CoolifyBLOCK
MCP server for Coolify — 42 optimized tools for managing self-hosted PaaS through AI assistants
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@masonator/coolify-mcp) [](https://www.npmjs.com/package/@masonator/coolify-mcp) [](https://github.com/StuMason/coolify-mcp/actions/workflows/ci.yml) [](https://github.com/StuMason/coolify-mcp/releases/latest/download/coolify-mcp.mcpb) [](https://registry.modelcontextprotocol.io) [](https://opensource.org/licenses/MIT) [](https://github.com/sponsors/StuMason)
Manage Coolify from Claude, Cursor, or any MCP client: 45 tools for deploying, debugging, and operating your self-hosted PaaS in plain English. Destructive operations ask a human first; secrets stay masked.
📖 [coolify-mcp.stumason.dev](https://coolify-mcp.stumason.dev) · Tool reference · Prompts and resources · Remote / HTTP mode · Fleet · Doctor · Safety and security · Changelog
Install
You need a running Coolify v4 instance and an API token (Coolify → Keys & Tokens → API tokens). Pick one of three ways to run the server.
Claude Desktop, one-click. Download `coolify-mcp.mcpb` and drag it into Settings → Extensions. You are prompted for your Coolify URL and token. No Node install, no JSON editing.
Locally, in any MCP client. Claude Cod
772bf91aad4bOBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add coolify-mcp --env COOLIFY_ACCESS_TOKEN=${COOLIFY_ACCESS_TOKEN} -- npx -y @masonator/[email protected]Exposed tools (8)
7 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
deploy-key | write | Estate deploy key |
echo | read | |
guarded_blocking | read | |
guarded_reentrant | read | |
nbg1 | read | Nuremberg |
saas-platform | read | Main product |
test-project | read | A test project |
updated-app | read | new desc |
Trust audit
BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
escalation) plus `pii`, `bola`, `bfla`, `excessive-agency`, under jailbreak and
description: Coolify MCP — adversarial red team (tool-use injection & exfiltration)
name: 'log injection → secret exfiltration via env_vars',
name: 'log injection → private key exfiltration',
value: 'postgres://user:hunter2@db/prod',
value: 'postgres://user:hunter2@db/prod',
internal_db_url: 'postgres://postgres:nested-db-secret@db:5432/app',
internal_db_url: 'postgres://postgres:db-secret@db:5432/app',
external_db_url: 'postgres://postgres:[email protected]:5432/app',
'-----BEGIN OPENSSH PRIVATE KEY-----\nCANARY-PRIVATE-KEY-91fd3c\n-----END OPENSSH PRIVATE KEY-----',
const pem = '-----BEGIN OPENSSH PRIVATE KEY-----\nabc123\n-----END OPENSSH PRIVATE KEY-----';
mockResponse({ uuid: 'key-uuid', private_key: '-----BEGIN RSA PRIVATE KEY-----' }),private_key: '-----BEGIN RSA PRIVATE KEY-----',
value: '-----BEGIN PRIVATE KEY-----\nMIIE...\n-----END PRIVATE KEY-----',
.lintstagedrc.json
.markdownlint-cli2.jsonc
.mcpbignore
.prettierignore
.prettierignore
expect(() => yaml.load(contents)).not.toThrow();
const spec = yaml.load(fs.readFileSync(SPEC_PATH, 'utf8')) as {const chunk = yaml.load(fs.readFileSync(path.join(CHUNKS_DIR, f), 'utf8')) as {const chunk = yaml.load(fs.readFileSync(path.join(CHUNKS_DIR, f), 'utf8')) as {const schemas = yaml.load(fs.readFileSync(path.join(CHUNKS_DIR, 'schemas.yaml'), 'utf8')) as {fileURLToPath(new URL('../../../README.md', import.meta.url)),Gates applied: instruction_override, no_behavioural_pass.
772bf91aad4bfull audit observations/trust-audit/mcp-server/stumason__coolify.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 772bf91aad4b | BLOCK | F | 45 | first audit |
Questions
What is the Coolify MCP server?
MCP server for Coolify — 42 optimized tools for managing self-hosted PaaS through AI assistants
What tools does Coolify expose?
8 in total: 7 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Coolify safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (45/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Coolify need?
It reads AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CF_ACCESS_CLIENT_SECRET, COOLIFY_ACCESS_TOKEN, COOLIFY_ACCESS_TOKEN_FILE, COOLIFY_TOKEN, EVALS_PASS_THRESHOLD, GOOGLE_AI_API_KEY, GOOGLE_GENERATIVE_AI_API_KEY, MCP_ACCESS_TOKEN_TTL, MCP_OAUTH_STATE_FILE and MCP_REFRESH_TOKEN_TTL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Coolify run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @masonator/coolify-mcp-site at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (772bf91aad4b), read on 2026-09-29. The repository is watched and re-audited when it changes.