Next.js DevToolsCAUTION
Next.js Development for Coding Agent
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://npmjs.org/package/next-devtools-mcp)
next-devtools-mcp is a Model Context Protocol (MCP) server that connects coding agents like Claude and Cursor to your running Next.js dev server.
It is a thin connector. It discovers running Next.js 16+ dev servers and proxies their built-in MCP endpoint (/_next/mcp) so agents get live runtime errors, routes, and logs. It also ships two gateways that point agents at tools they run directly: version-accurate docs and the `agent-browser` CLI.
[!NOTE] Docs and migration workflows no longer live in this server. Next.js bundles its own docs at node_modules/next/dist/docs/, and upgrade / Cache Components workflows are distributed as agent skills. See Migrating from 0.3.x.Requirements
- Node.js v20.19 or a newer LTS version
- npm or pnpm
- Next.js 16+ with a running dev server (for
nextjs_index/nextjs_call)
Install
Install for all your coding agents with `add-mcp`:
npx add-mcp next-devtools-mcp@latest
Add -y to skip the prompt and install to all detected agents. Add -g to install globally across all projects.
Or add the config to your MCP client manually:
{
"mcpServers": {
"next-devtools": {
"command": "npx",
"args": ["-y", "next-devtools-mcp@latest"]
}
}
}[!NOTE] next-devtools-mcp@latest keeps your client on the latest version.Client-specific setup
Amp
amp mcp add next-devtools -- npx next-devtools-mcp@latest
Or follow Amp's MCP docs with the config above.
Claude Code
b1aa6aa8e3f0OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add next-devtools-mcp -- npx -y [email protected]
Exposed tools (4)
3 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
browser_eval | write | Set up and use browser automation for this project via the agent-browser CLI. This tool does NOT drive the browser itself. It points you at \ |
nextjs_call | read | Call a specific MCP tool on a running Next.js development server. REQUIREMENTS: - Port number of the target Next.js dev server - Tool name to execute - Optional arguments object (if the tool requires parameters) Use |
nextjs_docs | read | Find the version-accurate Next.js documentation for THIS project. This tool does NOT fetch documentation. Recent Next.js releases ship their full docs inside the installed package at \ |
nextjs_index | read | Discover all running Next.js development servers and list their available MCP tools. WHEN TO USE THIS TOOL - Use proactively in these scenarios: 1. **Before implementing ANY changes to the app**: When asked to add, modify, or fix anything in the application: - |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
insecureHttpsAgent = new UndiciAgent({ connect: { rejectUnauthorized: false } }).prettierignore
if (cmd.includes("command -v") || cmd.includes("where ")) return "/usr/local/bin/agent-browser\n"if (cmd.includes("command -v") || cmd.includes("where ")) return "/usr/local/bin/agent-browser\n"import { resetMcpTelemetry, getMcpTelemetryUsage } from "../../src/telemetry/mcp-telemetry-tracker.js"const { mcpTelemetryTracker } = await import("../../src/telemetry/mcp-telemetry-tracker.js")const { mcpTelemetryTracker } = await import("../../src/telemetry/mcp-telemetry-tracker.js")const { eventMcpToolUsage, EVENT_MCP_TOOL_USAGE } = await import("../../src/telemetry/telemetry-events.js")import { handler, metadata } from "../../src/tools/browser-eval.js"undici, @anthropic-ai/claude-agent-sdk, @changesets/changelog-github, @changesets/cli, @types/node, dotenv, typescript, vitest
react, react-dom, typescript, @types/node, @types/react, @types/react-dom, eslint
react, react-dom, typescript, @types/node, @types/react, @types/react-dom
Gates applied: no_behavioural_pass, no_license.
b1aa6aa8e3f0full audit observations/trust-audit/mcp-server/vercel__next-js-devtools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | b1aa6aa8e3f0 | CAUTION | B | 86 | first audit |
Questions
What is the Next.js DevTools MCP server?
Next.js Development for Coding Agent
What tools does Next.js DevTools expose?
4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Next.js DevTools safe to connect to an agent?
With care. The audit graded it B (86/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Next.js DevTools need?
It reads NODE_TLS_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Next.js DevTools run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as nextjs16-minimal at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (b1aa6aa8e3f0), read on 2026-09-27. The repository is watched and re-audited when it changes.