Atlas / MCP servers / sveltejs / Svelte Agent Core

Svelte Agent CoreBLOCK

mcp/sveltejs/svelte-agent-core

The official svelte MCP for all your agentic needs.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
6 6r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
330
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Repo for the official Svelte MCP server.

Dev setup instructions

pnpm i
cp apps/mcp-remote/.env.example apps/mcp-remote/.env
pnpm dev
  1. Set the VOYAGEAPIKEY for embeddings support
[!NOTE] Currently to prevent having a bunch of Timeout logs on vercel we shut down the SSE channel immediately. This means that we can't use server.log and we are not sending list-changed notifications. We can use elicitation and sampling since those are sent on the same stream of the POST request

Local dev tools

MCP inspector

pnpm run inspect

Then visit http://localhost:6274/

  • Transport type: Streamable HTTP
  • http://localhost:5173/mcp

Database inspector

pnpm run db:studio

https://local.drizzle.studio/

Read from source at commit 587683a5cef6OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp -- npx -y @sveltejs/[email protected]
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
Svelte-Doc-SectionreadA single documentation section
get-documentationreadRetrieves full documentation content for Svelte 5 or SvelteKit sections. Supports flexible search by title (e.g.,
list-sectionsreadLists all available Svelte 5 and SvelteKit documentation sections in a structured format. Each section includes a
playground-link-uireadUI resource for the Svelte Playground widget
svelte-autofixerreadGiven a svelte component or module returns a list of suggestions to fix any issues it has. This tool MUST be used whenever the user is asking to write svelte code before sending the code back to the user
svelte-taskreadUse this Prompt to ask for any svelte related task. It will automatically instruct the LLM on how to best use the autofixer and how to query for documentation pages.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (10)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/opencode/update.js:161
exec(`npm view ${package_json.name} version`, (_, version) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/mcp-server/src/mcp/icons/index.ts:11
src: 'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAACvdJREFUeJztXQuQVMUVHT5GCYmSDwaVMhQWmpSRRIEkJqmdFVQCRuRjCiVq8MMGKKTYGESEREAFhI2i
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cocoignore
.cocoignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cocominify
.cocominify
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/mcp/autofixers/add-autofixers-issues.test.ts:3
import { base_runes } from '../../constants.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/mcp/autofixers/add-autofixers-issues.ts:1
import { parse } from '../../parse/parse.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/mcp/autofixers/add-autofixers-issues.ts:2
import { walk } from '../../mcp/autofixers/ast/walk.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/mcp/autofixers/visitors/imported-runes.ts:1
import { base_runes } from '../../../constants.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/mcp/autofixers/visitors/index.ts:4
import type { ParseResult } from '../../../parse/parse.js';

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 587683a5cef6full audit observations/trust-audit/mcp-server/sveltejs__svelte-agent-core.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06587683a5cef6BLOCKD69first audit
06

Questions

What is the Svelte Agent Core MCP server?

The official svelte MCP for all your agentic needs.

What tools does Svelte Agent Core expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Svelte Agent Core safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Svelte Agent Core need?

It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Svelte Agent Core run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @sveltejs/opencode at 0.1.16.

How current is this page?

The grade is for one exact copy of the source (587683a5cef6), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement