Flutter Lamp
NPM · FLUTTER-LAMP · SCANNED OCT 1
Live runtime data from a running Flutter app: exceptions, logs, network, frames, diagnosis.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 94 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to itsonu/flutter-lamp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 1 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability81
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 2084 tokens (~94/item across 22 items; 22 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage91
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 73% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 22 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 22 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the Flutter Lamp MCP server?
Flutter Lamp runs locally as an npm package, launched with npx -y flutter-lamp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · flutter-lamp
claude mcp add itsonu-flutter-lamp -- npx -y flutter-lamp
{
"mcpServers": {
"itsonu-flutter-lamp": {
"command": "npx",
"args": [
"-y",
"flutter-lamp"
]
}
}
} {
"servers": {
"itsonu-flutter-lamp": {
"command": "npx",
"args": [
"-y",
"flutter-lamp"
]
}
}
} codex mcp add itsonu-flutter-lamp -- npx -y flutter-lamp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"itsonu-flutter-lamp": {
"type": "local",
"command": [
"npx",
"-y",
"flutter-lamp"
],
"enabled": true
}
}
} openclaw mcp add itsonu-flutter-lamp --command npx --arg -y --arg flutter-lamp
mcp_servers:
itsonu-flutter-lamp:
command: "npx"
args: ["-y", "flutter-lamp"] {
"McpServers": {
"itsonu-flutter-lamp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"flutter-lamp"
]
}
}
} assistant mcp add itsonu-flutter-lamp -t stdio -c npx -a -y flutter-lamp
{
"mcpServers": {
"itsonu-flutter-lamp": {
"command": "npx",
"args": [
"-y",
"flutter-lamp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 30 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 29 Sept 26 66
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 1 Oct 2026 · Analysed npm/flutter-lamp@0.21.0
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | itsonu/flutter-lamp |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/itsonu/flutter-lamp/.github/workflows/release.yml@refs/heads/main |
| Rekor log index | 2997524698 |
| Predicate type | SLSA build provenance https://slsa.dev/provenance/v1 |
| Subject digest | sha512:e19b9fb9caed588929bee248e8bdc065a0916a2603badd42b507f2fd0792797f01046dcb4898bc0b7a03912507941d564581035893ed261b073416911 |
Background: How many MCP packages publish verified provenance →
Dependencies 94 packages
| Packages resolved | 94 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
connect_vm Connect to Flutter VM Service ~143
Connect to a running Flutter app's Dart VM Service and start collecting runtime data (logs, exceptions, frames, network). Pass the ws:// or http:// URI printed by `flutter run` (line: 'A Dart VM Service ... is available at:'). NOT purely read-only: enables dart:io HTTP timeline logging on the app so network capture works, and adds the GC stream to the VM timeline recorder so garbage-collection pauses can be correlated with jank. Existing recorded streams are preserved, never replaced.
| Name | Type | Req | Description |
|---|---|---|---|
| uri | string | yes | VM Service URI, e.g. http://127.0.0.1:52719/abcdef=/ or ws://... |
No output schema declared.
No examples provided.
diagnose_performance Diagnose performance ~130
Why the app is janky, not just how much. Returns frame percentiles, the build-vs-raster split, and findings correlating jank against in-flight requests, route transitions and heap growth — each with its own evidence ids, strength and fix. Reports 'healthy' when jank is within normal range and 'unknown' when there are too few frames to tell a pattern from noise. States what it cannot see: no CPU sampling, no widget rebuild counts. GC pauses are captured and correlated, but the strength of that correlation is reported against how much of the window frames actually covered.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
diagnose_runtime Diagnose runtime ~104
Correlate captured runtime evidence into a root-cause diagnosis. Returns status (diagnosed|unknown), summary, rootCause, evidence (each with a citable eventId), a chronological timeline around the root cause, alternativeCauses that also fit, limitations describing what could not be seen, confidence (0-1) with a breakdown of evidence strength / data completeness / alternative strength, and recommended fixes. Status is 'unknown' below 70% rather than a guess.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
ensure_tcp_device Prefer a wireless device transport ~174
Report Android device transports and recommend one, preferring wireless. A `flutter run` started on a USB transport loses its VM Service tunnel when the cable moves; one started on a TCP transport does not. Read-only by default. With promote:true it runs `adb tcpip` and `adb connect` to put a USB-attached device on a TCP transport — that restarts adbd on the device, needs the cable once, and is reversible with `adb usb`. Android-only: reports adbAvailable:false and changes nothing on iOS, desktop or web targets.
| Name | Type | Req | Description |
|---|---|---|---|
| port | integer | – | Device-side TCP port. |
| promote | boolean | – | Put a USB-only device onto a TCP transport. Changes device state. |
| serial | string | – | Which USB device to promote. Defaults to the first promotable one. |
No output schema declared.
No examples provided.
explain_diagnosis Explain a diagnosis ~65
Why diagnose_runtime reached its conclusion: the claim, every cited event resolved back to its full record, the timeline around the root cause, competing explanations, what evidence is missing, and the confidence breakdown. Use to answer 'why do you think that' without inventing reasoning.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
export_session Export the debugging session ~192
The whole session as one versioned JSON artifact: metadata, per-collector health, retention, the captured events, and every diagnosis (runtime, performance, navigation, rebuilds). Use mode 'brief' for the smallest sufficient context — the diagnoses plus only the events their evidence cites — and 'full' to archive everything retained, for a bug report, offline analysis or a regression fixture. Sizes are not close: measured on a ~1,700-event session, 'brief' returned 36kB and 'full' returned 247kB — roughly 62,000 tokens, about a third of a 200k context window, so treat 'full' as something to write to a file rather than read inline. Credentials are already redacted at capture, so nothing here was ever stored raw.
| Name | Type | Req | Description |
|---|---|---|---|
| mode | string | – | 'brief': diagnoses plus only the cited events. 'full': everything retained. |
No output schema declared.
No examples provided.
get_capabilities What this server can observe ~57
Machine-readable capability report: active collectors, every tool with its safety class, what can and cannot be observed on this target, and the current redaction, dashboard and retention configuration. Read this before attempting an operation that may not be supported.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_dashboard_url Get dashboard URL ~47
Return the URL of the live Realtime Runtime Dashboard (a browser UI streaming logs, network, exceptions, frames & memory). Open it in a browser to watch the app alongside the AI.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_exceptions Get runtime exceptions ~53
Flutter framework errors and unhandled VM exceptions, most recent first. Each includes the error summary, offending widget, library, and a reconstructed stack trace (data.stackTrace) when available.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
No output schema declared.
No examples provided.
get_frames Get frame timings ~91
Frame build/raster timings. Set onlyJanky to focus on frames over the frame budget — 16.67ms (60fps) by default, which is an assumption: the VM Service does not report the display refresh rate. Override with FLUTTER_LAMP_FRAME_BUDGET_MS when the target's rate is known.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| onlyJanky | boolean | – | – |
No output schema declared.
No examples provided.
get_logs Get console & structured logs ~87
Console output (Stdout/Stderr) and dart:developer logging, most recent first.
| Name | Type | Req | Description |
|---|---|---|---|
| contains | string | – | Case-insensitive substring filter. |
| limit | integer | – | – |
| minSeverity | string | – | Minimum severity to include. |
| sinceMs | number | – | Only events at/after this epoch-ms timestamp. |
| source | string | – | Restrict to one log source. |
No output schema declared.
No examples provided.
get_memory Get memory usage ~41
Current Dart heap usage for the main isolate (Dart heap in use, capacity, and external/native memory), in MB. Also records a snapshot into runtime history.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_navigation Route history ~86
The current route and recent route transitions, each with how long it was on screen and the exceptions, failed requests and janky frames attributed to it. Use to answer 'which screen is broken' and to scope other evidence to a screen. Network is attributed by overlap, so a request spanning a route change counts for both.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many recent visits to return. |
No output schema declared.
No examples provided.
get_network Get network requests ~48
HTTP requests/responses captured via dart:io profiling (covers Dio & package:http). Fetches the latest profile on demand, then returns completed requests most recent first.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
No output schema declared.
No examples provided.
get_rebuilds Widget rebuild hotspots ~82
Which widgets are rebuilding and how often, resolved to widget name, file and line, with your own code ranked above package code. Use for 'why is this screen slow to build' and to find needless rebuilds. Requires a debug build with widget creation tracking; reports why it is empty otherwise.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many hotspots to return. |
No output schema declared.
No examples provided.
get_selected_widget Get selected widget ~38
The widget currently selected in the Flutter Inspector (via 'select widget mode' in the app/DevTools). Returns null if nothing is selected.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_state_activity State-management activity ~145
How much state-management activity the app is doing and when, plus how often build-heavy frames coincide with it — use with get_rebuilds to answer 'is this rebuild storm driven by state churn'. Counts and timing only: Riverpod sends an app-side buffer offset and provider an element id, neither resolvable to a provider name or value. Counts are NOT transition counts — a provider event means dependents were notified, so one state change in a widget-heavy tree produces many events. Stock Bloc posts nothing itself; a flutter_bloc app appears here only as the provider activity its notifications cause.
| Name | Type | Req | Description |
|---|---|---|---|
| buckets | integer | – | How many of the busiest one-second buckets to return. |
No output schema declared.
No examples provided.
get_timeline Get VM timeline events ~128
Recent VM timeline trace events (build/paint/layout/GC/etc.), most recent first. Requires timeline recording — enable with recordFrom=true (sets Dart, GC, Compiler & Embedder streams) then reproduce the activity. recordFrom=true is NOT read-only: it changes the VM's recording configuration. Check recorderLagMs/stalled in the result: the VM recorder can stall permanently once its buffer fills while still reporting its streams as recorded, so events may be historical rather than current.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| recordFrom | boolean | – | Turn on timeline recording streams before reading. |
No output schema declared.
No examples provided.
get_widget_tree Get widget tree ~55
Snapshot of the running app's widget tree (summary tree from the Flutter Inspector). Use to understand structure, find a widget, or see what is mounted.
| Name | Type | Req | Description |
|---|---|---|---|
| maxDepth | integer | – | How deep to traverse before truncating. |
No output schema declared.
No examples provided.
runtime_health Runtime health snapshot ~73
One compact answer to 'is this app healthy right now'. Returns a verdict (healthy/degraded/failing/no-data) plus exception, network, frame, log and memory summaries with citable event ids, the retention window, and notes about anything that qualifies the numbers. Call this FIRST instead of calling six get_* tools.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
runtime_status Runtime health check ~73
Report connection health, the current debugging session, reconnection state, how many runtime events have been captured by category, and the retention window (per-category capacity, how many events were evicted, and the oldest event still held). Use to confirm the MCP is receiving live data and to know how far back the evidence goes.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
what_changed What changed before an incident ~172
Evidence from the window leading up to a failure, plus a baseline comparison: the incident window measured against the equal window before it, per dimension (exceptions, network volume/failures/latency p50/p95, jank ratio, log errors, memory) with directions new/spiked/increased/decreased and citable evidence. Anchors on the given eventId, or the most recent exception, or the current time. Network uses interval matching, so a request that started before the window but failed inside it still counts. When the baseline predates observation, directions are unknown rather than fabricated.
| Name | Type | Req | Description |
|---|---|---|---|
| eventId | string | – | Anchor on this event (e.g. 'exc_00142'). Defaults to the most recent exception. |
| windowMs | integer | – | How far back to look, in milliseconds. |
No output schema declared.
No examples provided.
What is the Flutter Lamp MCP server?
Flutter Lamp is an MCP server listed in the public MCP registry as io.github.itsonu/flutter-lamp. Live runtime data from a running Flutter app: exceptions, logs, network, frames, diagnosis. This page covers its npm package (flutter-lamp).
Is the Flutter Lamp MCP server safe to use?
Flutter Lamp scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 1 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Flutter Lamp MCP server expose?
Flutter Lamp exposes 22 tools: connect_vm, ensure_tcp_device, runtime_status, get_dashboard_url, get_logs, and 17 more. Their descriptions and schemas cost roughly 2,084 tokens of context every time the server is loaded.
Is the Flutter Lamp MCP server still maintained?
Flutter Lamp is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Flutter Lamp MCP server under?
Flutter Lamp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.