RsdoctorCAUTION
AI-friendly build analyzer for Rspack
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文
Rsdoctor is a build analyzer tailored for projects built with Rspack.
Rsdoctor is committed to being a one-stop, intelligent build analyzer that makes the build process transparent, predictable, and optimizable through visualization and smart analysis, helping development teams precisely identify bottlenecks, optimize performance, and improve engineering quality.
For webpack projects, continue using Rsdoctor 1.x or migrate to Rspack. See the migration guide for details.
🔥 Features
- Compilation Visualization: Rsdoctor visualizes the compilation behavior and time consumption, making it easy to view build issues.
- Multiple Analysis Capabilities: Rsdoctor supports build artifact, build-time analysis, and anti-degradation capabilities:
- Build artifact support for resource lists and module dependencies, etc.
- Build-time analysis supports Loader, Plugin, and Resolver building process analysis
- Build rules support duplicate package de
a2c13a5f54c7OBSERVED · 2026-09-25Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add test-helper -- npx -y @scripts/[email protected]
{
"mcpServers": {
"test-helper": {
"command": "npx",
"args": [
"-y",
"@scripts/[email protected]"
]
}
}
}Exposed tools (20)
19 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
--baseline | read | Path to baseline rsdoctor-data.json |
--category | write | Filter bailout modules by cause: cjs, barrel, side-effects, or dynamic-import. |
--code | read | Error code |
--compiler | read | Compiler name from compilers list; required for multi-compiler reports. |
--current | read | Path to current rsdoctor-data.json |
--emitted-only | read | Only include modules attached to emitted assets. |
--filter | read | Comma-separated row fields to keep, e.g. id,path,size,chunks,bailoutReason. |
--id | read | Chunk id |
--level | read | Error level |
--limit | read | Maximum rows to return (default: 100, max: 1000). |
--min-costs | read | Minimum costs threshold (ms) |
--min-total-costs | read | Minimum total costs threshold (ms) |
--modules | read | Comma-separated module ids, paths, or names to query. Defaults to all bailout modules. |
--name | read | Package name |
--page-number | read | Page number (default: 1) |
--page-size | read | Page size (default: 100, max: 1000) |
--path | read | Module name or path |
--sort | read | Sort by sourceSize, parsedSize, or gzipSize. |
--step | read | Execution step: 1 (basic analysis) or 2 (tree-shaking summary). If not specified, executes both. |
array_tool | read | test tool |
Trust audit
CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
function print(tokens: Token[]) {const uri = new URL(url, 'http://127.0.0.1');
apiKey: 'db98c3a0aa060d3aa4b30f49fee02b16', // cspell:disable-line
const hash = createHash('md5')const { RsdoctorRspackPlugin } = require('../../../dist/index');{ name: 'web', path: '../../rsdoctor-report.html' },} from '../../test-kit/index';
'../../fixtures/rsdoctor/manifest.json',
const newPath = path.resolve(__dirname, '../../../');
optionsWithOrigin(target, `http://127.0.0.1:${target.server.port}`),allowOrigin: `http://127.0.0.1:${target.server.port}`,optionsWithOrigin(target, `http://127.0.0.1:${target.server.port + 1}`),allowOrigin: `http://127.0.0.1:${target.server.port + 1}`,eJytWG1z2jgQ/isa3Qegp7GDAffiNL0TNM0xSSbTpplcp+aDYiugYmSPLUgIw3+/sWz8Fiu8JJ1Mx6xWq30erXZXWkESRVRE0Pq1ggERE2jBGeNsRjztdwQRjNgzhVbX6CDoTOZ8GmvCIzhC0PG5oFxAC+of5D8dNJstcPoZrICug0d6HxBn2vd9EYmQBDbP1Gxhw3lE
eJztPYly27iSv5JCzdabqZFIy87prbdxIjvHlrPJ5phsla1VQWRLgkICHACU5LH871uNg5fkI47s7Lzi1CQRcTQajUaju9Fkn5wTTlMg+2QBo4xG30iHzEEqJjjZJ4+CZ3vBDumQSPAxm5D9cxLRaAr4Q59l2G3MElBnSkNKOoQmiVj0RZJApBmfvINUyDOyP6aJgg5J
eJx90E0KwjAQBeC7ZKXQQtK/NFkUxGOIi7ROMWibkBkRrb27CNVWELdveB+PGVjjkJDp3cB60wHTrHaOkILxcVVD6wJsXeftGVjEkEygDTEtZFKIlPMiL7MsehtCFEqM0Swt63FlWoLwB5MyT4sPlohSJQts2Y6rg+t/GkplSTkbnKcLorO9bW+rK9TeNKdMO0+2s3fY
@actions/core, @lynx-js/react, @lynx-js/rspeedy, loader-utils
@arco-design/web-react, @svgr/webpack, @swc/helpers, classnames, less-loader, @testing-library/jest-dom, react-refresh, web-vitals
@arco-design/web-react, @svgr/webpack, @swc/helpers, classnames, less-loader, @testing-library/jest-dom, react-refresh, web-vitals
@arco-design/web-react, @svgr/webpack, @swc/helpers, classnames, less-loader, @testing-library/jest-dom, react-refresh, tsx
@types/node
- Reuse the SDK session and report server, and open the report page only for the first build.
Gates applied: no_behavioural_pass.
a2c13a5f54c7full audit observations/trust-audit/mcp-server/web-infra-dev__rsdoctor.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | a2c13a5f54c7 | CAUTION | B | 82 | first audit |
Questions
What is the Rsdoctor MCP server?
AI-friendly build analyzer for Rspack
What tools does Rsdoctor expose?
20 in total: 19 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Rsdoctor safe to connect to an agent?
With care. The audit graded it B (82/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Rsdoctor need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (a2c13a5f54c7), read on 2026-09-25. The repository is watched and re-audited when it changes.