Svelte5SAFE
A specialized Model Context Protocol (MCP) server for Svelte 5 frontend development
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A specialized Model Context Protocol (MCP) server for Svelte 5 frontend development, providing curated knowledge, code examples, and intelligent assistance for modern Svelte development with runes, snippets, and enhanced reactivity.
Features
🔍 Searchable Resources
- Knowledge Base: Curated Q&A covering Svelte 5 concepts, runes, and best practices
- Code Examples: Searchable collection of Svelte 5 patterns and component implementations
🛠️ Intelligent Tools
search_knowledge- Find explanations and conceptssearch_examples- Discover code patterns and implementationsgenerate_with_context- Create components using curated patternsaudit_with_rules- Review code against Svelte 5 best practicesexplain_concept- Get detailed explanations with examples
📝 Smart Prompts
generate-component- Generate modern Svelte 5 componentsaudit-svelte5-code- Audit code for optimization opportunitiesexplain-concept- Detailed concept explanationssearch-patterns- Find specific implementation patterns
Installation
# Clone and setup git clone cd svelte5-mcp-server # Install dependencies npm install # Build the server npm run build # Start the server npm start
Project Structure
svelte5-mcp-server/ ├── src/ │ └── index.ts # Main MCP server implementation ├── data/ │ ├── svelte_5_knowledge.json # Curated Q&A knowledge base │ └── svelte_5_patterns.json # Code examples and patterns ├── package.json ├── tsconfig.json ├── example system prompt # Svelte 5 specific system prompt (quite strict, adjust for your own preferences) └── README.md
Usage with Claude Desktop
Add to your Claude Desktop configuration:
{
"mcpServers": {
"svelte5": {
"command": "node",
"args": ["/path/to/svelte5-mcp-server/dist/index.js"],
"env": {}
}
}
}Usage Examples
🔍 Search Knowledge
To
b026fd647036OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add svelte5-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"svelte5-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (17)
16 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
audit-svelte5-code | read | Audit Svelte 5 code for best practices and optimization opportunities |
audit_with_rules | read | Audit Svelte 5 code against best practices and patterns |
code | read | Svelte 5 code to audit |
concept | read | Svelte 5 concept to explain (e.g., |
context | read | Additional context or requirements |
description | write | Description of the component to create |
explain-concept | read | Explain Svelte 5 concepts with detailed examples and comparisons |
explain_concept | read | Get detailed explanations of Svelte 5 concepts with examples |
features | read | Comma-separated list of features to include |
focus | read | Focus area: performance, accessibility, best-practices, or all |
generate-component | read | Generate a Svelte 5 component with modern patterns |
generate_with_context | read | Generate Svelte 5 components using knowledge context |
level | read | Detail level: basic, intermediate, or advanced |
pattern | read | Pattern or feature to search for |
search-patterns | read | Search for specific Svelte 5 patterns and implementations |
search_examples | read | Search Svelte 5 code examples and patterns |
search_knowledge | read | Search the Svelte 5 knowledge base for concepts, explanations, and Q&A |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
@modelcontextprotocol/sdk, better-sqlite3, zod, @types/better-sqlite3, @types/node, typescript
svelte5-knowledge.db
Gates applied: no_behavioural_pass, no_license.
b026fd647036full audit observations/trust-audit/mcp-server/studentofjs__svelte5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b026fd647036 | SAFE | B | 89 | first audit |
Questions
What is the Svelte5 MCP server?
A specialized Model Context Protocol (MCP) server for Svelte 5 frontend development
What tools does Svelte5 expose?
17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Svelte5 safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Svelte5 need?
No credential environment variables were found in its source, so it appears to need none.
How does Svelte5 run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as svelte5-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (b026fd647036), read on 2026-10-07. The repository is watched and re-audited when it changes.