Atlas / MCP servers / symfony / AI Mate

AI MateCAUTION

mcp/symfony/ai-mate

AI development assistant CLI for Symfony projects

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
MIT
Stars
41
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The Mate component provides a command-line assistant (vendor/bin/mate) that exposes project-aware development tools to coding agents (Claude Code, Codex, Cursor, ...) and developers. Agents run the mate commands directly, so tool schemas are read on demand via --help/tools:inspect instead of being loaded up front. This is a development tool, not intended for production use.

Install it in your project with:

composer require --dev symfony/ai-mate
vendor/bin/mate init
composer dump-autoload

Point your coding agent at the CLI (see the generated mate/AGENT_INSTRUCTIONS.md):

vendor/bin/mate tools:list                          # list available tools
vendor/bin/mate tools:inspect symfony-profiler-list # show a tool's parameters/schema
vendor/bin/mate tools:call symfony-profiler-list --limit=1
vendor/bin/mate resources:read symfony-profiler://profile/

Add --format=json to the tools:*, resources:read, debug:*, skills:list and skills:validate commands for machine-readable output.

The package ships with the symfony/ai-mate-composer-plugin, which automatically refreshes Mate extension discovery after composer install and composer update once the project has been initialized.

Installation

composer require --dev symfony/ai-mate

This repository is a READ-ONLY sub-tree split. See https://github.com/symfony/ai to create issues or submit pull requests.

Resources

send Pull Requests in the main Symfony AI repository

Read from source at commit b13e87998d4cOBSERVED · 2026-10-08
02

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
server-inforeadGet PHP runtime environment details: version, OS, OS family, and loaded extensions
03

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (5)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
resources/mate/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
LOWInventory / provenance · inv.hidden_file · CWE-1104
resources/mate/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
bin/mate.php:14
__DIR__.'/../../../autoload.php',  // Project autoloader
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/Command/InitCommand.php:186
copy(__DIR__.'/../../resources/'.$template, $destination);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/Skill/SkillInstaller.php:395
return '../../'.self::AGENTS_SKILLS_DIR.'/'.$installedName;

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha b13e87998d4cfull audit observations/trust-audit/mcp-server/symfony__ai-mate.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08b13e87998d4cCAUTIONB88first audit
05

Questions

What is the AI Mate MCP server?

AI development assistant CLI for Symfony projects

What tools does AI Mate expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is AI Mate safe to connect to an agent?

With care. The audit graded it B (88/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does AI Mate need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (b13e87998d4c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement