails } from '../../api/fox-api';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
main/mockProxy/viewRequest/viewRequest.ts:5
import { envUpdateEmitter } from "../../index";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
main/mockProxy/viewRequest/viewRequest.ts:656
const foxApi = await import('../../api/fox-api');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
main/mockProxy/viewRequest/viewRequest.ts:685
const foxApi = await import('../../api/fox-api');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
main/mockProxy/viewRequest/viewRequest.ts:717
const foxApi = await import('../../api/fox-api');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@eslint/js, @faker-js/faker, @modelcontextprotocol/sdk, @types/express, @types/react, @types/react-dom, antd, axios
Why it matters. 32 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 264e04df7596full audit observations/trust-audit/mcp-server/shunseven__mocxykit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08264e04df7596CAUTIONB84first audit
06

Questions

What is the Mocxykit MCP server?

This is an Frontend development service middleware that can be used with webpack and vite. Its main function is to visualize the configuration, manage http(s)-proxy, and mock data.

What tools does Mocxykit expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mocxykit safe to connect to an agent?

With care. The audit graded it B (84/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mocxykit need?

No credential environment variables were found in its source, so it appears to need none.

How does Mocxykit run?

It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as mocxykit at 2.11.0.

How current is this page?

The grade is for one exact copy of the source (264e04df7596), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement