Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Komodo MCP Server

NPM · KOMODO-MCP-SERVER · 2 COMPONENTS · SCANNED AUG 3

MCP server for Komodo - manage Docker containers, servers, stacks, and deployments via AI

+53 this week 78 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security79
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known high-severity CVE affects @opentelemetry/propagator-jaeger 2.8.0, reached via mcp-server-framework > @opentelemetry/sdk-node > @opentelemetry/propagator-jaeger. A fixed version is available. View diagnostics → Fail
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (176 of 184), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to MP-Tool/komodo-mcp-server). View diagnostics → Pass
  • Clear OSI-approved license (GPL-3.0).Pass
  • Actively maintained (last published 41 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability77
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 6981 tokens (~99/item across 70 items; 70 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · komodo-mcp-server

# add to Claude Code
claude mcp add mp-tool-komodo-mcp-server -- npx -y komodo-mcp-server
# add to Codex CLI
codex mcp add mp-tool-komodo-mcp-server -- npx -y komodo-mcp-server
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "mp-tool-komodo-mcp-server": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "komodo-mcp-server"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add mp-tool-komodo-mcp-server --command npx --arg -y --arg komodo-mcp-server
# ~/.hermes/config.yaml
mcp_servers:
  mp-tool-komodo-mcp-server:
    command: "npx"
    args: ["-y", "komodo-mcp-server"]
// mcp.json
{
  "mcpServers": {
    "mp-tool-komodo-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "komodo-mcp-server"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +4
    • Stability: unverified → 0.27 functional
  • 2 Aug 26 +38
    • Known CVEs: unverified → fail security
    • Provenance: unverified → pass security
    • Install scripts: unverified → pass security
    • Malware scan: unverified → pass security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • The attested source repository moved: MP-Tool/komodo-mcp-server security
    • Capabilities: pass → unverified functional
    • Tool coverage: 100 → unverified functional
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Licence: GPL-3.0 functional
  • 1 Aug 26 +31
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • Security disclosure: unverified → fail functional
    • MCP protocol: unverified → pass functional
    • Tool coverage: unverified → 100 functional
  • 31 Jul 26 −3
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −82
    • Provenance: pass → unverified security
    • Malware scan: pass → unverified security
    • Known CVEs: fail → unverified security
    • Install scripts: pass → unverified security
    • CVE-2026-59892 no longer affects this package security
    • The attested source repository moved: MP-Tool/komodo-mcp-server security
    • Maintenance: pass → unverified functional
    • License: pass → unverified functional
    • Tool coverage: 100 → unverified functional
    • Licence: GPL-3.0 functional
  • 29 Jul 26 +12
    • Schema quality: unverified → excellent functional
  • 28 Jul 26 +53
    • CVE-2026-59892 affects this package: high security
    • Known CVEs: unverified → fail security
    • Install scripts: unverified → pass security
    • Provenance: unverified → pass security
    • The attested source repository moved: MP-Tool/komodo-mcp-server security
    • License: unverified → pass functional
    • Tool coverage: unverified → 100 functional
    • Maintenance: unverified → pass functional
    • First check of Tool coverage: 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: unverified functional
    • First check of Schema quality: pass functional
    • First check of Schema quality: fail functional
    • Licence: GPL-3.0 functional
  • 26 Jul 26 25

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
MP-Tool/komodo-mcp-server
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/MP-Tool/komodo-mcp-server/.github/workflows/publish-npm.yml@refs/heads/main
Rekor log index:
1913549996
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:872ac58c7ad32da5b481c68069b5775b35ef489a055faa58ddc28774ff3f84d387492cc6c5292334ededeae2f7fd938e94aa3dde7996d26c26dd2c844
Discovery method:
attestation_endpoint
Vulnerabilities 1 finding
ID CVE Severity Vector Fix available
GHSA-45rx-2jwx-cxfr CVE-2026-59892 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes
Dependencies 176 packages

176 packages in the resolved dependency tree · 172 deprecated · 41 stale · 1 without a linked repository.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 70 exposed · ~6,981 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
komodo_stack_action ~116

Lifecycle action on a Compose stack: deploy (up), pull, start, restart, pause, unpause, stop, destroy (down — removes containers). destroy is destructive; config preserved.

NameTypeReqDescription
actionstringyesLifecycle action: deploy (compose up / re-deploy), pull (pull latest images), start (compose start), restart (stop+start), pause/unpause (freeze/resume processes), stop (compose stop), destroy (compo…
stackstringyesStack ID or name
NameTypeReqDescription
actionstringyesAction name that was executed (start, stop, deploy, prune, ...)
resource_idstringyesTarget resource ID or name
resource_typestringyesTarget resource type (container, deployment, stack, server)
serverstringTarget server, when the action runs against a host
statusstringyesUpdate status reported by Komodo (Complete, InProgress, Queued, ...)
successbooleanyesWhether the action completed successfully
versionstringResulting version string, when the action produces one (e.g. deploy)

No examples provided.

komodo_stack_apply ~187

Create or update a Docker Compose stack in Komodo (PATCH-style). action="create": new stack. Required: name. Recommended: server_id (Compose) or swarm_id (Swarm). action="update": existing stack (`stack` required). Only fields in `config` change. File source on create: file_contents | repo+branch | files_on_host.

NameTypeReqDescription
actionstringyes'create' to register a new stack, 'update' to PATCH an existing one
configobjectStack configuration fields to update (partial update)
namestringRequired when action='create' — unique name for the new stack
server_idstringConvenience field for action='create' — target server (mirrors `config.server_id`)
stackstringRequired when action='update' — existing stack id or name
NameTypeReqDescription
actionstringyesWhich apply action was performed
resourceobjectFull resource returned by Komodo (when available)
resource_idstringyesResource id or name affected
resource_typestringyesTarget resource type

No examples provided.

komodo_stack_delete ~41

Delete a Compose stack from Komodo. This removes the stack configuration but does not affect running containers.

NameTypeReqDescription
stackstringyesStack ID or name
NameTypeReqDescription
actionstringyesAlways 'remove' for delete tools
resourceobjectSnapshot of the deleted resource (when available)
resource_idstringyesResource id or name that was removed
resource_typestringyesTarget resource type

No examples provided.

komodo_stack_info ~73

Get detailed information about a Compose stack including configuration, current state, compose file contents, services, and environment variables.

NameTypeReqDescription
inline_fullbooleanIf true, return the full payload inline instead of a compact summary. Default: false.
stackstringyesStack ID or name to get info for
NameTypeReqDescription
infoFull stack resource payload, when returned inline
resourceLinkobjectReference to a server-exposed resource
summaryobjectyes

No examples provided.

komodo_stack_list ~75

List all Komodo-managed Compose stacks. Shows stack name, ID, and current state.

NameTypeReqDescription
cursorstringOpaque pagination cursor returned by a previous list call. Omit for the first page.
page_sizeintegerMaximum number of items to return (1-100). Default: server-defined.
NameTypeReqDescription
itemsarrayyesStacks visible to the caller
pageobjectPagination envelope for list responses

No examples provided.

komodo_swarm_action ~258

Swarm management. update_node: change availability/labels/role. remove_nodes: force-remove. remove_services / remove_stacks: equivalents of docker service rm / docker stack rm.

NameTypeReqDescription
actionstringyesSwarm action: update_node | remove_nodes | remove_services | remove_stacks
availabilitystringFor 'update_node': new node availability
detachbooleanFor 'remove_stacks': do not wait for removal to complete
forcebooleanFor 'remove_nodes': force-remove the node
label_addarrayFor 'update_node': labels to add (`key=value`)
label_rmarrayFor 'update_node': label keys to remove
nodestringRequired for 'update_node': node hostname or id
nodesarrayRequired for 'remove_nodes': node names/ids to remove
rolestringFor 'update_node': new node role
servicesarrayRequired for 'remove_services': service names/ids to remove
stacksarrayRequired for 'remove_stacks': stack names to remove
swarmstringyesSwarm id or name
NameTypeReqDescription
actionstringyesAction name that was executed (start, stop, deploy, prune, ...)
resource_idstringyesTarget resource ID or name
resource_typestringyesTarget resource type (container, deployment, stack, server)
serverstringTarget server, when the action runs against a host
statusstringyesUpdate status reported by Komodo (Complete, InProgress, Queued, ...)
successbooleanyesWhether the action completed successfully
versionstringResulting version string, when the action produces one (e.g. deploy)

No examples provided.

komodo_swarm_apply ~152

Create or update a Komodo Swarm (PATCH-style). Servers in config.server_ids form one Docker Swarm cluster. action="create": new swarm. Required: name. Recommended: config.server_ids. action="update": existing swarm (`swarm` required). Only fields in `config` change.

NameTypeReqDescription
actionstringyes'create' to register a new swarm, 'update' to PATCH an existing one
configobjectSwarm configuration (all fields optional, PATCH-style)
namestringRequired when action='create' — unique name for the new swarm
swarmstringRequired when action='update' — existing swarm id or name
NameTypeReqDescription
actionstringyesWhich apply action was performed
resourceobjectFull resource returned by Komodo (when available)
resource_idstringyesResource id or name affected
resource_typestringyesTarget resource type

No examples provided.

komodo_swarm_delete ~52

Unregister a Swarm from Komodo. Does NOT teardown the underlying Docker Swarm — it only removes the Komodo resource entry.

NameTypeReqDescription
swarmstringyesSwarm id or name to delete
NameTypeReqDescription
actionstringyesAlways 'remove' for delete tools
resourceobjectSnapshot of the deleted resource (when available)
resource_idstringyesResource id or name that was removed
resource_typestringyesTarget resource type

No examples provided.

komodo_swarm_info ~84

Get the full Komodo Swarm resource (manager server ids, links, alert/maintenance configuration). Large payloads are offloaded via a session-scoped resource link when available.

NameTypeReqDescription
inline_fullbooleanIf true, return the full payload inline instead of a compact summary. Default: false.
swarmstringyesSwarm id or name
NameTypeReqDescription
infoFull Swarm resource (only when not offloaded as a resource link)
resourceLinkobjectReference to a server-exposed resource
summaryobjectyes

No examples provided.

komodo_swarm_list ~83

List all swarms registered in Komodo. Each swarm groups one or more Server resources that act as Docker Swarm managers.

NameTypeReqDescription
cursorstringOpaque pagination cursor returned by a previous list call. Omit for the first page.
page_sizeintegerMaximum number of items to return (1-100). Default: server-defined.
NameTypeReqDescription
itemsarrayyesSwarms registered in Komodo
pageobjectPagination envelope for list responses

No examples provided.

komodo_swarm_nodes_list ~83

List the Docker nodes participating in a Komodo Swarm.

NameTypeReqDescription
cursorstringOpaque pagination cursor returned by a previous list call. Omit for the first page.
page_sizeintegerMaximum number of items to return (1-100). Default: server-defined.
swarmstringyesSwarm id or name
NameTypeReqDescription
itemsarrayyesNodes participating in the swarm
pageobjectPagination envelope for list responses
swarmstringyesSwarm id or name the nodes belong to

No examples provided.

komodo_swarm_services_list ~82

List Docker services running on a Komodo Swarm.

NameTypeReqDescription
cursorstringOpaque pagination cursor returned by a previous list call. Omit for the first page.
page_sizeintegerMaximum number of items to return (1-100). Default: server-defined.
swarmstringyesSwarm id or name
NameTypeReqDescription
itemsarrayyesServices running on the swarm
pageobjectPagination envelope for list responses
swarmstringyesSwarm id or name the services belong to

No examples provided.

komodo_update_info ~69

Get the full update payload for a single operation, including per-stage logs (stdout/stderr).

NameTypeReqDescription
idstringyesUpdate id (MongoDB ObjectId hex)
inline_fullbooleanIf true, return the full payload inline instead of a compact summary. Default: false.
NameTypeReqDescription
infoFull update payload (with stage logs) when returned inline
resourceLinkobjectReference to a server-exposed resource
summaryobjectyes

No examples provided.

komodo_update_list ~162

List Komodo update history (audit log of operations like Deploy/RunBuild/RunSync). Newest first. Supports filtering by operation name and resource target. Pagination uses an opaque cursor string (Komodo backend is page-based).

NameTypeReqDescription
cursorstringOpaque pagination cursor from a previous list call. Omit for the first page.
operationstringFilter by operation name (e.g. 'Deploy', 'RunBuild')
page_sizeintegerMaximum number of items to return (1-100)
target_idstringFilter by resource target id
target_typestringFilter by resource target type (e.g. 'Stack', 'Deployment', 'Build', 'Repo', 'Procedure')
NameTypeReqDescription
itemsarrayyesUpdate history items
pageobjectPagination envelope for list responses

No examples provided.

komodo_user_create_api_key ~91

Create a new API key for the currently authenticated Komodo user. Returns the key and secret — the secret is shown only once and cannot be retrieved later. Optionally set an expiry time.

NameTypeReqDescription
expires_in_daysintegerNumber of days until the key expires. 0 means no expiry. Default: 0
namestringyesA descriptive name for the API key
NameTypeReqDescription
expiresintegeryesExpiry timestamp in milliseconds since epoch (0 = never)
keystringyesAPI key ID (public identifier)
namestringyesName assigned to the new key
secretstringyesAPI key secret — shown only on creation, cannot be retrieved later

No examples provided.

komodo_user_delete_api_key ~113

Delete an API key for the currently authenticated Komodo user. Accepts either the key name or the full K_... key string. Use komodo_user_list_api_keys to see available keys.

NameTypeReqDescription
name_or_keystringyesThe key name (e.g. 'mykey') OR the full key string (e.g. 'K_abc...'). Use the name shown in komodo_user_list_api_keys. If multiple keys share the same name, provide the full K_... string.
NameTypeReqDescription
deletedbooleanyesWhether the API key was removed
key_idstringyesThe full K_... key string that was deleted
namestringThe key name, when resolved by name lookup

No examples provided.

komodo_user_list_api_keys ~87

List all API keys for the currently authenticated Komodo user. Shows key name, key ID (not secret), creation date, and expiry.

NameTypeReqDescription
cursorstringOpaque pagination cursor returned by a previous list call. Omit for the first page.
page_sizeintegerMaximum number of items to return (1-100). Default: server-defined.
NameTypeReqDescription
itemsarrayyesAPI keys for the authenticated user
pageobjectPagination envelope for list responses

No examples provided.

komodo_variable_apply ~162

Create or update a Komodo Variable (PATCH-style on update). action="create": new variable. Required: name. Optional: value, description, is_secret. action="update": existing variable (name required). Each of value, description, is_secret triggers a separate update call when provided.

NameTypeReqDescription
actionstringyes'create' to register a new variable, 'update' to change an existing variable's value/description/is_secret
descriptionstringOptional description
is_secretbooleanIf true, mark the variable as a secret (value redacted in responses)
namestringyesVariable name (unique key)
valuestringVariable value — required for action='create'; optional for update
NameTypeReqDescription
actionstringyesWhich apply action was performed
resourceobjectFull resource returned by Komodo (when available)
resource_idstringyesResource id or name affected
resource_typestringyesTarget resource type

No examples provided.

komodo_variable_delete ~48

Delete a Komodo Variable. Stacks/Deployments referencing it via `[[variable.name]]` will fail to interpolate afterwards.

NameTypeReqDescription
namestringyesVariable name (unique key)
NameTypeReqDescription
actionstringyesAlways 'remove' for delete tools
resourceobjectSnapshot of the deleted resource (when available)
resource_idstringyesResource id or name that was removed
resource_typestringyesTarget resource type

No examples provided.

komodo_variable_info ~39

Get a single Komodo variable. Secret variables are redacted for non-admin users.

NameTypeReqDescription
namestringyesVariable name (unique key)
NameTypeReqDescription
variableobjectyes

No examples provided.

komodo_variable_list ~78

List all global variables registered in Komodo. Secret variables have their value redacted for non-admin users.

NameTypeReqDescription
cursorstringOpaque pagination cursor returned by a previous list call. Omit for the first page.
page_sizeintegerMaximum number of items to return (1-100). Default: server-defined.
NameTypeReqDescription
itemsarrayyesVariables registered in Komodo
pageobjectPagination envelope for list responses

No examples provided.