Node.js DebuggerCAUTION
๐ MCP Node.js debugger
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server that gives Cursor or Claude Code access to Node.js at runtime to help you debug: `@hyperdrive-eng/mcp-nodejs-debugger`.
Demo
Cursor
https://github.com/user-attachments/assets/c193a17e-b0e6-4c51-82aa-7f3f0de17e1a
Claude Code
https://github.com/user-attachments/assets/adb7321b-3a6a-459b-a5c9-df365710d4d8
Quick start
Cursor
- Add to Cursor (
~/.cursor/mcp.json)
+ {
+ "mcpServers": {
+ "nodejs-debugger": {
+ "command": "npx",
+ "args": ["@hyperdrive-eng/mcp-nodejs-debugger"]
+ }
+ }
+ }- Run a Node.js server in debug mode (i.e. with the
--inspectflat)
node --inspect {file.js}- Ask Cursor to debug your Node.js server at runtime
Claude Code
- Add to Claude Code
claude mcp add nodejs-debugger npx @hyperdrive-eng/mcp-nodejs-debugger
- Start Claude Code
claude โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ โ โป Welcome to Claude Code research preview! โ โ โ โ /help for help โ โ โ โ Found 1 MCP server (use /mcp for status) โ โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
- Run a Node.js server in debug mode (i.e. with the
--inspectflat)
# In another terminal
node --inspect {file.js}- Ask Claude Code to debug your Node.js server at ru
c497ae3be069OBSERVED ยท 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source โ not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-nodejs-debugger -- npx -y @hyperdrive-eng/[email protected]
{
"mcpServers": {
"mcp-nodejs-debugger": {
"command": "npx",
"args": [
"-y",
"@hyperdrive-eng/[email protected]"
]
}
}
}Exposed tools (13)
11 read ยท 1 write ยท 1 destructive. Blast radius: 1 tool can delete or overwrite โ an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
continue | read | Continues code execution |
delete_breakpoint | destructive | Deletes a specified breakpoint |
evaluate | read | Evaluates a JavaScript expression in the current context |
get_console_output | read | Gets the most recent console output from the debugged process |
get_location | read | Gets the current execution location when paused |
inspect_variables | read | Inspects variables in current scope |
list_breakpoints | read | Lists all active breakpoints |
nodejs_inspect | read | Executes JavaScript code in the debugged process |
retry_connect | read | Manually triggers a reconnection attempt to the Node.js debugger |
set_breakpoint | write | Sets a breakpoint at specified line and file |
step_into | read | Steps into function calls |
step_out | read | Steps out of current function |
step_over | read | Steps over to the next line of code |
Trust audit
CAUTIONgrade B ยท trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (6)
const response = await fetch(`http://127.0.0.1:${this.port}/json`);\"mongodb+srv://cooluser:[email protected]/local_library?retryWr
[log] Connection string (masked): mongodb+srv://cooluser:[email protected]/local_library?retryWri
delete_breakpoint
@modelcontextprotocol/sdk, node-fetch, ws, zod
Gates applied: no_behavioural_pass, no_license.
c497ae3be069full audit observations/trust-audit/mcp-server/workbackai__node-js-debugger-2.json ยท Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | c497ae3be069 | CAUTION | B | 81 | first audit |
Questions
What is the Node.js Debugger MCP server?
๐ MCP Node.js debugger
What tools does Node.js Debugger expose?
13 in total: 11 read-only, 1 that write, and 1 that can delete or overwrite (delete_breakpoint). Every one is listed on this page with its risk.
Is Node.js Debugger safe to connect to an agent?
With care. The audit graded it B (81/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Node.js Debugger need?
No credential environment variables were found in its source, so it appears to need none.
How does Node.js Debugger run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @hyperdrive-eng/mcp-nodejs-debugger at 0.2.2.
How current is this page?
The grade is for one exact copy of the source (c497ae3be069), read on 2026-10-03. The repository is watched and re-audited when it changes.