Symfony Agent MCP runs on your own machine — the client starts it, so there is no endpoint to ping. 66 installs a week from npm. Last commit 30 Aug 2026.
Read-only Symfony introspection: routes, services, entities, Doctrine, security, Twig and more.
We read the source, 20 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
'/app/; rm -rf /',
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
const fullPath = path.join(appPath, rel);
'/app/../../../etc/shadow',
'https://hooks.slack.com/', 'services', '/T00000000/B00000000/', 'X'.repeat(24)
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Symfony Agent MCP and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add symfony-agent-mcp -- npx -y @shakaran/symfony-agent-mcp
{
"mcpServers": {
"symfony-agent-mcp": {
"args": [
"-y",
"@shakaran/symfony-agent-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.symfony-agent-mcp]
command = "npx"
args = ["-y", "@shakaran/symfony-agent-mcp"]
{
"mcpServers": {
"symfony-agent-mcp": {
"args": [
"-y",
"@shakaran/symfony-agent-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"symfony-agent-mcp": {
"args": [
"-y",
"@shakaran/symfony-agent-mcp"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
SYMFONY_MCP_DYNAMIC_TOOLS (Progressive tool discovery. Left on, tools/list advertises five discovery meta-tools and the rest become callable once a category is activated (~828 tokens on connect). Set to false to advertise all 1,677 up front (~154,000).), SYMFONY_MCP_TOKEN_BUDGET (Token ceiling for the schemas a session may have active at once.), SYMFONY_MCP_ALLOWED_PATHS (Colon-separated allowlist of directories the server may read. Any app_path outside them is refused.), SYMFONY_MCP_SESSION_SECRET (Enables session-token authentication. Unset, authentication is off.), SYMFONY_MCP_SESSION_TOKEN (Client-side token, required only once SYMFONY_MCP_SESSION_SECRET is set.), SYMFONY_MCP_AUDIT (Encrypted audit log of every tool call.), SYMFONY_MCP_DLP (Scan every result for credentials before returning it. Turning this off is reported as CRITICAL by the startup audit.).
The author declared them in the registry entry; get the values from the project itself.
Secure, read-only access to Amazon Redshift with schema introspection and smart sampling
Security sidecar for MCP servers: 11 read-only control-plane tools for prompt-injection checks.
Read-only MCP/agent-gateway readiness scanner — scores a repo across 7 security dimensions.
SSH server management for agents, with per-server read-only and allowlist security modes
Read-only Kubernetes MCP server: inspect resources, logs, events, and metrics. Secrets are masked.
Multi-layer security scanner for MCP servers and agent skills (injection, exfiltration)
MCP server providing Docker Desktop release notes and security information.
Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.
Answers built from our own checks of this server.