coding-tools-mcp
An MCP server that lets an agent read files, search code and run commands in a workspace
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Runs shell commands in the workspace
- Can expose remote network access to the workstation
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/coding-tools-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio --env 'MCP_API_KEY=<your MCP_API_KEY>' coding-tools-mcp -- nodeOr add to the file .mcp.json, in the project
{
"mcpServers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"coding-tools-mcp","type":"stdio","command":"node","args":[],"env":{"MCP_API_KEY":"<your MCP_API_KEY>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"coding-tools-mcp": {
"type": "stdio",
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add coding-tools-mcp --env 'MCP_API_KEY=<your MCP_API_KEY>' -- nodeOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.coding-tools-mcp]
command = "node"
args = []
env = { MCP_API_KEY = "<your MCP_API_KEY>" }If the file already exists, append the block to the end.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
gemini mcp add -s user -e 'MCP_API_KEY=<your MCP_API_KEY>' coding-tools-mcp nodeOr add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"coding-tools-mcp": {
"type": "local",
"command": [
"node"
],
"environment": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"coding-tools-mcp": {
"command": "node",
"args": [],
"env": {
"MCP_API_KEY": "<your MCP_API_KEY>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
MCP_API_KEYsecret, required- API key for authenticating with the MCP server
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add an MCP server with the command uvx coding-tools-mcp --stdio --workspace /path/to/repo (or replace uvx with npx). For HTTP drop --stdio.
Other ways from the author
uvx coding-tools-mcp --stdio --workspace /path/to/repoYou can replace uvx with npx for the Node toolchain.
This is third-party code. Review the repository files before installing.
What it does
The server gives any MCP-capable agent a basic set of coding tools: reading files, searching the repository and running commands in a chosen workspace. It runs via uvx or npx over stdio, or over Streamable HTTP on a local port. It supports several MCP protocol revisions, and remote access can use bearer tokens and OAuth. There is a Docker sandbox mode and a secure-tunnel option to drive a workstation from anywhere.
Who it is for. For developers who want to give an agent access to code and commands through a single MCP server.
Good fit when
- You want the agent to read files and search the repository
- You want to run commands in a specific workspace through MCP
- You need HTTP access to a workstation with a token
Not a fit when
- The agent already has built-in file and command tools
- You cannot let the agent run commands in the project
Example request
Find every place in the repository that calls the auth function and show the filesLimitations
The server runs commands and reads files in the workspace, so access should be scoped. Remote mode needs a tunnel and authorization set up. Running it requires uv or Node installed.
How to disable. Remove the coding-tools server from the agent's MCP config.
MCP
- Transport
- stdio, http
- Authentication
- not required
Security check
- Runs shell commands in the workspace
- Can expose remote network access to the workstation
README in short
The README describes an MCP server with file-reading, code-search and command-execution tools installed via uvx or npx. By default it speaks stdio, and without the --stdio flag it serves Streamable HTTP on a local port, supporting several protocol revisions. For remote access it shows bearer tokens, OAuth and a secure tunnel, plus a Docker sandbox mode. Apache-2.0 licensed.
FAQ
Should I run it with Python or Node?
Both are equivalent: uvx for the Python toolchain and npx for Node, with the same config JSON.
Can it work remotely?
Yes, it supports Streamable HTTP with bearer tokens and OAuth, and external access uses a secure tunnel.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything