NextCAUTION
Help LLMs to understand your Next apps better
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Demo
Features
get-routers-info
The Router Analyzer scans your Next.js app directory structure and extracts information about all API routes, including:
- API paths
- HTTP methods (GET, POST, PUT, DELETE, etc.)
- Request parameters
- Status codes
- Request and response schemas
Installation
npm install next-mcp-server
Or if you're using pnpm:
pnpm add next-mcp-server
Usage
Command Line
You can run the mcp server directly:
npm run build node dist/index.js
Docker
docker build -t mcp/next -f Dockerfile . docker run mcp/next -d
For cursor usage, define a mcp.json under ~/.cursor or [projectDir]/.cursor
{
"mcpServers": {
"next.js": {
"url": "http://localhost:4857/sse"
}
}
}The url here could vary based on your .env settings within the project.
Output
The tool generates detailed information about each route:
[
{
"filePath": "/path/to/your/app/api/test/route.ts",
"implementationPath": "/path/to/your/app/api/test/route.ts",
"apiPath": "/api/test",
"handlers": [
{
"method": "GET",
"path": "/api/test",
"functionSignature": "export async function GET(request: Request)",
"description": "Get test data",
"parameters": [],
"statusCodes": [200]
},
{
"method": "POST",
"path": "/api/test",
"functionSignature": "export async function POST(request: Request)",
"description": "Create test data",
"parameters": [],
"requestBodySchema": "{ name: string }",
"statusCodes": [201, 400]
}
]
}
]Development
To run tests:
npm run test
To run the mcp server locally:
npm run build node dist/index.js
To run it from node_modules after npm i:
node node_modules/next-mcp-server/dist/index.js
16f2b4a3fdecOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add playground -- npx -y playground
{
"mcpServers": {
"playground": {
"command": "npx",
"args": [
"-y",
"playground"
]
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Books | read | Books and publications |
Electronics | read | Electronic devices and accessories |
Laptop | read | High-performance laptop |
get_routers_info | read | Get Pages details in the Next.js app. |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (5)
.env
.env
.env.local
express, zod, zod-to-json-schema, @jest/globals, @types/express, @types/jest, @types/node, jest
next, react, react-dom, @types/node, @types/react, @types/react-dom, autoprefixer, postcss
Gates applied: no_behavioural_pass.
16f2b4a3fdecfull audit observations/trust-audit/mcp-server/vertile-ai__next.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 16f2b4a3fdec | CAUTION | B | 85 | first audit |
Questions
What is the Next MCP server?
Help LLMs to understand your Next apps better
What tools does Next expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Next safe to connect to an agent?
With care. The audit graded it B (85/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Next need?
No credential environment variables were found in its source, so it appears to need none.
How does Next run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as playground.
How current is this page?
The grade is for one exact copy of the source (16f2b4a3fdec), read on 2026-10-07. The repository is watched and re-audited when it changes.