Coding ToolsCAUTION
Give any AI agent the ability to code
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文
Give any AI chat or agent a safe pair of hands on your codebase.
[](https://pypi.org/project/coding-tools-mcp/) [](https://www.npmjs.com/package/coding-tools-mcp) [](https://pypi.org/project/coding-tools-mcp/) [](https://github.com/xyTom/coding-tools-mcp/actions/workflows/compliance.yml) [](https://github.com/xyTom/coding-tools-mcp/actions/workflows/release.yml) [](LICENSE)
Coding Tools MCP is a model-neutral coding runtime served over the Model Context Protocol: file reading and search, structured multi-file patches, command execution, interactive sessions, and git — one server that any MCP client can drive. Claude Desktop, Claude Code, Codex, Cursor, Cline, VS Code, Windsurf, Gemini CLI, or an agent you build yourself gets the default catalog of 18 battle-tested tools, confined to one workspace and gated by permission modes.
[](https://youtu.be/N9lQaXt1eqQ?si=LyEwvzzQF6QjUxR0)
Why people use it
- It turns a chat app into a coding agent. Claude Desktop — or any MCP
chat client — gets real repo access with the subscription you already have. No extra product required.
- Safety is the product, not an afterthought. One workspace root per
server. Absolute paths, .. traversal, and symlink escapes are rejected. Permission modes gate network access, shell expansion, inline scripts, and destructive commands. On Linux, [Landlock](docs/security-bound
5f15e6e117d0OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add tiny-js-project --env CODING_TOOLS_MCP_AUTH_TOKEN=${CODING_TOOLS_MCP_AUTH_TOKEN} --env TWINE_PASSWORD=${TWINE_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"tiny-js-project": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CODING_TOOLS_MCP_AUTH_TOKEN": "${CODING_TOOLS_MCP_AUTH_TOKEN}",
"TWINE_PASSWORD": "${TWINE_PASSWORD}"
}
}
}
}Exposed tools (2)
0 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_coding_tools_sandbox_status | write | Query the GitHub Actions workflow run status for a coding-tools-mcp sandbox and optionally probe the fixed MCP tunnel endpoint. |
start_coding_tools_sandbox | write | Trigger the GitHub Actions workflow that starts a coding-tools-mcp Docker sandbox and exposes it through Cloudflare Tunnel. |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (16)
app_zh_CN.qm
print(f"OAuth authorize password: {password}", file=sys.stderr)--endpoint http://127.0.0.1:$(DOGFOOD_PORT)/mcp \
"Local MCP URL: http://127.0.0.1:{port}/mcp",token = "test-token-remote-mcp"
storage.log_dir_for_profile("../../outside")`http://127.0.0.1:8765/mcp`. Both protocol eras are served on either
`http://127.0.0.1:8765/mcp` 上讲 Streamable HTTP。两代协议在两种 transport
- Cloudflare 命名隧道模式下,本地服务地址需要和 Cloudflare Tunnel 的 ingress 目标一致,通常是 `http://127.0.0.1:<本地端口>`
return base64.b64decode(payload, validate=True).decode("utf-8")decoded = base64.b64decode(auth_header[6:]).decode("utf-8")token_secret = bytes.fromhex(raw_secret)
apply_update_hunks_detailed("alpha\nbeta\ngamma\n", [["-bета", "+delta"]])@remotion/cli, react, react-dom, remotion, @types/react, typescript
curl -fsSL https://raw.githubusercontent.com/xyTom/coding-tools-mcp/main/scripts/install.sh | bash
| Remote HTTP | POST JSON-RPC to `http://host:8765/mcp` with `Authorization: Bearer <token>` | server lifetime is managed by whoever started it |
Gates applied: no_behavioural_pass.
5f15e6e117d0full audit observations/trust-audit/mcp-server/xytom__coding-tools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 5f15e6e117d0 | CAUTION | B | 83 | first audit |
Questions
What is the Coding Tools MCP server?
Give any AI agent the ability to code
What tools does Coding Tools expose?
2 in total: 0 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Coding Tools safe to connect to an agent?
With care. The audit graded it B (83/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Coding Tools need?
It reads CODING_TOOLS_MCP_AUTH_TOKEN and TWINE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Coding Tools run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as tiny-js-project at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (5f15e6e117d0), read on 2026-09-28. The repository is watched and re-audited when it changes.