Komodo MCP Server
NPM · KOMODO-MCP-SERVER · 2 COMPONENTS · SCANNED AUG 3
MCP server for Komodo - manage Docker containers, servers, stacks, and deployments via AI
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security79
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known high-severity CVE affects @opentelemetry/propagator-jaeger 2.8.0, reached via mcp-server-framework > @opentelemetry/sdk-node > @opentelemetry/propagator-jaeger. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- Only part of the dependency tree could be resolved (176 of 184), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to MP-Tool/komodo-mcp-server). View diagnostics → Pass
- Clear OSI-approved license (GPL-3.0).Pass
- Actively maintained (last published 41 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability77
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 6981 tokens (~99/item across 70 items; 70 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · komodo-mcp-server
claude mcp add mp-tool-komodo-mcp-server -- npx -y komodo-mcp-server
codex mcp add mp-tool-komodo-mcp-server -- npx -y komodo-mcp-server
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"mp-tool-komodo-mcp-server": {
"type": "local",
"command": [
"npx",
"-y",
"komodo-mcp-server"
],
"enabled": true
}
}
} openclaw mcp add mp-tool-komodo-mcp-server --command npx --arg -y --arg komodo-mcp-server
mcp_servers:
mp-tool-komodo-mcp-server:
command: "npx"
args: ["-y", "komodo-mcp-server"] {
"mcpServers": {
"mp-tool-komodo-mcp-server": {
"command": "npx",
"args": [
"-y",
"komodo-mcp-server"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +4
- Stability: unverified → 0.27 ▲ functional
- 2 Aug 26 +38
- Known CVEs: unverified → fail ▼ security
- Provenance: unverified → pass ▲ security
- Install scripts: unverified → pass ▲ security
- Malware scan: unverified → pass ▲ security
- Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
- The attested source repository moved: MP-Tool/komodo-mcp-server security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Maintenance: unverified → pass ▲ functional
- License: unverified → pass ▲ functional
- Dependency health: unverified → partial ▲ functional
- Licence: GPL-3.0 functional
- 1 Aug 26 +31
- Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
- Security disclosure: unverified → fail ▼ functional
- MCP protocol: unverified → pass ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- 31 Jul 26 −3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 −82
- Provenance: pass → unverified ▼ security
- Malware scan: pass → unverified ▼ security
- Known CVEs: fail → unverified ▼ security
- Install scripts: pass → unverified ▼ security
- CVE-2026-59892 no longer affects this package ▲ security
- The attested source repository moved: MP-Tool/komodo-mcp-server security
- Maintenance: pass → unverified ▼ functional
- License: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Licence: GPL-3.0 functional
- 29 Jul 26 +12
- Schema quality: unverified → excellent ▲ functional
- 28 Jul 26 +53
- CVE-2026-59892 affects this package: high ▼ security
- Known CVEs: unverified → fail ▼ security
- Install scripts: unverified → pass ▲ security
- Provenance: unverified → pass ▲ security
- The attested source repository moved: MP-Tool/komodo-mcp-server security
- License: unverified → pass ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- Maintenance: unverified → pass ▲ functional
- First check of Tool coverage: 100 functional
- First check of Tool coverage: 100 functional
- First check of Schema quality: unverified functional
- First check of Schema quality: pass functional
- First check of Schema quality: fail functional
- Licence: GPL-3.0 functional
- 26 Jul 26 25
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Analysed npm/[email protected]
Provenance verified
Ecosystem: npm · Outcome: verified
Reason: verified
- Source repo:
- MP-Tool/komodo-mcp-server
- Certificate issuer:
- https://token.actions.githubusercontent.com
- Certificate SAN:
- https://github.com/MP-Tool/komodo-mcp-server/.github/workflows/publish-npm.yml@refs/heads/main
- Rekor log index:
- 1913549996
- Predicate type:
- https://slsa.dev/provenance/v1
- Subject digest:
- sha512:872ac58c7ad32da5b481c68069b5775b35ef489a055faa58ddc28774ff3f84d387492cc6c5292334ededeae2f7fd938e94aa3dde7996d26c26dd2c844
- Discovery method:
- attestation_endpoint
Vulnerabilities 1 finding
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-45rx-2jwx-cxfr | CVE-2026-59892 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
Dependencies 176 packages
176 packages in the resolved dependency tree · 172 deprecated · 41 stale · 1 without a linked repository.
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
komodo_stack_action ~116
Lifecycle action on a Compose stack: deploy (up), pull, start, restart, pause, unpause, stop, destroy (down — removes containers). destroy is destructive; config preserved.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Lifecycle action: deploy (compose up / re-deploy), pull (pull latest images), start (compose start), restart (stop+start), pause/unpause (freeze/resume processes), stop (compose stop), destroy (compo… |
| stack | string | yes | Stack ID or name |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Action name that was executed (start, stop, deploy, prune, ...) |
| resource_id | string | yes | Target resource ID or name |
| resource_type | string | yes | Target resource type (container, deployment, stack, server) |
| server | string | — | Target server, when the action runs against a host |
| status | string | yes | Update status reported by Komodo (Complete, InProgress, Queued, ...) |
| success | boolean | yes | Whether the action completed successfully |
| version | string | — | Resulting version string, when the action produces one (e.g. deploy) |
No examples provided.
komodo_stack_apply ~187
Create or update a Docker Compose stack in Komodo (PATCH-style). action="create": new stack. Required: name. Recommended: server_id (Compose) or swarm_id (Swarm). action="update": existing stack (`stack` required). Only fields in `config` change. File source on create: file_contents | repo+branch | files_on_host.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | 'create' to register a new stack, 'update' to PATCH an existing one |
| config | object | — | Stack configuration fields to update (partial update) |
| name | string | — | Required when action='create' — unique name for the new stack |
| server_id | string | — | Convenience field for action='create' — target server (mirrors `config.server_id`) |
| stack | string | — | Required when action='update' — existing stack id or name |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Which apply action was performed |
| resource | object | — | Full resource returned by Komodo (when available) |
| resource_id | string | yes | Resource id or name affected |
| resource_type | string | yes | Target resource type |
No examples provided.
komodo_stack_delete ~41
Delete a Compose stack from Komodo. This removes the stack configuration but does not affect running containers.
| Name | Type | Req | Description |
|---|---|---|---|
| stack | string | yes | Stack ID or name |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Always 'remove' for delete tools |
| resource | object | — | Snapshot of the deleted resource (when available) |
| resource_id | string | yes | Resource id or name that was removed |
| resource_type | string | yes | Target resource type |
No examples provided.
komodo_stack_info ~73
Get detailed information about a Compose stack including configuration, current state, compose file contents, services, and environment variables.
| Name | Type | Req | Description |
|---|---|---|---|
| inline_full | boolean | — | If true, return the full payload inline instead of a compact summary. Default: false. |
| stack | string | yes | Stack ID or name to get info for |
| Name | Type | Req | Description |
|---|---|---|---|
| info | — | — | Full stack resource payload, when returned inline |
| resourceLink | object | — | Reference to a server-exposed resource |
| summary | object | yes | — |
No examples provided.
komodo_stack_list ~75
List all Komodo-managed Compose stacks. Shows stack name, ID, and current state.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor returned by a previous list call. Omit for the first page. |
| page_size | integer | — | Maximum number of items to return (1-100). Default: server-defined. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Stacks visible to the caller |
| page | object | — | Pagination envelope for list responses |
No examples provided.
komodo_swarm_action ~258
Swarm management. update_node: change availability/labels/role. remove_nodes: force-remove. remove_services / remove_stacks: equivalents of docker service rm / docker stack rm.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Swarm action: update_node | remove_nodes | remove_services | remove_stacks |
| availability | string | — | For 'update_node': new node availability |
| detach | boolean | — | For 'remove_stacks': do not wait for removal to complete |
| force | boolean | — | For 'remove_nodes': force-remove the node |
| label_add | array | — | For 'update_node': labels to add (`key=value`) |
| label_rm | array | — | For 'update_node': label keys to remove |
| node | string | — | Required for 'update_node': node hostname or id |
| nodes | array | — | Required for 'remove_nodes': node names/ids to remove |
| role | string | — | For 'update_node': new node role |
| services | array | — | Required for 'remove_services': service names/ids to remove |
| stacks | array | — | Required for 'remove_stacks': stack names to remove |
| swarm | string | yes | Swarm id or name |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Action name that was executed (start, stop, deploy, prune, ...) |
| resource_id | string | yes | Target resource ID or name |
| resource_type | string | yes | Target resource type (container, deployment, stack, server) |
| server | string | — | Target server, when the action runs against a host |
| status | string | yes | Update status reported by Komodo (Complete, InProgress, Queued, ...) |
| success | boolean | yes | Whether the action completed successfully |
| version | string | — | Resulting version string, when the action produces one (e.g. deploy) |
No examples provided.
komodo_swarm_apply ~152
Create or update a Komodo Swarm (PATCH-style). Servers in config.server_ids form one Docker Swarm cluster. action="create": new swarm. Required: name. Recommended: config.server_ids. action="update": existing swarm (`swarm` required). Only fields in `config` change.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | 'create' to register a new swarm, 'update' to PATCH an existing one |
| config | object | — | Swarm configuration (all fields optional, PATCH-style) |
| name | string | — | Required when action='create' — unique name for the new swarm |
| swarm | string | — | Required when action='update' — existing swarm id or name |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Which apply action was performed |
| resource | object | — | Full resource returned by Komodo (when available) |
| resource_id | string | yes | Resource id or name affected |
| resource_type | string | yes | Target resource type |
No examples provided.
komodo_swarm_delete ~52
Unregister a Swarm from Komodo. Does NOT teardown the underlying Docker Swarm — it only removes the Komodo resource entry.
| Name | Type | Req | Description |
|---|---|---|---|
| swarm | string | yes | Swarm id or name to delete |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Always 'remove' for delete tools |
| resource | object | — | Snapshot of the deleted resource (when available) |
| resource_id | string | yes | Resource id or name that was removed |
| resource_type | string | yes | Target resource type |
No examples provided.
komodo_swarm_info ~84
Get the full Komodo Swarm resource (manager server ids, links, alert/maintenance configuration). Large payloads are offloaded via a session-scoped resource link when available.
| Name | Type | Req | Description |
|---|---|---|---|
| inline_full | boolean | — | If true, return the full payload inline instead of a compact summary. Default: false. |
| swarm | string | yes | Swarm id or name |
| Name | Type | Req | Description |
|---|---|---|---|
| info | — | — | Full Swarm resource (only when not offloaded as a resource link) |
| resourceLink | object | — | Reference to a server-exposed resource |
| summary | object | yes | — |
No examples provided.
komodo_swarm_list ~83
List all swarms registered in Komodo. Each swarm groups one or more Server resources that act as Docker Swarm managers.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor returned by a previous list call. Omit for the first page. |
| page_size | integer | — | Maximum number of items to return (1-100). Default: server-defined. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Swarms registered in Komodo |
| page | object | — | Pagination envelope for list responses |
No examples provided.
komodo_swarm_nodes_list ~83
List the Docker nodes participating in a Komodo Swarm.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor returned by a previous list call. Omit for the first page. |
| page_size | integer | — | Maximum number of items to return (1-100). Default: server-defined. |
| swarm | string | yes | Swarm id or name |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Nodes participating in the swarm |
| page | object | — | Pagination envelope for list responses |
| swarm | string | yes | Swarm id or name the nodes belong to |
No examples provided.
komodo_swarm_services_list ~82
List Docker services running on a Komodo Swarm.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor returned by a previous list call. Omit for the first page. |
| page_size | integer | — | Maximum number of items to return (1-100). Default: server-defined. |
| swarm | string | yes | Swarm id or name |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Services running on the swarm |
| page | object | — | Pagination envelope for list responses |
| swarm | string | yes | Swarm id or name the services belong to |
No examples provided.
komodo_update_info ~69
Get the full update payload for a single operation, including per-stage logs (stdout/stderr).
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Update id (MongoDB ObjectId hex) |
| inline_full | boolean | — | If true, return the full payload inline instead of a compact summary. Default: false. |
| Name | Type | Req | Description |
|---|---|---|---|
| info | — | — | Full update payload (with stage logs) when returned inline |
| resourceLink | object | — | Reference to a server-exposed resource |
| summary | object | yes | — |
No examples provided.
komodo_update_list ~162
List Komodo update history (audit log of operations like Deploy/RunBuild/RunSync). Newest first. Supports filtering by operation name and resource target. Pagination uses an opaque cursor string (Komodo backend is page-based).
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor from a previous list call. Omit for the first page. |
| operation | string | — | Filter by operation name (e.g. 'Deploy', 'RunBuild') |
| page_size | integer | — | Maximum number of items to return (1-100) |
| target_id | string | — | Filter by resource target id |
| target_type | string | — | Filter by resource target type (e.g. 'Stack', 'Deployment', 'Build', 'Repo', 'Procedure') |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Update history items |
| page | object | — | Pagination envelope for list responses |
No examples provided.
komodo_user_create_api_key ~91
Create a new API key for the currently authenticated Komodo user. Returns the key and secret — the secret is shown only once and cannot be retrieved later. Optionally set an expiry time.
| Name | Type | Req | Description |
|---|---|---|---|
| expires_in_days | integer | — | Number of days until the key expires. 0 means no expiry. Default: 0 |
| name | string | yes | A descriptive name for the API key |
| Name | Type | Req | Description |
|---|---|---|---|
| expires | integer | yes | Expiry timestamp in milliseconds since epoch (0 = never) |
| key | string | yes | API key ID (public identifier) |
| name | string | yes | Name assigned to the new key |
| secret | string | yes | API key secret — shown only on creation, cannot be retrieved later |
No examples provided.
komodo_user_delete_api_key ~113
Delete an API key for the currently authenticated Komodo user. Accepts either the key name or the full K_... key string. Use komodo_user_list_api_keys to see available keys.
| Name | Type | Req | Description |
|---|---|---|---|
| name_or_key | string | yes | The key name (e.g. 'mykey') OR the full key string (e.g. 'K_abc...'). Use the name shown in komodo_user_list_api_keys. If multiple keys share the same name, provide the full K_... string. |
| Name | Type | Req | Description |
|---|---|---|---|
| deleted | boolean | yes | Whether the API key was removed |
| key_id | string | yes | The full K_... key string that was deleted |
| name | string | — | The key name, when resolved by name lookup |
No examples provided.
komodo_user_list_api_keys ~87
List all API keys for the currently authenticated Komodo user. Shows key name, key ID (not secret), creation date, and expiry.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor returned by a previous list call. Omit for the first page. |
| page_size | integer | — | Maximum number of items to return (1-100). Default: server-defined. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | API keys for the authenticated user |
| page | object | — | Pagination envelope for list responses |
No examples provided.
komodo_variable_apply ~162
Create or update a Komodo Variable (PATCH-style on update). action="create": new variable. Required: name. Optional: value, description, is_secret. action="update": existing variable (name required). Each of value, description, is_secret triggers a separate update call when provided.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | 'create' to register a new variable, 'update' to change an existing variable's value/description/is_secret |
| description | string | — | Optional description |
| is_secret | boolean | — | If true, mark the variable as a secret (value redacted in responses) |
| name | string | yes | Variable name (unique key) |
| value | string | — | Variable value — required for action='create'; optional for update |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Which apply action was performed |
| resource | object | — | Full resource returned by Komodo (when available) |
| resource_id | string | yes | Resource id or name affected |
| resource_type | string | yes | Target resource type |
No examples provided.
komodo_variable_delete ~48
Delete a Komodo Variable. Stacks/Deployments referencing it via `[[variable.name]]` will fail to interpolate afterwards.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Variable name (unique key) |
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Always 'remove' for delete tools |
| resource | object | — | Snapshot of the deleted resource (when available) |
| resource_id | string | yes | Resource id or name that was removed |
| resource_type | string | yes | Target resource type |
No examples provided.
komodo_variable_info ~39
Get a single Komodo variable. Secret variables are redacted for non-admin users.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Variable name (unique key) |
| Name | Type | Req | Description |
|---|---|---|---|
| variable | object | yes | — |
No examples provided.
komodo_variable_list ~78
List all global variables registered in Komodo. Secret variables have their value redacted for non-admin users.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor returned by a previous list call. Omit for the first page. |
| page_size | integer | — | Maximum number of items to return (1-100). Default: server-defined. |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | Variables registered in Komodo |
| page | object | — | Pagination envelope for list responses |
No examples provided.