Atlas / MCP servers / web-infra-dev / Rsdoctor

RsdoctorCAUTION

mcp/web-infra-dev/rsdoctor

AI-friendly build analyzer for Rspack

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
20 19r · 1w · 0d
Transport
—
License
MIT
Stars
1,143
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 简体中文

Rsdoctor is a build analyzer tailored for projects built with Rspack.

Rsdoctor is committed to being a one-stop, intelligent build analyzer that makes the build process transparent, predictable, and optimizable through visualization and smart analysis, helping development teams precisely identify bottlenecks, optimize performance, and improve engineering quality.

For webpack projects, continue using Rsdoctor 1.x or migrate to Rspack. See the migration guide for details.

🔥 Features

  • Compilation Visualization: Rsdoctor visualizes the compilation behavior and time consumption, making it easy to view build issues.
  • Multiple Analysis Capabilities: Rsdoctor supports build artifact, build-time analysis, and anti-degradation capabilities:
  • Build artifact support for resource lists and module dependencies, etc.
  • Build-time analysis supports Loader, Plugin, and Resolver building process analysis
  • Build rules support duplicate package de
Read from source at commit a2c13a5f54c7OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add test-helper -- npx -y @scripts/[email protected]
claude-desktop
{
  "mcpServers": {
    "test-helper": {
      "command": "npx",
      "args": [
        "-y",
        "@scripts/[email protected]"
      ]
    }
  }
}
03

Exposed tools (20)

19 read · 1 write · 0 destructive.

ToolRiskDescription
--baselinereadPath to baseline rsdoctor-data.json
--categorywriteFilter bailout modules by cause: cjs, barrel, side-effects, or dynamic-import.
--codereadError code
--compilerreadCompiler name from compilers list; required for multi-compiler reports.
--currentreadPath to current rsdoctor-data.json
--emitted-onlyreadOnly include modules attached to emitted assets.
--filterreadComma-separated row fields to keep, e.g. id,path,size,chunks,bailoutReason.
--idreadChunk id
--levelreadError level
--limitreadMaximum rows to return (default: 100, max: 1000).
--min-costsreadMinimum costs threshold (ms)
--min-total-costsreadMinimum total costs threshold (ms)
--modulesreadComma-separated module ids, paths, or names to query. Defaults to all bailout modules.
--namereadPackage name
--page-numberreadPage number (default: 1)
--page-sizereadPage size (default: 100, max: 1000)
--pathreadModule name or path
--sortreadSort by sourceSize, parsedSize, or gzipSize.
--stepreadExecution step: 1 (basic analysis) or 2 (tree-shaking summary). If not specified, executes both.
array_toolreadtest tool
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (22)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/client/src/components/base/DiffViewer/beautify.ts:351
function print(tokens: Token[]) {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/core/src/sdk/server/apis/data.ts:21
const uri = new URL(url, 'http://127.0.0.1');
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/document/theme/index.tsx:19
apiKey: 'db98c3a0aa060d3aa4b30f49fee02b16', // cspell:disable-line
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/core/src/sdk/sdk/core.ts:81
const hash = createHash('md5')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/cases/doctor-rsbuild/fixtures/port.js:1
const { RsdoctorRspackPlugin } = require('../../../dist/index');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/cases/doctor-rsbuild/multi-environments.test.ts:153
{ name: 'web', path: '../../rsdoctor-report.html' },
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/cases/doctor-rspack/bundle-diff.test.ts:6
} from '../../test-kit/index';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/cases/doctor-rspack/bundle-diff.test.ts:54
'../../fixtures/rsdoctor/manifest.json',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
e2e/cases/doctor-rspack/bundle-diff.test.ts:57
const newPath = path.resolve(__dirname, '../../../');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/core/tests/sdk/server/apis/project.test.ts:106
optionsWithOrigin(target, `http://127.0.0.1:${target.server.port}`),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/core/tests/sdk/server/apis/project.test.ts:109
allowOrigin: `http://127.0.0.1:${target.server.port}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/core/tests/sdk/server/apis/project.test.ts:113
optionsWithOrigin(target, `http://127.0.0.1:${target.server.port + 1}`),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/core/tests/sdk/server/apis/project.test.ts:116
allowOrigin: `http://127.0.0.1:${target.server.port + 1}`,
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
e2e/fixtures/rsdoctor/chunkGraph/0:1
eJytWG1z2jgQ/isa3Qegp7GDAffiNL0TNM0xSSbTpplcp+aDYiugYmSPLUgIw3+/sWz8Fiu8JJ1Mx6xWq30erXZXWkESRVRE0Pq1ggERE2jBGeNsRjztdwQRjNgzhVbX6CDoTOZ8GmvCIzhC0PG5oFxAC+of5D8dNJstcPoZrICug0d6HxBn2vd9EYmQBDbP1Gxhw3lE
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
e2e/fixtures/rsdoctor/configs/0:1
eJztPYly27iSv5JCzdabqZFIy87prbdxIjvHlrPJ5phsla1VQWRLgkICHACU5LH871uNg5fkI47s7Lzi1CQRcTQajUaju9Fkn5wTTlMg+2QBo4xG30iHzEEqJjjZJ4+CZ3vBDumQSPAxm5D9cxLRaAr4Q59l2G3MElBnSkNKOoQmiVj0RZJApBmfvINUyDOyP6aJgg5J
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
e2e/fixtures/rsdoctor/summary/0:1
eJx90E0KwjAQBeC7ZKXQQtK/NFkUxGOIi7ROMWibkBkRrb27CNVWELdveB+PGVjjkJDp3cB60wHTrHaOkILxcVVD6wJsXeftGVjEkEygDTEtZFKIlPMiL7MsehtCFEqM0Swt63FlWoLwB5MyT4sPlohSJQts2Y6rg+t/GkplSTkbnKcLorO9bW+rK9TeNKdMO0+2s3fY
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
e2e/package.json
@actions/core, @lynx-js/react, @lynx-js/rspeedy, loader-utils
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/rspack-banner-minimal/package.json
@arco-design/web-react, @svgr/webpack, @swc/helpers, classnames, less-loader, @testing-library/jest-dom, react-refresh, web-vitals
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/rspack-layers-minimal/package.json
@arco-design/web-react, @svgr/webpack, @swc/helpers, classnames, less-loader, @testing-library/jest-dom, react-refresh, web-vitals
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/rspack-minimal/package.json
@arco-design/web-react, @svgr/webpack, @swc/helpers, classnames, less-loader, @testing-library/jest-dom, react-refresh, tsx
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/rspress-minimal/package.json
@types/node
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
packages/document/docs/en/blog/release/release-note-2_0.mdx:131
- Reuse the SDK session and report server, and open the report page only for the first build.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha a2c13a5f54c7full audit observations/trust-audit/mcp-server/web-infra-dev__rsdoctor.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-25a2c13a5f54c7CAUTIONB82first audit
06

Questions

What is the Rsdoctor MCP server?

AI-friendly build analyzer for Rspack

What tools does Rsdoctor expose?

20 in total: 19 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Rsdoctor safe to connect to an agent?

With care. The audit graded it B (82/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Rsdoctor need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (a2c13a5f54c7), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement