Atlas / MCP servers / vizioz / Swagger

SwaggerBLOCK

mcp/vizioz/swagger-4

MCP wrapper for Swagger/OpenAPI definitions

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
14 12r · 1w · 1d
Transport
stdio
License
MIT
Stars
165
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server that connects to a Swagger specification and helps an AI to build all the required models to generate a MCP server for that service.

Features

  • Downloads a Swagger specification and stores it locally for faster reference.
  • Returns a list of all the endpoints and their HTTP Methods and descriptions
  • Returns a list of all the models
  • Returns a model
  • Returns service to connect to the end point
  • Returns MCP function definitions
  • Generates complete MCP tool definitions with full schema information
  • Includes AI-specific instructions in tool descriptions

Prerequisites

  • Node.js (v14 or higher)
  • npm or yarn

Installation

  1. Clone the repository:
git clone https://github.com/readingdancer/swagger-mcp.git
cd swagger-mcp
  1. Install dependencies:
npm install
  1. Create a .env file based on the .env.example file:
cp .env.example .env
  1. Update the .env file.

Configuration

Edit the .env file to configure the application:

  • PORT: The port on which the server will run (default: 3000)
  • NODE_ENV: The environment (development, production, test)
  • LOG_LEVEL: Logging level (info, error, debug)

Usage

Building the application

Build the application:

npm run build

This will compile the TypeScript code ready to be used as an MCP Server

Running as an MCP Server

To run as an MCP server for integration with Cursor and other applications:

node build/index.js

You can also provide a Swagger URL via CLI argument:

node build/index.js --swagger-url="https://petstore.swagger.io/v2/swagger.json"

Or using the alternative format:

node build/index.js --swaggerUrl="https://petstore.swagger.io/v2/swagger.json"

Note: The CLI --swagger-url argument takes priority over the swaggerFilePath parameter in tool calls. If both are provided, the CLI argument will be used.

Using the MCP Inspector

To run the MCP inspector for debugging:

npm run 
Read from source at commit 06c2fab40182OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add swagger-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "swagger-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (14)

12 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add-endpointwriteGuide through the process of adding a new endpoint using Swagger MCP tools
endpointPathreadPath of the endpoint to implement (e.g., /pets/{id})
generateEndpointToolCodereadGenerates TypeScript code for an MCP tool definition based on a Swagger endpoint. Priority: CLI --swagger-url > swaggerFilePath parameter.
generateModelCodereadGenerates TypeScript code for a model from the Swagger definition. Priority: CLI --swagger-url > swaggerFilePath parameter.
getPetreadGet a pet by ID
getSwaggerDefinitionreadFetches a Swagger/OpenAPI definition from a URL and saves it locally. IMPORTANT: After calling this tool, you will receive a response containing a
httpMethoddestructiveHTTP method of the endpoint (e.g., GET, POST, PUT, DELETE)
listEndpointModelsreadLists all models used by a specific endpoint from the Swagger definition. Priority: CLI --swagger-url > swaggerFilePath parameter.
listEndpointsreadLists all endpoints from the Swagger definition including their HTTP methods and descriptions. Priority: CLI --swagger-url > swaggerFilePath parameter.
project.FeatureOrderreadSimple model (FeatureOrder)
swaggerUrlreadURL of the Swagger definition (optional if already configured)
task.RequestreadComplex model (Task Request)
task.TaskreadCore model (Task)
versionreadReturns the current version number of the Swagger MCP Server.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/utils/swaggerLoader.ts:88
swaggerData = yaml.load(response.data);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/utils/swaggerLoader.ts:134
return yaml.load(swaggerContent);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
httpMethod
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/version.ts:32
const packageJsonPath = path.resolve(__dirname, "../../package.json");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/js-yaml, @types/minimist, axios, dotenv, js-yaml, minimist, winston
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 06c2fab40182full audit observations/trust-audit/mcp-server/vizioz__swagger-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0606c2fab40182BLOCKD69first audit
06

Questions

What is the Swagger MCP server?

MCP wrapper for Swagger/OpenAPI definitions

What tools does Swagger expose?

14 in total: 12 read-only, 1 that write, and 1 that can delete or overwrite (httpMethod). Every one is listed on this page with its risk.

Is Swagger safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Swagger need?

No credential environment variables were found in its source, so it appears to need none.

How does Swagger run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as swagger-mcp at 1.0.1.

How current is this page?

The grade is for one exact copy of the source (06c2fab40182), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement