Atlas / MCP servers / xytom / Coding Tools

Coding ToolsCAUTION

mcp/xytom/coding-tools

Give any AI agent the ability to code

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
2 0r · 2w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
1,158
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 简体中文

Give any AI chat or agent a safe pair of hands on your codebase.

[](https://pypi.org/project/coding-tools-mcp/) [](https://www.npmjs.com/package/coding-tools-mcp) [](https://pypi.org/project/coding-tools-mcp/) [](https://github.com/xyTom/coding-tools-mcp/actions/workflows/compliance.yml) [](https://github.com/xyTom/coding-tools-mcp/actions/workflows/release.yml) [](LICENSE)

Coding Tools MCP is a model-neutral coding runtime served over the Model Context Protocol: file reading and search, structured multi-file patches, command execution, interactive sessions, and git — one server that any MCP client can drive. Claude Desktop, Claude Code, Codex, Cursor, Cline, VS Code, Windsurf, Gemini CLI, or an agent you build yourself gets the default catalog of 18 battle-tested tools, confined to one workspace and gated by permission modes.

[](https://youtu.be/N9lQaXt1eqQ?si=LyEwvzzQF6QjUxR0)

Why people use it

  • It turns a chat app into a coding agent. Claude Desktop — or any MCP

chat client — gets real repo access with the subscription you already have. No extra product required.

  • Safety is the product, not an afterthought. One workspace root per

server. Absolute paths, .. traversal, and symlink escapes are rejected. Permission modes gate network access, shell expansion, inline scripts, and destructive commands. On Linux, [Landlock](docs/security-bound

Read from source at commit 5f15e6e117d0OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add tiny-js-project --env CODING_TOOLS_MCP_AUTH_TOKEN=${CODING_TOOLS_MCP_AUTH_TOKEN} --env TWINE_PASSWORD=${TWINE_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "tiny-js-project": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CODING_TOOLS_MCP_AUTH_TOKEN": "${CODING_TOOLS_MCP_AUTH_TOKEN}",
        "TWINE_PASSWORD": "${TWINE_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (2)

0 read · 2 write · 0 destructive.

ToolRiskDescription
get_coding_tools_sandbox_statuswriteQuery the GitHub Actions workflow run status for a coding-tools-mcp sandbox and optionally probe the fixed MCP tunnel endpoint.
start_coding_tools_sandboxwriteTrigger the GitHub Actions workflow that starts a coding-tools-mcp Docker sandbox and exposes it through Cloudflare Tunnel.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (4 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (16)

MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/desktop-client/mcp_desktop_client/locales/app_zh_CN.qm
app_zh_CN.qm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
coding_tools_mcp/server.py:7046
print(f"OAuth authorize password: {password}", file=sys.stderr)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Makefile:93
--endpoint http://127.0.0.1:$(DOGFOOD_PORT)/mcp \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/desktop-client/mcp_desktop_client/app.py:774
"Local MCP URL: http://127.0.0.1:{port}/mcp",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/compliance/test_mcp_contract.py:768
token = "test-token-remote-mcp"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_desktop_client.py:99
storage.log_dir_for_profile("../../outside")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:71
`http://127.0.0.1:8765/mcp`. Both protocol eras are served on either
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.zh-CN.md:64
`http://127.0.0.1:8765/mcp` 上讲 Streamable HTTP。两代协议在两种 transport
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/desktop-client/README.md:70
- Cloudflare 命名隧道模式下,本地服务地址需要和 Cloudflare Tunnel 的 ingress 目标一致,通常是 `http://127.0.0.1:<本地端口>`
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
coding_tools_mcp/protocol.py:175
return base64.b64decode(payload, validate=True).decode("utf-8")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
coding_tools_mcp/server.py:6845
decoded = base64.b64decode(auth_header[6:]).decode("utf-8")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
coding_tools_mcp/server.py:7050
token_secret = bytes.fromhex(raw_secret)
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/compliance/test_runtime_helpers.py:2322
apply_update_hunks_detailed("alpha\nbeta\ngamma\n", [["-bета", "+delta"]])
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
media/promo-video/package.json
@remotion/cli, react, react-dom, remotion, @types/react, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/quickstart.md:6
curl -fsSL https://raw.githubusercontent.com/xyTom/coding-tools-mcp/main/scripts/install.sh | bash
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/embedding.md:201
| Remote HTTP | POST JSON-RPC to `http://host:8765/mcp` with `Authorization: Bearer <token>` | server lifetime is managed by whoever started it |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 5f15e6e117d0full audit observations/trust-audit/mcp-server/xytom__coding-tools.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-285f15e6e117d0CAUTIONB83first audit
06

Questions

What is the Coding Tools MCP server?

Give any AI agent the ability to code

What tools does Coding Tools expose?

2 in total: 0 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Coding Tools safe to connect to an agent?

With care. The audit graded it B (83/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Coding Tools need?

It reads CODING_TOOLS_MCP_AUTH_TOKEN and TWINE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Coding Tools run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as tiny-js-project at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (5f15e6e117d0), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement