Atlas / MCP servers / stumason / Coolify

CoolifyBLOCK

mcp/stumason/coolify

MCP server for Coolify — 42 optimized tools for managing self-hosted PaaS through AI assistants

Verdict
BLOCK
Grade
F
Trust score
45 /100
Exposed tools
8 7r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
603
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@masonator/coolify-mcp) [](https://www.npmjs.com/package/@masonator/coolify-mcp) [](https://github.com/StuMason/coolify-mcp/actions/workflows/ci.yml) [](https://github.com/StuMason/coolify-mcp/releases/latest/download/coolify-mcp.mcpb) [](https://registry.modelcontextprotocol.io) [](https://opensource.org/licenses/MIT) [](https://github.com/sponsors/StuMason)

Manage Coolify from Claude, Cursor, or any MCP client: 45 tools for deploying, debugging, and operating your self-hosted PaaS in plain English. Destructive operations ask a human first; secrets stay masked.

📖 [coolify-mcp.stumason.dev](https://coolify-mcp.stumason.dev) · Tool reference · Prompts and resources · Remote / HTTP mode · Fleet · Doctor · Safety and security · Changelog

Install

You need a running Coolify v4 instance and an API token (Coolify → Keys & Tokens → API tokens). Pick one of three ways to run the server.

Claude Desktop, one-click. Download `coolify-mcp.mcpb` and drag it into Settings → Extensions. You are prompted for your Coolify URL and token. No Node install, no JSON editing.

Locally, in any MCP client. Claude Cod

Read from source at commit 772bf91aad4bOBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add coolify-mcp --env COOLIFY_ACCESS_TOKEN=${COOLIFY_ACCESS_TOKEN} -- npx -y @masonator/[email protected]
03

Exposed tools (8)

7 read · 1 write · 0 destructive.

ToolRiskDescription
deploy-keywriteEstate deploy key
echoread
guarded_blockingread
guarded_reentrantread
nbg1readNuremberg
saas-platformreadMain product
test-projectreadA test project
updated-appreadnew desc
04

Trust audit

BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
evals/README.md:153
escalation) plus `pii`, `bola`, `bfla`, `excessive-agency`, under jailbreak and
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
evals/redteam.yaml:18
description: Coolify MCP — adversarial red team (tool-use injection & exfiltration)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
evals/src/injection/prompt-injection.eval.ts:92
name: 'log injection → secret exfiltration via env_vars',
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
evals/src/injection/prompt-injection.eval.ts:133
name: 'log injection → private key exfiltration',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/__tests__/audit.test.ts:48
value: 'postgres://user:hunter2@db/prod',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/__tests__/audit.test.ts:267
value: 'postgres://user:hunter2@db/prod',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/__tests__/coolify-client.test.ts:291
internal_db_url: 'postgres://postgres:nested-db-secret@db:5432/app',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/__tests__/coolify-client.test.ts:496
internal_db_url: 'postgres://postgres:db-secret@db:5432/app',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/__tests__/coolify-client.test.ts:497
external_db_url: 'postgres://postgres:[email protected]:5432/app',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
evals/src/fixture/data.ts:30
'-----BEGIN OPENSSH PRIVATE KEY-----\nCANARY-PRIVATE-KEY-91fd3c\n-----END OPENSSH PRIVATE KEY-----',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/__tests__/coolify-client.test.ts:622
const pem = '-----BEGIN OPENSSH PRIVATE KEY-----\nabc123\n-----END OPENSSH PRIVATE KEY-----';
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/__tests__/coolify-client.test.ts:652
mockResponse({ uuid: 'key-uuid', private_key: '-----BEGIN RSA PRIVATE KEY-----' }),
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/__tests__/coolify-client.test.ts:656
private_key: '-----BEGIN RSA PRIVATE KEY-----',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/__tests__/coolify-client.test.ts:2850
value: '-----BEGIN PRIVATE KEY-----\nMIIE...\n-----END PRIVATE KEY-----',
LOWInventory / provenance · inv.hidden_file · CWE-1104
.lintstagedrc.json
.lintstagedrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint-cli2.jsonc
.markdownlint-cli2.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
evals/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/__tests__/split-openapi-chunks.test.ts:99
expect(() => yaml.load(contents)).not.toThrow();
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/__tests__/split-openapi-chunks.test.ts:105
const spec = yaml.load(fs.readFileSync(SPEC_PATH, 'utf8')) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/__tests__/split-openapi-chunks.test.ts:123
const chunk = yaml.load(fs.readFileSync(path.join(CHUNKS_DIR, f), 'utf8')) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/__tests__/split-openapi-chunks.test.ts:139
const chunk = yaml.load(fs.readFileSync(path.join(CHUNKS_DIR, f), 'utf8')) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/__tests__/split-openapi-chunks.test.ts:148
const schemas = yaml.load(fs.readFileSync(path.join(CHUNKS_DIR, 'schemas.yaml'), 'utf8')) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
evals/src/contract/toolsnaps.test.ts:46
fileURLToPath(new URL('../../../README.md', import.meta.url)),

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 772bf91aad4bfull audit observations/trust-audit/mcp-server/stumason__coolify.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-29772bf91aad4bBLOCKF45first audit
06

Questions

What is the Coolify MCP server?

MCP server for Coolify — 42 optimized tools for managing self-hosted PaaS through AI assistants

What tools does Coolify expose?

8 in total: 7 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Coolify safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (45/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Coolify need?

It reads AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CF_ACCESS_CLIENT_SECRET, COOLIFY_ACCESS_TOKEN, COOLIFY_ACCESS_TOKEN_FILE, COOLIFY_TOKEN, EVALS_PASS_THRESHOLD, GOOGLE_AI_API_KEY, GOOGLE_GENERATIVE_AI_API_KEY, MCP_ACCESS_TOKEN_TTL, MCP_OAUTH_STATE_FILE and MCP_REFRESH_TOKEN_TTL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Coolify run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @masonator/coolify-mcp-site at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (772bf91aad4b), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement