Atlas / MCP servers / vercel / Next.js DevTools

Next.js DevToolsCAUTION

mcp/vercel/next-js-devtools

Next.js Development for Coding Agent

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
4 3r · 1w · 0d
Transport
stdio
License
—
Stars
823
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://npmjs.org/package/next-devtools-mcp)

next-devtools-mcp is a Model Context Protocol (MCP) server that connects coding agents like Claude and Cursor to your running Next.js dev server.

It is a thin connector. It discovers running Next.js 16+ dev servers and proxies their built-in MCP endpoint (/_next/mcp) so agents get live runtime errors, routes, and logs. It also ships two gateways that point agents at tools they run directly: version-accurate docs and the `agent-browser` CLI.

[!NOTE] Docs and migration workflows no longer live in this server. Next.js bundles its own docs at node_modules/next/dist/docs/, and upgrade / Cache Components workflows are distributed as agent skills. See Migrating from 0.3.x.

Requirements

  • Node.js v20.19 or a newer LTS version
  • npm or pnpm
  • Next.js 16+ with a running dev server (for nextjs_index / nextjs_call)

Install

Install for all your coding agents with `add-mcp`:

npx add-mcp next-devtools-mcp@latest

Add -y to skip the prompt and install to all detected agents. Add -g to install globally across all projects.

Or add the config to your MCP client manually:

{
"mcpServers": {
"next-devtools": {
"command": "npx",
"args": ["-y", "next-devtools-mcp@latest"]
}
}
}
[!NOTE] next-devtools-mcp@latest keeps your client on the latest version.

Client-specific setup

Amp

amp mcp add next-devtools -- npx next-devtools-mcp@latest

Or follow Amp's MCP docs with the config above.

Claude Code

Read from source at commit b1aa6aa8e3f0OBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add next-devtools-mcp -- npx -y [email protected]
03

Exposed tools (4)

3 read · 1 write · 0 destructive.

ToolRiskDescription
browser_evalwriteSet up and use browser automation for this project via the agent-browser CLI. This tool does NOT drive the browser itself. It points you at \
nextjs_callreadCall a specific MCP tool on a running Next.js development server. REQUIREMENTS: - Port number of the target Next.js dev server - Tool name to execute - Optional arguments object (if the tool requires parameters) Use
nextjs_docsreadFind the version-accurate Next.js documentation for THIS project. This tool does NOT fetch documentation. Recent Next.js releases ship their full docs inside the installed package at \
nextjs_indexreadDiscover all running Next.js development servers and list their available MCP tools. WHEN TO USE THIS TOOL - Use proactively in these scenarios: 1. **Before implementing ANY changes to the app**: When asked to add, modify, or fix anything in the application: -
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/_internal/nextjs-runtime-manager.ts:65
insecureHttpsAgent = new UndiciAgent({ connect: { rejectUnauthorized: false } })
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
test/unit/browser-eval-gateway.test.ts:26
if (cmd.includes("command -v") || cmd.includes("where ")) return "/usr/local/bin/agent-browser\n"
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
test/unit/browser-eval-gateway.test.ts:53
if (cmd.includes("command -v") || cmd.includes("where ")) return "/usr/local/bin/agent-browser\n"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/e2e/telemetry-tracking.test.ts:6
import { resetMcpTelemetry, getMcpTelemetryUsage } from "../../src/telemetry/mcp-telemetry-tracker.js"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/e2e/telemetry-tracking.test.ts:182
const { mcpTelemetryTracker } = await import("../../src/telemetry/mcp-telemetry-tracker.js")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/e2e/telemetry-tracking.test.ts:198
const { mcpTelemetryTracker } = await import("../../src/telemetry/mcp-telemetry-tracker.js")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/e2e/telemetry-tracking.test.ts:199
const { eventMcpToolUsage, EVENT_MCP_TOOL_USAGE } = await import("../../src/telemetry/telemetry-events.js")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/unit/browser-eval-gateway.test.ts:9
import { handler, metadata } from "../../src/tools/browser-eval.js"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
undici, @anthropic-ai/claude-agent-sdk, @changesets/changelog-github, @changesets/cli, @types/node, dotenv, typescript, vitest
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
test/fixtures/nextjs14-minimal/package.json
react, react-dom, typescript, @types/node, @types/react, @types/react-dom, eslint
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
test/fixtures/nextjs16-minimal/package.json
react, react-dom, typescript, @types/node, @types/react, @types/react-dom
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-09-27 · audit v0.4.1 · source sha b1aa6aa8e3f0full audit observations/trust-audit/mcp-server/vercel__next-js-devtools.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-27b1aa6aa8e3f0CAUTIONB86first audit
06

Questions

What is the Next.js DevTools MCP server?

Next.js Development for Coding Agent

What tools does Next.js DevTools expose?

4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Next.js DevTools safe to connect to an agent?

With care. The audit graded it B (86/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Next.js DevTools need?

It reads NODE_TLS_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Next.js DevTools run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as nextjs16-minimal at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (b1aa6aa8e3f0), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement