SwaggerBLOCK
MCP wrapper for Swagger/OpenAPI definitions
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server that connects to a Swagger specification and helps an AI to build all the required models to generate a MCP server for that service.
Features
- Downloads a Swagger specification and stores it locally for faster reference.
- Returns a list of all the endpoints and their HTTP Methods and descriptions
- Returns a list of all the models
- Returns a model
- Returns service to connect to the end point
- Returns MCP function definitions
- Generates complete MCP tool definitions with full schema information
- Includes AI-specific instructions in tool descriptions
Prerequisites
- Node.js (v14 or higher)
- npm or yarn
Installation
- Clone the repository:
git clone https://github.com/readingdancer/swagger-mcp.git cd swagger-mcp
- Install dependencies:
npm install
- Create a
.envfile based on the.env.examplefile:
cp .env.example .env
- Update the
.envfile.
Configuration
Edit the .env file to configure the application:
PORT: The port on which the server will run (default: 3000)NODE_ENV: The environment (development, production, test)LOG_LEVEL: Logging level (info, error, debug)
Usage
Building the application
Build the application:
npm run build
This will compile the TypeScript code ready to be used as an MCP Server
Running as an MCP Server
To run as an MCP server for integration with Cursor and other applications:
node build/index.js
You can also provide a Swagger URL via CLI argument:
node build/index.js --swagger-url="https://petstore.swagger.io/v2/swagger.json"
Or using the alternative format:
node build/index.js --swaggerUrl="https://petstore.swagger.io/v2/swagger.json"
Note: The CLI --swagger-url argument takes priority over the swaggerFilePath parameter in tool calls. If both are provided, the CLI argument will be used.
Using the MCP Inspector
To run the MCP inspector for debugging:
npm run
06c2fab40182OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add swagger-mcp -- npx -y [email protected]
{
"mcpServers": {
"swagger-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (14)
12 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add-endpoint | write | Guide through the process of adding a new endpoint using Swagger MCP tools |
endpointPath | read | Path of the endpoint to implement (e.g., /pets/{id}) |
generateEndpointToolCode | read | Generates TypeScript code for an MCP tool definition based on a Swagger endpoint. Priority: CLI --swagger-url > swaggerFilePath parameter. |
generateModelCode | read | Generates TypeScript code for a model from the Swagger definition. Priority: CLI --swagger-url > swaggerFilePath parameter. |
getPet | read | Get a pet by ID |
getSwaggerDefinition | read | Fetches a Swagger/OpenAPI definition from a URL and saves it locally. IMPORTANT: After calling this tool, you will receive a response containing a |
httpMethod | destructive | HTTP method of the endpoint (e.g., GET, POST, PUT, DELETE) |
listEndpointModels | read | Lists all models used by a specific endpoint from the Swagger definition. Priority: CLI --swagger-url > swaggerFilePath parameter. |
listEndpoints | read | Lists all endpoints from the Swagger definition including their HTTP methods and descriptions. Priority: CLI --swagger-url > swaggerFilePath parameter. |
project.FeatureOrder | read | Simple model (FeatureOrder) |
swaggerUrl | read | URL of the Swagger definition (optional if already configured) |
task.Request | read | Complex model (Task Request) |
task.Task | read | Core model (Task) |
version | read | Returns the current version number of the Swagger MCP Server. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
swaggerData = yaml.load(response.data);
return yaml.load(swaggerContent);
httpMethod
const packageJsonPath = path.resolve(__dirname, "../../package.json");
@modelcontextprotocol/sdk, @types/js-yaml, @types/minimist, axios, dotenv, js-yaml, minimist, winston
Gates applied: no_behavioural_pass.
06c2fab40182full audit observations/trust-audit/mcp-server/vizioz__swagger-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 06c2fab40182 | BLOCK | D | 69 | first audit |
Questions
What is the Swagger MCP server?
MCP wrapper for Swagger/OpenAPI definitions
What tools does Swagger expose?
14 in total: 12 read-only, 1 that write, and 1 that can delete or overwrite (httpMethod). Every one is listed on this page with its risk.
Is Swagger safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Swagger need?
No credential environment variables were found in its source, so it appears to need none.
How does Swagger run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as swagger-mcp at 1.0.1.
How current is this page?
The grade is for one exact copy of the source (06c2fab40182), read on 2026-10-06. The repository is watched and re-audited when it changes.